找回密码
 立即注册

QQ登录

只需一步,快速开始

查看: 12754|回复: 0

nginx配合modsecurity实现WAF功能

[复制链接]
发表于 2017-10-19 16:53:31 | 显示全部楼层 |阅读模式
modsecurity原本是Apache上的一款开源waf,可以有效的增强web安全性,目前已经支持nginx和IIS,配合nginx的灵活和高效,可以打造成生产级的WAF,是保护和审核web安全的利器。
. c3 h' \2 h1 J; I0 M  q* p: X/ O" X
一.准备工作
$ |) [: c2 j+ i8 B7 |& |0 p8 E% g' X" u
系统:centos 6.5 64位、 tengine 2.1.0, modsecurity 2.8.0! `4 ~, g. _6 M- K
) v3 h9 J3 S" t6 o) v( L* H, _" h
tengine : http://tengine.taobao.org/download/tengine-2.1.0.tar.gz
. M* V! j6 Y, L4 s& F  p
  ~- z3 B, A; k5 M7 e) _# m9 ?modsecurity for Nginx: https://www.modsecurity.org/tarball/2.8.0/modsecurity-2.8.0.tar.gz
. M# W2 Q8 H5 G1 V. {1 e5 t$ x$ L: I
OWASP规则集: https://github.com/SpiderLabs/owasp-modsecurity-crs
5 {/ M7 L) {, X& x6 w, u  c/ Z2 O. `7 A: N+ N
依赖关系:" _9 L2 R7 t% f9 B( F+ A* t% K, O
tengine(nginx)依赖: pcre 、zlib、 openssl, 这三个包centos 6.5 系统源里都有:9 E" Q  B% X; L/ u9 m5 s
( M  v5 C! Y- I* H* H- D8 F
yum install zlib zlib-devel openssl openssl-devel  pcre pcre-devel
. ?- q/ a( J7 x( |1 |" ?modsecurty依赖的包:pcre httpd-devel libxml2 apr' T, f- G& Q7 _

