|
|
modsecurity原本是Apache上的一款开源waf,可以有效的增强web安全性,目前已经支持nginx和IIS,配合nginx的灵活和高效,可以打造成生产级的WAF,是保护和审核web安全的利器。
9 Z, a3 W( R9 C. e- h. t
7 y" ?% h+ s4 e/ g一.准备工作
- P) \5 y+ N2 T5 c
9 M9 E6 e* H5 ~0 h' Z3 |. @系统:centos 6.5 64位、 tengine 2.1.0, modsecurity 2.8.0
4 |+ S; z4 z5 S/ \
$ n& g+ H( T% s0 B' Utengine : http://tengine.taobao.org/download/tengine-2.1.0.tar.gz
; Q2 p$ Q6 x# L4 ~* F
* k* N1 _+ k$ ~) Q: p, r! Emodsecurity for Nginx: https://www.modsecurity.org/tarball/2.8.0/modsecurity-2.8.0.tar.gz7 g# M; N( Y. X4 m+ v* ~
$ X: \6 I3 r6 r& K8 K4 vOWASP规则集: https://github.com/SpiderLabs/owasp-modsecurity-crs% B: D$ R: k: n2 O1 w
& Z5 z$ E1 B; N6 N$ e8 ~' Z8 C依赖关系:4 ~+ e# c+ _! Q, \) ]
tengine(nginx)依赖: pcre 、zlib、 openssl, 这三个包centos 6.5 系统源里都有:
% l4 x. D: X) i6 e$ l1 i+ B: Z! l6 C
- b8 w7 M& k4 d0 o% @) Uyum install zlib zlib-devel openssl openssl-devel pcre pcre-devel/ L2 z P7 E2 j( L& j
modsecurty依赖的包:pcre httpd-devel libxml2 apr
$ k6 G1 f2 S! N5 `4 v0 e* o+ E {- h
yum install httpd-devel apr apr-util-devel apr-devel pcre pcre-devel libxml2 libxml2-devel# D! _$ _6 l/ a
二.启用standalone模块并编译' w) s" T# T. u& ]4 A* `
. _0 Q( G# N. I, a+ Y; O; B
下载modsecurity for nginx 解压,进入解压后目录执行:! Y! w. I a" S. c/ A" n
6 j. N6 O( n: x9 }9 \4 @& ?/ R
./autogen.sh
" p1 w9 j' x6 n% K% R. k./configure --enable-standalone-module --disable-mlogc
+ L3 p5 B g6 S: r/ j, J7 a) smake
- R) R' I- p: Q4 }& `$ q) S三.nginx添加modsecurity模块6 \1 N P) ] S& B8 @& g
3 N: u* ~! I* i. L: Z" Q
在编译standalone后,nginx编译时可以通过"--add-module"添加modsecurity模块:$ W) a& V- r4 x/ l4 N; w
E7 y# y6 ?7 z1 X./configure --add-module=/root/modsecurity-2.8.0/nginx/modsecurity/ --prefix=/opt/tengine" Q' f2 o2 A. K, G( F- L
make && make install7 b# `4 Q. p8 b1 L7 T4 ?9 }, O& `
四.添加规则# h u% |; u/ [; q0 d8 S8 v
, y; b" G# b [. lmodsecurity倾向于过滤和阻止web危险,之所以强大就在于规则,OWASP提供的规则是于社区志愿者维护的,被称为核心规则CRS(corerules),规则可靠强大,当然也可以自定义规则来满足各种需求。& j7 o! j1 v/ c0 g9 \: d4 c
, B- ^3 M: I3 o6 k( X: D7 E% H1.下载OWASP规则:9 d4 X, R ~& M
6 q3 P! T3 D0 \1 X# Jgit clone https://github.com/SpiderLabs/owasp-modsecurity-crs) A- [- n4 {1 S7 a( I: t4 P
y+ h1 c5 [: J N
mv owasp-modsecurity-crs /opt/tengine/conf/# ~1 ~2 Z8 h# M9 [+ K, x. B
( c5 m. D( L$ q- t! \cd /opt/tengine/conf/owasp-modsecurity-crs && mv modsecurity_crs_10_setup.conf.example modsecurity_crs_10_setup.conf8 ^- o% n8 x1 p% W4 l$ U' u8 z' m5 r# W
2.启用OWASP规则:8 K; l- x0 C! h+ Q1 l$ E' v
8 l+ w* i3 y# |! j* d5 G" q复制modsecurity源码目录下的modsecurity.conf-recommended和unicode.mapping到nginx的conf目录下,并将modsecurity.conf-recommended重新命名为modsecurity.conf。; r6 {# F M' a
