找回密码
 立即注册

QQ登录

只需一步,快速开始

查看: 12762|回复: 0

nginx配合modsecurity实现WAF功能

[复制链接]
发表于 2017-10-19 16:53:31 | 显示全部楼层 |阅读模式
modsecurity原本是Apache上的一款开源waf,可以有效的增强web安全性,目前已经支持nginx和IIS,配合nginx的灵活和高效,可以打造成生产级的WAF,是保护和审核web安全的利器。
' \4 V4 p' {& F' r0 p+ P5 C5 o  F* w0 d: M- U; z; T
一.准备工作, U0 Y+ G8 J  z( J6 O- }+ g' J

1 C, N* K  \( M" b" K  x系统:centos 6.5 64位、 tengine 2.1.0, modsecurity 2.8.0
) {) R) R! T( m9 @# \  |' Q! Y1 U" b  v" z) A) f  A
tengine : http://tengine.taobao.org/download/tengine-2.1.0.tar.gz2 m& j, S5 X& b
1 S+ z0 i3 M$ N- D1 D
modsecurity for Nginx: https://www.modsecurity.org/tarball/2.8.0/modsecurity-2.8.0.tar.gz1 B% w9 o- b- `

5 m. h, d8 o0 }OWASP规则集: https://github.com/SpiderLabs/owasp-modsecurity-crs
, {1 A1 K4 |, }7 k$ H: @# Q- U3 C! W/ Q
依赖关系:/ @) f  `: O$ K6 }( q# P
tengine(nginx)依赖: pcre 、zlib、 openssl, 这三个包centos 6.5 系统源里都有:
% P; l6 a' X. \5 Z# o: M
' }8 `' T. l/ ^) Z  ryum install zlib zlib-devel openssl openssl-devel  pcre pcre-devel
+ H6 A9 k' Q! S# \modsecurty依赖的包:pcre httpd-devel libxml2 apr. G' a( Q/ s7 u+ s1 [* \- H9 F- Z
: v/ v: s; }' T: F: M& s
yum install httpd-devel apr apr-util-devel apr-devel  pcre pcre-devel  libxml2 libxml2-devel2 a& P* h$ o4 j% H  i) {
二.启用standalone模块并编译
( }6 Q- U: ]- i: a; T& K5 y5 z2 ?+ K# A/ f# v( q$ n2 r
下载modsecurity for nginx 解压,进入解压后目录执行:& ?2 ^' h/ p) `6 U# Q. ~& M1 }
6 o( ]0 M( ]5 B" u2 w% \
./autogen.sh
0 a" }5 f, F% _8 H* _5 s7 o./configure --enable-standalone-module --disable-mlogc
; }. c" k. J8 @0 gmake
# ]* t8 E( r4 q9 {, Y, W. O2 s三.nginx添加modsecurity模块) [' B# }9 T. j; ~1 i
" r1 M6 C* B  ?6 y: b  m7 j
在编译standalone后,nginx编译时可以通过"--add-module"添加modsecurity模块:+ l# `1 X% g5 h6 a. b
5 E" u6 f/ K) G2 w9 I1 P
./configure --add-module=/root/modsecurity-2.8.0/nginx/modsecurity/  --prefix=/opt/tengine
, W6 |. I6 i. ]& c! D# _! \7 \make && make install
" Z- i/ _% {  x$ W四.添加规则
& N" Q8 _, e: {. V( Z" w( N4 {8 x; i6 Y- F0 e