" U- p& `; L" S8 i% n: R5 `7 R# cyum install httpd-devel apr apr-util-devel apr-devel  pcre pcre-devel  libxml2 libxml2-devel
1 Y; F9 b0 `* I- y" o二.启用standalone模块并编译& D5 f, ~" t, k" T& ]
$ k: |4 Z" u& |% Q
下载modsecurity for nginx 解压,进入解压后目录执行:  B1 T% {4 U: v/ M0 }
* _* S! e- F; [: |; g; w
./autogen.sh
1 Z; P, F  \5 m./configure --enable-standalone-module --disable-mlogc3 X& p0 h: V' |, B% }
make
; a9 m9 ]) Q! U" b' Q- m三.nginx添加modsecurity模块
9 Y0 D8 v- V: u8 Y! F
- F  C2 t9 q+ w7 m9 d在编译standalone后,nginx编译时可以通过"--add-module"添加modsecurity模块:( a+ s" D1 ?6 ~" `; n+ {
9 R- p! _' j4 Y  \* Q6 P: u* C
./configure --add-module=/root/modsecurity-2.8.0/nginx/modsecurity/  --prefix=/opt/tengine% U6 H/ j& f8 b
make && make install# |/ w- h- V" m( |- n
四.添加规则
( o, B' h# q: G  u/ b
( u  ?2 _8 ~6 y- Emodsecurity倾向于过滤和阻止web危险,之所以强大就在于规则,OWASP提供的规则是于社区志愿者维护的,被称为核心规则CRS(corerules),规则可靠强大,当然也可以自定义规则来满足各种需求。% p" B( i" G- ^9 {
. ^' y: \) C3 F  K
1.下载OWASP规则:* @" n, P) u+ I3 [8 a
4 x/ T$ V  N% Z
git clone https://github.com/SpiderLabs/owasp-modsecurity-crs
, d9 [5 D$ o6 |+ ]: W( Y! M+ P$ G9 a
mv owasp-modsecurity-crs /opt/tengine/conf/
3 {2 r$ F- _! L2 a+ O/ Z! G0 g3 u7 d! m, X" t" ^$ d
cd /opt/tengine/conf/owasp-modsecurity-crs && mv modsecurity_crs_10_setup.conf.example modsecurity_crs_10_setup.conf
; J  F4 `; h" ^' F; E; A0 H2.启用OWASP规则:
+ U% x0 q+ D+ O/ g: y
  k) D- L- B: U$ O1 ~复制modsecurity源码目录下的modsecurity.conf-recommended和unicode.mapping到nginx的conf目录下,并将modsecurity.conf-recommended重新命名为modsecurity.conf。
/ z, l- d+ O% x+ f5 ?$ g" ]" q+ t* U' M
编辑modsecurity.conf 文件,将SecRuleEngine设置为 on
$ z6 g( S8 l1 h: D. N( U8 D  y8 R5 ~/ \6 ~% `' ^
owasp-modsecurity-crs下有很多存放规则的文件夹,例如base_rules、experimental_rules、optional_rules、slr_rules,里面的规则按需要启用,需要启用的规则使用Include进来即可。( }/ d1 R- r5 Z) S' o; ^, z9 U9 c, I
! u$ p+ h2 z% b2 n' s- F1 y' P( }1 c
Include owasp-modsecurity-crs/modsecurity_crs_10_setup.conf
# x+ L4 @9 Q" I  ^  B% N& sInclude owasp-modsecurity-crs/base_rules/modsecurity_crs_41_sql_injection_attacks.conf
" a) T. b* |5 v2 m  B3 IInclude owasp-modsecurity-crs/base_rules/modsecurity_crs_41_xss_attacks.conf+ l3 d+ [6 J; ^
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_40_generic_attacks.conf# S" ~) L2 [$ S3 i3 l% m( s- ~
Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_dos_protection.conf
. y  G9 P, _0 @3 e( z5 i7 gInclude owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_brute_force.conf6 t! d3 B! J! F
Include owasp-modsecurity-crs/optional_rules/modsecurity_crs_16_session_hijacking.conf
& O' A  x! n6 l* k五.配置nginx* K% k( q# v- s6 L
, D* Q0 u8 t' X9 g, Q7 i
在需要启用modsecurity的主机的location下面加入下面两行即可:
( A* _- d, n' H5 M! A, T9 T- o3 T" T  t4 W) I* Z! Q
ModSecurityEnabled on;  " ]8 |* W; J2 |) }; z8 d
ModSecurityConfig modsecurity.conf;
) G% l6 _! G4 y! C下面是两个示例配置,php虚拟主机:
$ h0 H  Z& H' }7 r0 O+ O3 i7 W3 C) s$ w' X# K
server {' C& N8 K! `' J. p! n) |, A7 e
      listen      80;
6 Q5 f4 k# ?" ~& a# v- b      server_name 52os.net www.52os.net;
% J- R/ R9 U$ X. e       a' u/ {" U# c  I6 w* L: W
      location ~ \.php$ {
5 o: b2 e3 @8 j  P0 y( p$ t3 M3 |9 F8 [      ModSecurityEnabled on;  ( A3 t3 l4 B7 Q9 v/ Y8 B( O
      ModSecurityConfig modsecurity.conf;: P! o$ f5 u( D0 R/ o# F

2 `# t) Y& p' M. X4 e      root /web/wordpress;
+ r3 v/ l2 \* {9 Y$ e  y      index index.php index.html index.htm;
( A: x/ }7 F0 B: T% U7 L3 ?  " b; j, s9 a2 T
      fastcgi_pass   127.0.0.1:9000;- m, c0 U( E; j9 g) O; g
      fastcgi_index  index.php;* y0 \  r6 S0 `- |: n; f
      fastcgi_param  SCRIPT_FILENAME  $Document_root$fastcgi_script_name;
, f# j5 W6 D/ H' s! u$ j. _- E      include        fastcgi_params;1 ]' Q8 }' t" J- u2 o! @& c: G! h
      }1 Y( J/ m5 i8 F4 Z
  }
0 V7 c$ c' e) I8 |/ ?* ~upstream负载均衡:' W4 A1 {2 X' r, {/ m

