|
|
modsecurity原本是Apache上的一款开源waf,可以有效的增强web安全性,目前已经支持nginx和IIS,配合nginx的灵活和高效,可以打造成生产级的WAF,是保护和审核web安全的利器。& P: I3 ~7 I t8 u2 [: w
0 K+ H4 t; R5 k5 @: U& Z一.准备工作/ G1 y) j$ n& y2 a
1 J. G# V+ N7 N0 r( _5 Q
系统:centos 6.5 64位、 tengine 2.1.0, modsecurity 2.8.0
# e# T( |7 |$ S( Y, `
2 K$ `5 j9 W% v; U& [tengine : http://tengine.taobao.org/download/tengine-2.1.0.tar.gz V* l( D* Z; ]/ B1 p
: y# c6 N! o0 xmodsecurity for Nginx: https://www.modsecurity.org/tarball/2.8.0/modsecurity-2.8.0.tar.gz% n1 Y. _; s4 c- `6 R
4 O" o' s2 c4 m* b# VOWASP规则集: https://github.com/SpiderLabs/owasp-modsecurity-crs
0 N8 V4 P, t, u
; [# R( u, A' R/ ?# m6 c5 f依赖关系:6 F8 H2 o9 i! e Q6 N& O
tengine(nginx)依赖: pcre 、zlib、 openssl, 这三个包centos 6.5 系统源里都有:
! c) u( I, C+ u2 w! I- j9 ?
- _+ E; ~/ c9 a! V; a. B) yyum install zlib zlib-devel openssl openssl-devel pcre pcre-devel
' O3 ~2 H* K' l! O6 S- F# Z: I# ymodsecurty依赖的包:pcre httpd-devel libxml2 apr5 r: ~$ ]# X6 ~- ?/ m% P
* Y, H: c6 j, e1 o! L3 t: z: U
yum install httpd-devel apr apr-util-devel apr-devel pcre pcre-devel libxml2 libxml2-devel8 ^7 J6 O9 t9 y" l4 b+ P
二.启用standalone模块并编译2 Z6 ], j2 x2 e0 @
( B( k( ?1 U' B: w下载modsecurity for nginx 解压,进入解压后目录执行:; P0 ] a# V; I7 F7 R) {. O
, ]6 s4 o; z+ t./autogen.sh3 {1 l# X* @) z
./configure --enable-standalone-module --disable-mlogc
7 s9 _1 H7 ?# X2 x) {8 Nmake N: e( O" \' i1 j8 Z
三.nginx添加modsecurity模块# J9 @) Q8 G; G; Y% a# H9 ^3 [
+ p+ B# k0 h r$ Q
在编译standalone后,nginx编译时可以通过"--add-module"添加modsecurity模块:
- N5 @; L) ], T: `: o' ~
a! f% Z/ v, i9 z, ^( H0 n; l./configure --add-module=/root/modsecurity-2.8.0/nginx/modsecurity/ --prefix=/opt/tengine
* _0 j' A, r$ S! m( V- V6 C0 a1 Omake && make install
5 X; l* \% N; r4 B: @& y0 A' U四.添加规则
+ [0 \% \1 v. i# [/ o) z2 e. p" P" {% ^: e
modsecurity倾向于过滤和阻止web危险,之所以强大就在于规则,OWASP提供的规则是于社区志愿者维护的,被称为核心规则CRS(corerules),规则可靠强大,当然也可以自定义规则来满足各种需求。% s Y- k- V( y
/ v9 x, @& ]* W. `5 ]% ^9 w" u
1.下载OWASP规则:( O0 F4 n' H0 F9 `' F
7 ^+ ~; a2 v: k: C) s6 \
git clone https://github.com/SpiderLabs/owasp-modsecurity-crs9 n- ~/ T' M7 F. h' ?2 [* t; `9 o( _
" P1 _+ u9 l0 O& H ~mv owasp-modsecurity-crs /opt/tengine/conf/
& a. T( n7 P1 s, q2 C0 c* Z
