|
|
modsecurity原本是Apache上的一款开源waf,可以有效的增强web安全性,目前已经支持nginx和IIS,配合nginx的灵活和高效,可以打造成生产级的WAF,是保护和审核web安全的利器。
& M) }8 E; {4 I4 ]3 e- z t4 |& ], V% E r6 S2 \
一.准备工作
& z5 A9 g1 V7 f. [; U7 \6 y8 P3 ] {" x0 m: c9 O( |" e
系统:centos 6.5 64位、 tengine 2.1.0, modsecurity 2.8.0
; [, O4 z* l9 ?# r5 o1 R7 `# I) Y, e; |/ q7 I( i! B, o
tengine : http://tengine.taobao.org/download/tengine-2.1.0.tar.gz
7 R$ i+ M0 }& x5 F+ ?* x
7 e% E& \4 l" L/ m( N1 Wmodsecurity for Nginx: https://www.modsecurity.org/tarball/2.8.0/modsecurity-2.8.0.tar.gz- N {) f) [' S9 T) w
0 x2 L; l+ ~$ V+ n7 R$ KOWASP规则集: https://github.com/SpiderLabs/owasp-modsecurity-crs5 S3 j0 t3 Y1 p2 [% A9 u
6 `/ z' Q. f1 V; q. {
依赖关系:; p/ d2 x; v* j) l: Q+ i) @7 g
tengine(nginx)依赖: pcre 、zlib、 openssl, 这三个包centos 6.5 系统源里都有:" T5 [5 y0 }! l3 o; c3 v
+ w7 W! n$ n, ^: |9 i/ |4 c2 f
yum install zlib zlib-devel openssl openssl-devel pcre pcre-devel
2 J4 y; m2 ?, N: f- O6 y, ~5 ~modsecurty依赖的包:pcre httpd-devel libxml2 apr
8 o$ S; l1 s2 o3 G7 R7 i# N, [
' o8 `9 g3 r5 a s8 \0 F; t, ~( r* Cyum install httpd-devel apr apr-util-devel apr-devel pcre pcre-devel libxml2 libxml2-devel
/ H; I1 r! J1 I, |7 b4 P二.启用standalone模块并编译( j. H0 H" f4 O, Z
R0 s0 c3 l/ @8 x. j9 V- t
下载modsecurity for nginx 解压,进入解压后目录执行:7 R, |3 P' H! J
6 W" d0 q1 T7 g' o" T: g' M9 z./autogen.sh
. W& Q7 p7 T) o7 \% v./configure --enable-standalone-module --disable-mlogc/ N5 ?& m' F/ d% J o9 N# [
make 6 f3 a7 S. `4 E' _1 J1 D K
三.nginx添加modsecurity模块
, V' N; |. K& Q9 O3 r6 U4 q* n% C8 u, T* n' o: _+ T
在编译standalone后,nginx编译时可以通过"--add-module"添加modsecurity模块:) Z, g, y" t& `1 K" v
, k, {5 u% Y; L- X./configure --add-module=/root/modsecurity-2.8.0/nginx/modsecurity/ --prefix=/opt/tengine# ~; e8 K5 Y: q2 X# B7 u
make && make install
$ R- ?, n1 a3 N/ o( _5 n4 |4 `四.添加规则
$ t! n$ e" G: a( H
; }- `' e) b2 x( s- Amodsecurity倾向于过滤和阻止web危险,之所以强大就在于规则,OWASP提供的规则是于社区志愿者维护的,被称为核心规则CRS(corerules),规则可靠强大,当然也可以自定义规则来满足各种需求。& s# L! d4 V' b! K0 \% W
1 X! C* X4 j) O" a1.下载OWASP规则:3 s6 z9 p5 P% f1 y2 S0 n
7 F( d" V4 B( A/ H( T2 [' t6 N
git clone https://github.com/SpiderLabs/owasp-modsecurity-crs/ A# J' I( k$ t) E/ j/ k