+ X+ y% l: ~8 g% @upstream 52os.net {
1 A5 d( M3 Q0 e7 `$ q+ N0 N    server 192.168.1.100:8080;
$ a- }' I/ l6 E# T5 u, l    server 192.168.1.101:8080 backup;% i3 }5 n- R2 Q; E3 _
}
4 W! w2 A/ p+ A. G- G" d5 u2 v7 V) o
$ O+ B& N. d2 s7 l# K# L: }; gserver {
1 o0 C  x3 d+ G0 v7 ylisten 80;6 x* A8 b9 c1 h/ X2 ^* B" J  N/ j
server_name 52os.net www.52os.net;, ]4 F" f6 k5 z: K. C5 n
4 B# E7 p5 m$ I/ |  E) ~5 {+ B4 o
location / {0 l2 X# x* L# `9 R; I5 l. \
    ModSecurityEnabled on;  ; Y2 f, F7 A1 J1 W
    ModSecurityConfig modsecurity.conf;  
6 _! l6 i0 h$ ^3 Q2 T5 {, q# a/ Y. [, T* A! a2 p- |4 Y
        proxy_pass http://online;
  p& c0 P$ S$ n# @% A0 J        proxy_redirect         off;  h% H7 k3 o( N2 L
        proxy_set_header Host $host;; _* L( g: Y4 Z8 m/ u0 y8 ]' [
        proxy_set_header X-Real-IP $remote_addr;
: g7 ?5 M- t# f. `+ V* v2 @$ Z        proxy_set_header  X-Forwarded-For $proxy_add_x_forwarded_for;$ @. j0 Q5 ~% h$ H; E" h* g
    }
9 V% T2 {/ x  k: V2 Z% Z}
$ g0 [, ^  r9 X. M六.测试: Z" ]' q* N5 h
6 f& v: T% e, U
我们启用了xss和sql注入的过滤,不正常的请求会直接返回403。以php环境为例,新建一个phpinfo.php内容为:4 E* }! J8 h8 Y' N4 F

4 A% {2 J  f% G" `. t* o* s<?php( b# p/ c" m% R& B3 Z
    phpinfo();   
; ~. M# `7 f) G& i/ L5 p?>7 R7 D/ j" c% B$ R/ w, e& [
在浏览器中访问:0 N* X: H! p0 T0 F& y
5 i# O+ I- T! e5 W: k& C
http://www.52os.net/phpinfo.php?id=1 正常显示。
  b( w' X" f  C1 [. X6 Khttp://www.52os.net/phpinfo.php?id=1 and 1=1  返回403。% a9 p; e0 ~5 y4 k' ?) g* E3 p
http://www.52os.net/phpinfo.php?search=<scritp>alert('xss');</script>  返回403。
- n- p5 h, A) [" `说明sql注入和xss已经被过滤了
; j; g. L8 @2 o
# ?7 d0 l0 s( Q, t七、安装过程中排错
& L& H( F/ c1 q/ l3 P
* s1 f7 o! D3 \: c) ?2 J7 H9 J1.缺少APXS会报错
, `, h% x  l! Y- U0 K- ^4 g/ X/ e) [7 T( `) s- m. q
configure: looking for Apache module support via DSO through APXS
8 a2 Y2 ]8 \' ?3 B# {+ Wconfigure: error: couldn't find APXS
9 o% _0 _# ]9 z/ Z; C8 Papxs是一个为Apache HTTP服务器编译和安装扩展模块的工具,用于编译一个或多个源程序或目标代码文件为动态共享对象。
7 `8 v/ F, [6 U. a( t2 d1 F解决方法:" ~- T% C' S! o. V7 Z, K" z1 O

/ Q( {* H! K8 R0 q0 yyum install httpd-devel0 `5 r% C2 X, u
2.没有pcre
( Z7 A+ ]9 `$ @9 c) I1 E. W0 C6 N' j& E8 ]4 R) ^0 D
configure: *** pcre library not found.
  f! y& x% g; K+ A* iconfigure: error: pcre library is required4 {( Y1 A, b8 t: F; }8 p
解决方法:
$ _* u6 \1 d/ r2 f% ^
3 o+ X, @, z/ M' c0 U& |yum install pcre pcre-devel* l8 P% Z8 k" E8 c  c2 G
3.没有libxml2
% ?$ v+ }+ f8 J% C# f! l4 s
9 g0 W1 W) ]- @) T" y) b2 z7 g
configure: *** xml library not found.' E( W7 w% u2 H4 g- ?* Q( P' r
configure: error: libxml2 is required
6 h$ S/ \# R) j# N% U5 b解决方法:8 S3 {9 O" B! l. L8 t3 U2 q5 T