modsecurity倾向于过滤和阻止web危险,之所以强大就在于规则,OWASP提供的规则是于社区志愿者维护的,被称为核心规则CRS(corerules),规则可靠强大,当然也可以自定义规则来满足各种需求。
; h1 x1 A, \& \% p6 B; F5 i" w5 E
1.下载OWASP规则:
+ L/ s% X( J9 S6 R# t$ I, Q
( f- p5 l/ ?/ G* ^" M4 Hgit clone https://github.com/SpiderLabs/owasp-modsecurity-crs
+ X; K& j& B, I: ~( h% V7 k0 u( ~4 [9 i
4 g( @* I2 q& G* F) B2 Qmv owasp-modsecurity-crs /opt/tengine/conf/
0 A- f/ ~( t  s0 S5 B+ M) i) M$ j' B$ Z! h; ]* V7 d7 K# y/ S8 L- ^! j
cd /opt/tengine/conf/owasp-modsecurity-crs && mv modsecurity_crs_10_setup.conf.example modsecurity_crs_10_setup.conf
$ C0 `4 l, {) w2.启用OWASP规则:# g/ {% v* W- x( W
* d6 I* @. T9 `9 ^2 y( c: v
复制modsecurity源码目录下的modsecurity.conf-recommended和unicode.mapping到nginx的conf目录下,并将modsecurity.conf-recommended重新命名为modsecurity.conf。* v. T  r" Z4 e: _; b' k# R
4 d: {8 g" }, M- @
编辑modsecurity.conf 文件,将SecRuleEngine设置为 on4 _' y0 e0 V. z
4 r& U( h; U& X3 J( S) U
owasp-modsecurity-crs下有很多存放规则的文件夹,例如base_rules、experimental_rules、optional_rules、slr_rules,里面的规则按需要启用,需要启用的规则使用Include进来即可。) J5 H7 T& D4 o$ ?' F5 S
; ^6 D9 n- D1 L) T$ Z* F3 W: i. N* O& R" r
Include owasp-modsecurity-crs/modsecurity_crs_10_setup.conf, O3 u+ H( r, A1 R$ P
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_sql_injection_attacks.conf
3 y% |8 m5 u1 t9 ?. t( D: d. R9 Z  o+ @Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_xss_attacks.conf
6 {+ D6 L9 m  H8 g1 ~Include owasp-modsecurity-crs/base_rules/modsecurity_crs_40_generic_attacks.conf% b' \" w  @2 x; h/ T8 P3 a8 x; L. e
Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_dos_protection.conf0 f9 J7 }" Q2 N7 y( u/ g: b
Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_brute_force.conf5 B- B$ E" J/ c9 l
Include owasp-modsecurity-crs/optional_rules/modsecurity_crs_16_session_hijacking.conf
$ f- b9 G' L8 ?0 K( \9 M6 |: |五.配置nginx  I) P3 D" ~! [) L, v
5 R; g: [5 L7 K- w/ q
在需要启用modsecurity的主机的location下面加入下面两行即可:5 F' n, ~$ X+ ^. X( P3 N' ~