7 j+ I% ]2 o: j, G5 J, r" }; l
mv owasp-modsecurity-crs /opt/tengine/conf/* h# I% Q; n$ ]8 p5 Y
+ [! u' ]2 ]* g6 H6 P$ j Y" X% wcd /opt/tengine/conf/owasp-modsecurity-crs && mv modsecurity_crs_10_setup.conf.example modsecurity_crs_10_setup.conf
4 X9 G3 R4 s. O. ~& y% q h5 k/ S& p2.启用OWASP规则:
) i+ N+ a8 q) d% O! t" @& A& n9 V: y& t. L
复制modsecurity源码目录下的modsecurity.conf-recommended和unicode.mapping到nginx的conf目录下,并将modsecurity.conf-recommended重新命名为modsecurity.conf。) m2 p9 B1 I! ? t9 p4 ~5 e
# E3 K5 F; v# ^( T+ j& O
编辑modsecurity.conf 文件,将SecRuleEngine设置为 on: X' K1 U4 d0 ?* B0 h# M. t) M
8 U# r d2 ?+ A& X+ ? \ Bowasp-modsecurity-crs下有很多存放规则的文件夹,例如base_rules、experimental_rules、optional_rules、slr_rules,里面的规则按需要启用,需要启用的规则使用Include进来即可。
5 H* L& i: v* \- Y/ }9 A
8 p5 e8 M3 s0 Z7 KInclude owasp-modsecurity-crs/modsecurity_crs_10_setup.conf% j+ _" U; K3 F) J+ N
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_sql_injection_attacks.conf
/ S4 d4 X. v7 [" H; q3 x6 I. M& YInclude owasp-modsecurity-crs/base_rules/modsecurity_crs_41_xss_attacks.conf5 U, |& F2 `# _" N$ Y# G4 ~) C
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_40_generic_attacks.conf5 L6 \* A( f \
Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_dos_protection.conf7 n, a9 C- t. K8 d2 f
Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_brute_force.conf2 U# O) u6 Y' n. ~
Include owasp-modsecurity-crs/optional_rules/modsecurity_crs_16_session_hijacking.conf
: n" w, J& L3 `五.配置nginx
1 o7 U @4 p7 z5 z# q. H$ `. z' Y
, S9 I" g* v* ?8 X$ C" n在需要启用modsecurity的主机的location下面加入下面两行即可:9 ^6 u; V7 S3 @) Y
4 v! e- k2 h( D& {! k; A$ VModSecurityEnabled on;
4 X: D. e9 s3 E9 l5 s: u9 |1 AModSecurityConfig modsecurity.conf;
% ~9 Y. B }7 v. d" d# A+ `- J1 w下面是两个示例配置,php虚拟主机:
5 _; U: R8 [/ `, E% V
$ J5 |2 U! Z& `# H) Eserver {1 w |1 h. N1 j
listen 80;
; C& [! x6 h% q2 r7 @2 j5 w server_name 52os.net www.52os.net;
+ ~4 R* w6 H1 J) W" B4 y, J
B7 L# O; u- I9 k8 n* Z. T7 Z location ~ \.php$ {
! A+ }$ F- w5 f8 O ModSecurityEnabled on; # V" b5 h8 H \1 T+ d& h2 o
ModSecurityConfig modsecurity.conf;