* F& ]% W3 s$ M. R( k3 G. }  ]yum install  libxml2 libxml2-devel+ R8 k% _1 `8 O: R
4.执行 /opt/tengine/sbin/nginx -m 时有警告4 z$ F$ z. l" a& v* i! K- b6 q# Y' j

  ]* c; U$ g2 y5 h# e3 j, r2 eTengine version: Tengine/2.1.0 (nginx/1.6.2)
9 `3 ]4 _6 `$ u; nnginx: [warn] ModSecurity: Loaded APR do not match with compiled!
. A4 _& U- Y0 @6 \% O4 t" g8 I原因:modsecurity编译时和加载时的apr版本不一致造成的,并且会有以下error.log$ l' n. u- S5 o
- Y! r9 H/ H' o6 U# h7 G, n  q
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity for nginx (STABLE)/2.8.0 () configured.$ F' ~- v- Y1 Y# {9 A, T7 s
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: APR compiled version="1.5.0"; loaded     version="1.3.9"3 g6 \  K6 N' C* y
2015/01/26 02:04:18 [warn] 29036#0: ModSecurity: Loaded APR do not match with compiled!5 W; q5 k7 d/ y  Y$ Y
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: PCRE compiled version="7.8 "; loaded version="7.8 2008-09-05"
3 o' a* e/ w' L7 e2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: LIBXML compiled version="2.7.6"
, l, T3 u2 i; S; l$ x: d4 q2015/01/26 02:04:18 [notice] 29036#0: Status engine is currently disabled, enable it by set SecStatusEngine to On.. l: {$ W+ L1 Q, X& G  X* i) ^* J
解决方法,移除低版本的APR (1.3.9)
& r$ Q* [/ h3 H/ N) q" n- t3 J4 Q! i8 F1 q- n
yum remove apr* H* o: w+ X: f& X! ?2 J- d
5.Error.log中有: Audit log: Failed to lock global mutex
% t2 g5 u$ B" A" [
$ Y9 u3 c# p9 y3 B8 `2015/01/26 04:15:42 [error] 61610#0: [client 10.11.15.161] ModSecurity: Audit log: Failed to lock     & M. K5 Q$ z0 b1 ~
global mutex: Permission denied [hostname ""] [uri "/i.php"] [unique_id "AcAcAcAcAcAcAcA4DcA7AcAc"]
& M! x  \* X! k' T8 ]9 U, Z解决方法:
! L" G/ o& d! a# ^编辑modsecurity.conf,注释掉默认的SecAuditLogType和SecAuditLog,添加以下内容:
( a$ J$ O* B2 C0 M$ x% ~
, R( p/ O1 k" s& g% n! F5 ]SecAuditLogDirMode 0777
/ g' j( K. F5 X7 G- q$ ?. BSecAuditLogFileMode 0550
1 }2 C9 H/ k$ Y% LSecAuditLogStorageDir /var/log/modsecurity
; _2 m; ]/ F" V" f; I$ l8 zSecAuditLogType Concurrent; ?& V& Z7 Y: m% E
参考文章:# b/ p; ]$ P: M  r
https://github.com/SpiderLabs/ModSecurity/wiki/Reference-Manual#Installation_for_NGINX/ \& a+ G5 S+ F7 m1 g" x
http://drops.wooyun.org/tips/2614
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

QQ|Archiver|手机版|小黑屋|第一站论坛 ( 蜀ICP备06004864号-6 )

GMT+8, 2026-10-7 08:55 , Processed in 0.068265 second(s), 19 queries .

Powered by Discuz! X3.5

© 2001-2026 Discuz! Team.

快速回复 返回顶部 返回列表