+ u( C3 ?* {. FModSecurityEnabled on;  3 X0 P# ^0 f' O( k# S
ModSecurityConfig modsecurity.conf;1 C, _- J! U. I0 S- G# C
下面是两个示例配置,php虚拟主机:
, b& b* }) R2 O4 U
, r& |0 [9 F( t- @0 ?; Yserver {
# I4 c: r: ?& P      listen      80;
: s+ E; [' B; O# r      server_name 52os.net www.52os.net;! x3 y0 t! P( k6 X9 ]
     0 ?; l1 a9 U: T6 P0 b8 ~8 E
      location ~ \.php$ {1 `" z% R# P0 X$ x
      ModSecurityEnabled on;  * G! f: T0 J! [7 i! L2 ^& j, _1 ^7 c
      ModSecurityConfig modsecurity.conf;
* {+ u- M' ~6 C- l2 n0 g
& B0 O; x" i, m) V      root /web/wordpress;
& {! j* f+ g( x) ~- Y' X; a      index index.php index.html index.htm;
6 o4 X6 S  b. t" j' C  o7 U  ' J& a( d. h3 q- c  @! I, K
      fastcgi_pass   127.0.0.1:9000;, P9 K1 Y0 M% L/ j
      fastcgi_index  index.php;
+ q4 k0 e. P; v$ u( j      fastcgi_param  SCRIPT_FILENAME  $Document_root$fastcgi_script_name;
( ]0 e, [) m& Z      include        fastcgi_params;* X  p* G; n# G- S* Z, Y! `
      }
- }7 D+ J. i6 ^  }
% Y, O3 g8 b% w! c( Eupstream负载均衡:
' u5 X" I: @' u3 o) k) z4 _
" d, `; n, {- c1 P. T2 oupstream 52os.net {
& ]. ]2 j! @& ]" C- W3 H4 x    server 192.168.1.100:8080;+ M7 y! G5 S$ N' L# m
    server 192.168.1.101:8080 backup;' P2 r( J! b  I$ r4 R7 \
}
' o0 N: ~8 t% B/ ?- t, _* f+ }( j3 U2 b4 Q2 g6 k6 p' u1 \& \
server {( x) G8 z# m$ P' |
listen 80;6 U+ W, s3 b7 ?8 n
server_name 52os.net www.52os.net;1 i8 R- l* d7 G( X4 J! h1 O. x& A4 a
0 w+ g  e% o2 o8 n9 }9 r- i
location / {
+ z" q+ B) U. k4 t    ModSecurityEnabled on;  ) H& G! P' |$ ?; i
    ModSecurityConfig modsecurity.conf;  3 p- x, r* r, X" Z" L' p: X' o
% g3 [1 K6 Z: E8 }
        proxy_pass http://online;
. W% l0 h; k* t9 T        proxy_redirect         off;$ G  y7 L  M9 Y: F
        proxy_set_header Host $host;* P. ^" {  y" H/ v4 C/ Q
        proxy_set_header X-Real-IP $remote_addr;3 f2 ~, j, w4 S6 @
        proxy_set_header  X-Forwarded-For $proxy_add_x_forwarded_for;! c4 N9 p: m: @1 K- G. o2 R, q; a' }
    }
( K; \" w3 y. Y' p# u9 h}
% B7 c/ I( P  I' g+ \% T' i六.测试
8 ?8 H# t4 o; J) [! F+ o! s& |# Y  ^2 {  _  }
我们启用了xss和sql注入的过滤,不正常的请求会直接返回403。以php环境为例,新建一个phpinfo.php内容为:
! ^0 L7 B6 |% \: X1 Q/ a
* N: m& F7 \& R! d& n<?php# P! H: ~1 x" F
    phpinfo();   
3 Y- _. e* `5 H9 X. j?>$ x) i8 x4 Z! Z& V. i
在浏览器中访问:
' V% f$ P2 G0 @7 J. J. }+ s$ F
# [8 _% W% H* |# _: m$ _* R. h: e' F4 F& Yhttp://www.52os.net/phpinfo.php?id=1 正常显示。
2 X! u2 Q) u- w& ohttp://www.52os.net/phpinfo.php?id=1 and 1=1  返回403。
0 V/ r. N8 _5 h; Xhttp://www.52os.net/phpinfo.php?search=<scritp>alert('xss');</script>  返回403。
2 ^3 z3 [! K6 ~) Q7 q说明sql注入和xss已经被过滤了6 o7 }2 o4 o( s. Y  Y# V% c. j% \
1 A7 S) L& e: {
七、安装过程中排错
5 M, W" d+ ^  F/ w" w, ?6 a
! H6 l4 E* e6 C6 n1.缺少APXS会报错
/ \* h/ @. K+ W' @
5 m  ^* y' R( E, h& U2 v2 aconfigure: looking for Apache module support via DSO through APXS) g1 Y% a! b4 k+ Z
configure: error: couldn't find APXS, b+ Q$ ?% h2 P# t/ w5 W8 w3 }( @
apxs是一个为Apache HTTP服务器编译和安装扩展模块的工具,用于编译一个或多个源程序或目标代码文件为动态共享对象。
4 C, `, B: k0 J% u3 Q9 I3 b' D解决方法:
) H+ p+ ~7 U" j; \# B' b* U$ w+ m, C  T
yum install httpd-devel
3 N0 s# K% A6 l+ h- P$ Y5 n. ?2.没有pcre
- i# ~1 M: k- t6 p0 g
6 q  D" o; q: y$ s  w% D! }/ econfigure: *** pcre library not found.
) |6 @! t3 d; m5 k" Gconfigure: error: pcre library is required2 N+ T& x! J! i) v! O% |
解决方法:( ~# H# w6 W. h