1 f* s3 \2 d* `3 f3 T2 n. |. [% c9 K$ C0 c/ a4 Z2 D0 m
root /web/wordpress;
q0 h- C$ F' U9 S# N1 G8 `/ Z7 a index index.php index.html index.htm;
- V, i* w6 Z0 `. Z
6 s5 m5 Q. {* T; ^9 r" O0 k5 Y: x fastcgi_pass 127.0.0.1:9000;
6 p+ }3 g) M3 [, c fastcgi_index index.php;
! Z0 @5 T1 a! ]+ G4 P5 ` fastcgi_param SCRIPT_FILENAME $Document_root$fastcgi_script_name;
; U9 @+ h% ?* d# R include fastcgi_params;
2 W: J& r2 |5 y' ?: m4 d; A1 \" d# [ }# |" L6 [& ^- R) C3 Z; x' x. N; A o
}
+ Z' ]* T8 N5 q7 a" ~3 M( e5 Mupstream负载均衡:9 y; ^. X" O- J1 w9 y' o1 D
, G9 j) Y3 Y; `+ Q4 uupstream 52os.net {+ d7 L( q4 A4 C% T0 O' P
server 192.168.1.100:8080;
. L& D3 {/ B3 }9 Z server 192.168.1.101:8080 backup;7 a6 Q6 u/ g) `5 F( B' f
}
) c; H% c% e0 K! Q; `0 W9 n+ x9 e
server {" L E! X8 i1 [4 }; z: ~2 e
listen 80;5 a* b! X/ |; ` Q! @; R/ C5 q: w' w
server_name 52os.net www.52os.net;7 s1 t6 S, J1 D4 _+ k+ ^
' N; ]3 b t+ P2 Dlocation / {
8 n5 a% f+ G8 c, w ModSecurityEnabled on;
! g- [) A- P7 i& U3 J: N) P5 n' T ModSecurityConfig modsecurity.conf; + P2 m$ K& D; @0 h9 Z2 j
) v$ [7 N, S7 F proxy_pass http://online;9 A1 L# j) [& I2 F/ h6 I
proxy_redirect off;
$ k6 j8 \" e, X! @ proxy_set_header Host $host;9 \5 S9 k& h, \1 \' |) W; D1 b7 y
proxy_set_header X-Real-IP $remote_addr;5 h; c1 x: h0 |( j
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
% q4 j. a" v8 d p' g }
s& R- [! r( j; F+ F}$ Z: x! ?' o- a# U+ n% u
六.测试
: i& |: A$ {2 h( n% K* t' B( M. d; } `0 G% G
我们启用了xss和sql注入的过滤,不正常的请求会直接返回403。以php环境为例,新建一个phpinfo.php内容为:
4 ?1 F' L+ I3 U) d. |2 C2 Y0 c2 n; Z1 j7 t
<?php6 n7 Q' h5 N3 J$ c6 [6 v* d
phpinfo();
3 d# C1 x! Y$ O?>1 L: `% U) B5 T" x
在浏览器中访问:
5 k4 Q% p$ A4 F4 y* K
# [8 G* u& U7 d: x; q% @8 R9 ]http://www.52os.net/phpinfo.php?id=1 正常显示。
7 i9 b3 x k% Q! r( R' S' Shttp://www.52os.net/phpinfo.php?id=1 and 1=1 返回403。
2 H" R) Z1 B2 S% Bhttp://www.52os.net/phpinfo.php?search=<scritp>alert('xss');</script> 返回403。
- @) G9 | |- h$ i& a3 A% f说明sql注入和xss已经被过滤了
7 A( @+ T6 C# G
. k4 c( S4 k w! R2 I& z6 w七、安装过程中排错
: k6 Z+ L: R5 F' v, N/ j3 z$ Y- v' Z1 C! k. g" A" k+ U+ ?