8 s' {$ Q5 [) b- A
编辑modsecurity.conf 文件,将SecRuleEngine设置为 on3 K+ C6 C: A6 |1 a p/ G
: a/ {5 ? }- Uowasp-modsecurity-crs下有很多存放规则的文件夹,例如base_rules、experimental_rules、optional_rules、slr_rules,里面的规则按需要启用,需要启用的规则使用Include进来即可。
, O+ c# c& w- t K' ? l( X3 y- u' z: C: B' d! `
Include owasp-modsecurity-crs/modsecurity_crs_10_setup.conf- y9 g1 R2 C: N" V- h- {
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_sql_injection_attacks.conf
+ g r3 M- v# _& z1 h" Q8 f+ Y- GInclude owasp-modsecurity-crs/base_rules/modsecurity_crs_41_xss_attacks.conf
7 G6 }8 n& D- KInclude owasp-modsecurity-crs/base_rules/modsecurity_crs_40_generic_attacks.conf, G# s& f$ Z8 V- x' q
Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_dos_protection.conf5 n1 ]; r6 l+ n0 h2 A0 N
Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_brute_force.conf
$ {1 r: o; p, c% [7 G0 ]8 L, qInclude owasp-modsecurity-crs/optional_rules/modsecurity_crs_16_session_hijacking.conf. d# B: @& B' }8 @
五.配置nginx, c% u, P0 ^3 ^3 e# u
? V' `2 d, U在需要启用modsecurity的主机的location下面加入下面两行即可:
6 e }, d, e6 u5 I; g0 ~' W6 ^8 v: }# x- }( }1 R! f
ModSecurityEnabled on;
S, R7 W# l1 i2 H; c) uModSecurityConfig modsecurity.conf;5 V- ^& [, a% C3 \( n
下面是两个示例配置,php虚拟主机:
% d* N& I, P; R
- ~) c8 A# F* Cserver {; o4 y+ B& _* O4 |
listen 80;
6 s1 [) a4 e6 u, R: X server_name 52os.net www.52os.net;" L: N, L% w% q% G+ _
1 h" x/ t$ \6 z+ U- R
location ~ \.php$ {
, u/ R5 _4 P1 k5 r% J+ q ModSecurityEnabled on; 9 g% _' r$ t8 W: y% a& R+ v
ModSecurityConfig modsecurity.conf;* G# V; a) I- O0 R s, O* A
( o- B, ^# \4 u6 q$ M+ a% c# R& W. ^
root /web/wordpress;
3 c/ L7 v6 [' ]6 _( g3 S index index.php index.html index.htm;+ b# _. Z5 w9 s' X+ `. t9 J
# H0 ]& C% Y+ c" Q6 h7 i9 y
fastcgi_pass 127.0.0.1:9000;
# C% U7 C" m+ V$ B; B& G. Z8 I fastcgi_index index.php;" o. u& Q8 S6 o
fastcgi_param SCRIPT_FILENAME $Document_root$fastcgi_script_name;& P7 T. Q1 d4 _7 _
include fastcgi_params;3 C& c) L% l d
}
5 g" f) o, `( N" k# d" B; w }* {# Q9 V! S: E7 g8 r
upstream负载均衡:+ C3 T }4 T& `0 k
, e' o) e, u" F" M; ]
upstream 52os.net {) d6 t$ `/ G6 B2 }6 n! D
server 192.168.1.100:8080;
4 D$ G, n6 v- W+ d6 q server 192.168.1.101:8080 backup;
* S( [. ?0 |0 S: y: F}
7 W5 A; c+ p# [; P" m' S" F0 {) w' M# u) f- ` M5 o; u. W9 q* u
server {
+ M+ V* V1 V- B, hlisten 80;
g: F! c% e% B$ i( s/ Yserver_name 52os.net www.52os.net;
2 h0 h) [+ h; u4 i5 f& ] ]% K+ z( Q# K4 m6 v( n