5 g" S: _2 _$ bcd /opt/tengine/conf/owasp-modsecurity-crs && mv modsecurity_crs_10_setup.conf.example modsecurity_crs_10_setup.conf
) Z+ C7 v4 t; a% z2.启用OWASP规则:1 [9 \3 ^* S4 ^ B
0 w1 J. Y" \1 s- @复制modsecurity源码目录下的modsecurity.conf-recommended和unicode.mapping到nginx的conf目录下,并将modsecurity.conf-recommended重新命名为modsecurity.conf。
8 }. ?7 P) U& J& ]7 T$ |
6 s* ~. j( {) P5 B! s% Y6 L, [编辑modsecurity.conf 文件,将SecRuleEngine设置为 on4 M7 v1 ]# z; Z+ x- I4 r0 N) f, I
8 a8 ^$ x3 K; Y3 |: {
owasp-modsecurity-crs下有很多存放规则的文件夹,例如base_rules、experimental_rules、optional_rules、slr_rules,里面的规则按需要启用,需要启用的规则使用Include进来即可。
/ S" d. K- R: k8 \2 \
7 j R3 ~/ R; N5 w2 l& {7 uInclude owasp-modsecurity-crs/modsecurity_crs_10_setup.conf; X5 p9 n$ L) w& M+ X! x. T3 f
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_sql_injection_attacks.conf
Y# r1 C* ~! o7 TInclude owasp-modsecurity-crs/base_rules/modsecurity_crs_41_xss_attacks.conf0 Y% N/ ]& \. @& J x, r
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_40_generic_attacks.conf5 a: V$ M/ \3 [2 w$ _' F5 h7 r1 T
Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_dos_protection.conf
, E- W( F D) g" WInclude owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_brute_force.conf! \2 }7 `5 e4 E) V
Include owasp-modsecurity-crs/optional_rules/modsecurity_crs_16_session_hijacking.conf
6 D( c, B- d! N. r2 d% C8 ]五.配置nginx. H6 x: e) O" k- n3 {5 m) D) p
* d: G# t) p6 a, k7 F$ N( [
在需要启用modsecurity的主机的location下面加入下面两行即可:
F7 g" A" C! S, ~5 t0 R, M* E" l& E. k, `" G4 ?
ModSecurityEnabled on;
+ H. ]: h3 j9 IModSecurityConfig modsecurity.conf;
" z! Z3 X% R6 j0 X, f( ]" s4 Y9 \" }3 X下面是两个示例配置,php虚拟主机:
# L+ Y# b* {! m3 u! B' X7 Y6 E
- z5 ^7 @5 k3 p$ b kserver {
- k4 p5 d4 U7 m6 {2 k listen 80;/ A3 R4 ^3 F) p3 ?8 Y
server_name 52os.net www.52os.net;
; a; K' N" ]- f5 A# Y, N
' z3 H1 ]8 h# E8 k a4 U {' Y location ~ \.php$ {
7 Z: _ z7 r, g1 o; G ModSecurityEnabled on; 4 a; L0 |$ f4 Q0 y+ q" G6 |4 b
ModSecurityConfig modsecurity.conf;
* D3 \$ i: \6 u- l2 C9 r
1 u6 o- c0 v, V! y! t' x6 x, }2 V root /web/wordpress;2 j! `. h/ E! a3 H1 F- P0 x! x* F8 u
index index.php index.html index.htm;9 g% a9 r" }0 U1 f8 H! |
& V# Y& M9 C# V; N
fastcgi_pass 127.0.0.1:9000;5 b8 P+ Y. h1 P. N5 T; S& {
fastcgi_index index.php;& T* s7 i8 f0 g$ ?