1.缺少APXS会报错& [- N0 \9 |# W- x/ d8 ~$ ~
' G: B2 l0 p2 ?& bconfigure: looking for Apache module support via DSO through APXS Q$ x! _9 Q5 D" I
configure: error: couldn't find APXS" m. i: q/ Z# ]* I9 ]$ ?8 k- X/ l
apxs是一个为Apache HTTP服务器编译和安装扩展模块的工具,用于编译一个或多个源程序或目标代码文件为动态共享对象。
' h, G5 t" P, Y; F) A解决方法:* W/ N6 z; _4 B4 v9 k$ f! o
3 r5 n5 K) y6 [& b6 \1 h( }& L
yum install httpd-devel" a; F; ]! l: Q( N: t) X
2.没有pcre( F; a1 G- m0 |" r1 U
7 Q% ?) `. E" i% N4 bconfigure: *** pcre library not found./ ]/ t Y8 D8 E6 A! S/ g8 a* b% V
configure: error: pcre library is required3 p- f6 y6 j3 ^3 K
解决方法:. T% K) \. |4 O' c, J9 X* U0 r Y6 w/ j
]" d! \" y5 m5 _$ x2 }/ dyum install pcre pcre-devel
& ^# M5 R8 h7 A3 o3.没有libxml2
1 }! o# W8 @4 u( S
* G& U- C- `- H p& n* Q3 N: g: w2 ?$ j2 g. Z- ^ H! u: f4 G
configure: *** xml library not found.$ t$ n$ v- w2 P# x2 U
configure: error: libxml2 is required. H: @2 s w- z3 k
解决方法:
: q0 {( } a6 W( y4 s% [! z
~+ n% P Q4 J8 y2 K1 a7 gyum install libxml2 libxml2-devel3 Q6 K* A/ S& I$ u' F
4.执行 /opt/tengine/sbin/nginx -m 时有警告# N7 N" m C) t' H9 d
8 p: c6 K- h; k- S: S! m+ ]
Tengine version: Tengine/2.1.0 (nginx/1.6.2)
" r- v9 [- F5 R' J* U+ qnginx: [warn] ModSecurity: Loaded APR do not match with compiled!& t8 M3 @3 M1 s
原因:modsecurity编译时和加载时的apr版本不一致造成的,并且会有以下error.log
2 Q) N# X# i! o* L# k* b- ^9 T
% O6 Z' c& | a! Q2015/01/26 02:04:18 [notice] 29036#0: ModSecurity for nginx (STABLE)/2.8.0 () configured.
" ]8 o3 W5 a: R* ^* m& W$ z2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: APR compiled version="1.5.0"; loaded version="1.3.9"
/ X6 x- D& O6 D' A$ a& C+ z2015/01/26 02:04:18 [warn] 29036#0: ModSecurity: Loaded APR do not match with compiled!
' s- P# d$ x$ Q# u5 ~8 `2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: PCRE compiled version="7.8 "; loaded version="7.8 2008-09-05"
% N' A) a/ I( O3 k+ y2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: LIBXML compiled version="2.7.6"$ T! s# b# k7 b; I: P3 @- v# v. t
2015/01/26 02:04:18 [notice] 29036#0: Status engine is currently disabled, enable it by set SecStatusEngine to On.& S5 A4 P% F! I1 C
解决方法,移除低版本的APR (1.3.9)
, R! O+ R: N& |" i0 P/ o6 e
1 Q) [# R; W6 }5 ?$ C" p' }6 Ryum remove apr/ u6 M/ ?: J+ Y* k- e6 \4 m! o( T
5.Error.log中有: Audit log: Failed to lock global mutex. H& P; {: m5 h* _7 i! ?. w
7 @& b( n5 S4 M1 |& [. R2015/01/26 04:15:42 [error] 61610#0: [client 10.11.15.161] ModSecurity: Audit log: Failed to lock
/ Y) R. Y" a- m/ D# [& w& A% [ Bglobal mutex: Permission denied [hostname ""] [uri "/i.php"] [unique_id "AcAcAcAcAcAcAcA4DcA7AcAc"]4 o# |+ h4 j2 t, B$ b4 }7 [
解决方法:
]( ~$ r# L1 ^/ C2 d. X4 G编辑modsecurity.conf,注释掉默认的SecAuditLogType和SecAuditLog,添加以下内容:
- s* J2 [7 R* q0 j* a! C; s2 K/ C4 f) G# _- H& g: n4 U) K5 K/ ]
SecAuditLogDirMode 0777$ `0 C6 o% O6 K; y
SecAuditLogFileMode 05506 \0 d& }! X3 R% m
SecAuditLogStorageDir /var/log/modsecurity
/ Y X" K$ S1 [; b+ n3 cSecAuditLogType Concurrent/ P% }8 E# U; m' u# @
参考文章:
5 A" k. l: K. ohttps://github.com/SpiderLabs/ModSecurity/wiki/Reference-Manual#Installation_for_NGINX! m6 R1 U) r* o# @* N" O
http://drops.wooyun.org/tips/2614 |
|