8 ~5 _9 V3 o4 Gyum install pcre pcre-devel6 J/ Z" |2 {. g
3.没有libxml2/ e# t6 u& c* s# e; T
4 F/ J! u% j8 d$ U; f6 k

1 L4 y0 Q; Y' R/ h: Vconfigure: *** xml library not found.
) o5 q' N! J( C# Q8 fconfigure: error: libxml2 is required, |6 x. Q% [- T5 e' ?0 N
解决方法:
# X% c' W+ k+ w$ j* T! [7 [- O' u+ g% N2 j. L2 M. d2 e
yum install  libxml2 libxml2-devel3 q& j. X3 f* W. e( N
4.执行 /opt/tengine/sbin/nginx -m 时有警告+ y4 I+ E4 ?9 U

: v( m" W" x8 v+ G6 C4 BTengine version: Tengine/2.1.0 (nginx/1.6.2)
$ V  t4 j2 E! e) ^4 n. jnginx: [warn] ModSecurity: Loaded APR do not match with compiled!
: u1 E+ L, k  a& {) g原因:modsecurity编译时和加载时的apr版本不一致造成的,并且会有以下error.log& h' r$ G2 @, u
) T( j! m2 L$ ~$ F
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity for nginx (STABLE)/2.8.0 () configured./ @$ ^: I3 b4 w4 ]: U
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: APR compiled version="1.5.0"; loaded     version="1.3.9"! G7 p2 i) K2 x- U) I+ S
2015/01/26 02:04:18 [warn] 29036#0: ModSecurity: Loaded APR do not match with compiled!
! q$ P1 f; V  t; A7 X8 L2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: PCRE compiled version="7.8 "; loaded version="7.8 2008-09-05"
5 c( p1 [4 c4 x6 f0 }( c- W8 G. S2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: LIBXML compiled version="2.7.6"8 a: Q9 X' D% b) M' @3 S+ R2 d& V; l
2015/01/26 02:04:18 [notice] 29036#0: Status engine is currently disabled, enable it by set SecStatusEngine to On.
" V  k: W3 U" `" I8 ~解决方法,移除低版本的APR (1.3.9)
9 J4 S/ X) C9 |7 W; ]% R- f5 H) c  U% e% O: V+ C5 a
yum remove apr
$ n# y9 X/ O1 R/ j8 N0 F5.Error.log中有: Audit log: Failed to lock global mutex7 ^, u0 F' I' [9 t" R3 \, {

8 `7 {. v9 |& B3 m" g, Z, d7 D2015/01/26 04:15:42 [error] 61610#0: [client 10.11.15.161] ModSecurity: Audit log: Failed to lock     1 H. U5 H$ l: e0 D' I) _# U; y
global mutex: Permission denied [hostname ""] [uri "/i.php"] [unique_id "AcAcAcAcAcAcAcA4DcA7AcAc"]
4 O0 |  w7 h9 L' Y+ z. z# `7 w$ T, o0 A解决方法:4 ^- N5 S% V: \/ Y! @1 l5 F
编辑modsecurity.conf,注释掉默认的SecAuditLogType和SecAuditLog,添加以下内容:$ H2 B# F- ]5 S) P
) Z- _/ m+ L* K, m; x9 u2 p6 A
SecAuditLogDirMode 0777
4 h* \1 c9 l* M( M; ySecAuditLogFileMode 0550
. J% X* K" J! M$ [8 [+ `. wSecAuditLogStorageDir /var/log/modsecurity. _: Y" ~* o, D
SecAuditLogType Concurrent
7 X: G9 ?. s& ], j( k& B参考文章:
' C/ ]' K- }, L6 k5 bhttps://github.com/SpiderLabs/ModSecurity/wiki/Reference-Manual#Installation_for_NGINX
) Q$ j+ n! P+ S0 Vhttp://drops.wooyun.org/tips/2614
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

QQ|Archiver|手机版|小黑屋|第一站论坛 ( 蜀ICP备06004864号-6 )

GMT+8, 2026-10-9 01:28 , Processed in 0.382250 second(s), 19 queries .

Powered by Discuz! X3.5

© 2001-2026 Discuz! Team.

快速回复 返回顶部 返回列表