fastcgi_param SCRIPT_FILENAME $Document_root$fastcgi_script_name;
) i! n: X. U- r+ v p include fastcgi_params;9 j9 A2 U8 Y% x' B! ~
}& P% B$ k8 `0 j: H( u' u
}
3 c1 K, Y5 P& I7 F/ A/ X- n- E/ ^" Vupstream负载均衡:
; p) }5 q1 g( L) J9 ?6 b5 D1 n) t- d8 n2 F. A8 }6 D3 d
upstream 52os.net {
/ T1 h& J' V8 C7 c server 192.168.1.100:8080;
2 u- ]( R5 I. Q$ S server 192.168.1.101:8080 backup;
1 ~$ a) ^, R, g" k# G3 u}
! Q7 N* y% w- L6 C/ H1 q7 j2 R9 D+ D) i
server {
( P5 R! E+ z0 ^2 F Hlisten 80;
# S* X. x2 C( P0 Cserver_name 52os.net www.52os.net;2 ^+ x( r, F5 H% l
' Q$ m% g2 C1 s5 W# Alocation / {0 C8 L& [( K( R' {' n5 R0 c
ModSecurityEnabled on; ( _5 J5 N, A5 k* T7 L
ModSecurityConfig modsecurity.conf;
" m* [$ l3 p3 ?8 P
! |4 r* ^: C/ B, ?* l; V! t proxy_pass http://online;! D8 u! T* ~! I; Y' Z
proxy_redirect off; r4 P4 f) ~( d+ y: Y6 b
proxy_set_header Host $host;
( p/ N/ Y4 z% D0 K }7 L proxy_set_header X-Real-IP $remote_addr;
. q4 W; W4 Q( s3 [- t* \ proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;! u" y* {/ A# e3 o: c
}, M& l7 Q5 b. Q" F( J
}6 c. J- Q% k- t
六.测试6 s! N) y- ^" L6 p. G2 U
- X. \$ @5 G: [% ]! E3 f. d% o我们启用了xss和sql注入的过滤,不正常的请求会直接返回403。以php环境为例,新建一个phpinfo.php内容为:+ P8 L& W2 _5 p+ U+ h
7 o% X4 I1 V+ g1 K X* E
<?php; G# W$ U9 {. G% E- s: L9 L
phpinfo();
4 [, K. c1 A" e5 V$ v?>
: f- Z( A |4 I) |) v" M在浏览器中访问:3 ]7 h8 f# B0 Y" F
: u' e/ M0 N# w; Z
http://www.52os.net/phpinfo.php?id=1 正常显示。
9 N9 G% D/ m/ P. f! Phttp://www.52os.net/phpinfo.php?id=1 and 1=1 返回403。6 F: V; i) j+ f# G/ _4 x" G( p* P
http://www.52os.net/phpinfo.php?search=<scritp>alert('xss');</script> 返回403。8 i7 f* e& C+ i
说明sql注入和xss已经被过滤了 W; ]/ Z+ [) h1 O4 w2 l/ c o
- ?( e5 \8 R+ Z9 F( n( U( n* j4 T
七、安装过程中排错! o- ?1 g( f9 F( n
, ?* [: k$ r# Q0 ?+ T1.缺少APXS会报错% x8 _! G/ C1 M; a I, `
2 E7 }; F1 n+ s, O
configure: looking for Apache module support via DSO through APXS6 b- ^" H: I8 A) @0 A/ p
configure: error: couldn't find APXS% @, V5 f J# T7 G; a, I" T
apxs是一个为Apache HTTP服务器编译和安装扩展模块的工具,用于编译一个或多个源程序或目标代码文件为动态共享对象。
! V B1 v, z7 Z' k* |7 G解决方法:# r' t- e" q* |; z( ~7 c6 i+ e1 S
1 x+ s5 J% ]9 y6 Y, Yyum install httpd-devel
% e% }8 T% G- e7 m. \2.没有pcre# Y' I* i& B% T: i; z' S8 x6 ^
8 r8 @4 b3 |9 l% I* kconfigure: *** pcre library not found./ W6 n0 r( H9 O C- s1 W" b
configure: error: pcre library is required
2 k/ \: u- I+ a- w: d解决方法:3 I0 G1 D' C3 l: a
% M3 i* b5 ]! gyum install pcre pcre-devel9 f1 X+ v$ h* H9 f, Z: H$ H) C
3.没有libxml2
0 w8 a7 [( r' F' K% y: E* M0 c2 S. h7 |3 P+ \
" o- X7 Y! Z% e) C
configure: *** xml library not found.
0 W. a8 ]4 ~" n+ p; |* [/ fconfigure: error: libxml2 is required. ~, A9 r( k y% {2 o9 p1 M8 f
解决方法:1 ]6 }& P: H2 E1 r
$ q* `& w1 g6 Y/ [/ @! U3 Zyum install libxml2 libxml2-devel
) V) Z7 z) G6 I0 i! m4.执行 /opt/tengine/sbin/nginx -m 时有警告8 L& ^4 o/ @% g, Y: z
" ^$ ^- ?. ^3 K0 T# A8 y0 @4 C# a) pTengine version: Tengine/2.1.0 (nginx/1.6.2)4 y! F& {- Y: z8 |; T
nginx: [warn] ModSecurity: Loaded APR do not match with compiled!3 @, Z) s; R. v: @2 F
原因:modsecurity编译时和加载时的apr版本不一致造成的,并且会有以下error.log
5 n' h7 l5 ^2 E3 l/ ]
. l; }" g8 W G Y2 v& v* T2015/01/26 02:04:18 [notice] 29036#0: ModSecurity for nginx (STABLE)/2.8.0 () configured.9 H" Z5 L8 F: _. [
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: APR compiled version="1.5.0"; loaded version="1.3.9"
$ x; | G) H1 a) w8 o& R2015/01/26 02:04:18 [warn] 29036#0: ModSecurity: Loaded APR do not match with compiled!
5 j* r2 }' N" w9 W3 w2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: PCRE compiled version="7.8 "; loaded version="7.8 2008-09-05"6 f) X& a% {% ~8 g1 k
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: LIBXML compiled version="2.7.6"' |4 z( k* r0 V% e7 q# |
2015/01/26 02:04:18 [notice] 29036#0: Status engine is currently disabled, enable it by set SecStatusEngine to On.
- T( Q/ j: j- \1 y7 y! p, }* E# t解决方法,移除低版本的APR (1.3.9)+ C' J& D& r) b/ R7 J9 N- t( [
3 y, k: D* }0 I
yum remove apr5 T- V" A, m. a" D8 p% C) n
5.Error.log中有: Audit log: Failed to lock global mutex
$ u' J; c- F) k7 {2 V8 G# [9 i% ]4 y+ a
2015/01/26 04:15:42 [error] 61610#0: [client 10.11.15.161] ModSecurity: Audit log: Failed to lock
/ w- t: k1 m5 h/ N6 U; tglobal mutex: Permission denied [hostname ""] [uri "/i.php"] [unique_id "AcAcAcAcAcAcAcA4DcA7AcAc"]0 {4 w( s- E' M# b6 _
解决方法:
2 F- a9 w: M. _7 _. B编辑modsecurity.conf,注释掉默认的SecAuditLogType和SecAuditLog,添加以下内容:# v* S1 l8 r5 o& `. J
+ f% V' P9 v: `1 c
SecAuditLogDirMode 0777
f, V. n) M9 [' F$ b$ g8 M6 X5 mSecAuditLogFileMode 0550
( ?& M* T# I. E# i6 fSecAuditLogStorageDir /var/log/modsecurity
9 g0 h- k9 x. {( x# `SecAuditLogType Concurrent
: Q b: _& y4 q+ F1 V参考文章:9 g! q, V1 m' c+ r: [ V. u
https://github.com/SpiderLabs/ModSecurity/wiki/Reference-Manual#Installation_for_NGINX6 U) c7 a+ \$ V9 p/ I
http://drops.wooyun.org/tips/2614 |
|