location / {
4 U/ [) _3 c( m5 F' j$ n ModSecurityEnabled on; ' z- Q6 d( W# ~9 a1 G
ModSecurityConfig modsecurity.conf; ; U! C/ E- O$ E' F) O& V
/ X, f; x$ K$ \/ c( Y proxy_pass http://online;
( m& ~* n) L& N( ^ O b proxy_redirect off;, X7 j/ X8 Q0 G8 D+ {' Z8 R
proxy_set_header Host $host;
" ~/ Q9 }* D9 @ proxy_set_header X-Real-IP $remote_addr;
- h% Y5 M* z$ a: ?- O) R* I proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
" x# L0 ^4 h8 x; W" e9 g. D/ j5 D' e }5 I& `# f1 F& k
}
# p8 l8 z, g/ R( Z' u s六.测试
8 D. J4 {7 X+ ?- N- }; Z$ X& M# m/ C. D4 I1 I- y
我们启用了xss和sql注入的过滤,不正常的请求会直接返回403。以php环境为例,新建一个phpinfo.php内容为:
: t; H& e1 X- Q! `, m
) |4 S/ L* s4 A" A<?php
* @- m5 `5 n- Q3 E. M phpinfo(); ! k' y4 m" f1 m
?>' B2 v7 Q- D! T$ M, D) i+ s, p, E$ f
在浏览器中访问:
; S. p, h9 f' F, y+ k) w9 C0 d3 b3 ?$ t. u
http://www.52os.net/phpinfo.php?id=1 正常显示。6 @: D" q9 `5 |8 S0 G
http://www.52os.net/phpinfo.php?id=1 and 1=1 返回403。
; G& M0 o& R% z; c- J5 ?http://www.52os.net/phpinfo.php?search=<scritp>alert('xss');</script> 返回403。# O" g& x% ~; K
说明sql注入和xss已经被过滤了) M, F4 l; l7 U/ \
1 }5 g9 }" G2 U: m
七、安装过程中排错" t! s# K3 P3 M g) p4 B) E
' Z5 e* z5 x/ \' @) b& I8 ]
1.缺少APXS会报错
$ i& l3 w- V7 P4 g# `
' ? S& _- G( I n/ `" d1 `7 gconfigure: looking for Apache module support via DSO through APXS# c" m/ U4 H. h7 Z) @
configure: error: couldn't find APXS' v& R; r, {) \/ b2 F* M& Z
apxs是一个为Apache HTTP服务器编译和安装扩展模块的工具,用于编译一个或多个源程序或目标代码文件为动态共享对象。" v/ I; ^, P* I# ^4 W9 S) ]& A _
解决方法:
; t4 D( Q: l' f& r! Q& H4 ^
- H5 Z3 y! {8 K6 t6 f/ byum install httpd-devel
* l+ {5 n8 Z! n+ \4 I2.没有pcre
3 T* X- G8 x- \7 R0 E5 I/ |
1 K- k% ~9 Q4 x4 X$ O9 E* c3 vconfigure: *** pcre library not found., w- G' q4 t( ` }
configure: error: pcre library is required
5 B/ E$ r2 i4 Z8 z解决方法:
1 H. r5 z# w' [ v+ _2 y9 v' @; `+ ?* p ~
yum install pcre pcre-devel6 W* ]; y. C) p J6 Y4 G8 @
3.没有libxml2
( Z0 J$ ]' } w, R% L
! P" V1 A3 Z3 B8 ~8 ~4 X$ X
+ K$ m/ G% n9 Fconfigure: *** xml library not found.
+ L% Y! I) w8 `/ c: |2 a( cconfigure: error: libxml2 is required
+ M! y7 x8 W y* M解决方法:) q$ D* q- u, H2 t
8 l" h5 M! Q- pyum install libxml2 libxml2-devel
& g# L( F* U! ^/ l4.执行 /opt/tengine/sbin/nginx -m 时有警告) I, k. s9 r$ q! U0 b
- G; x- q5 p/ T7 b+ q: DTengine version: Tengine/2.1.0 (nginx/1.6.2)" x& U6 G+ I( A
nginx: [warn] ModSecurity: Loaded APR do not match with compiled!
% m& R' f/ o, Z原因:modsecurity编译时和加载时的apr版本不一致造成的,并且会有以下error.log+ I6 S, p( n, ]6 V" @
" |* Q. K4 c3 }. v- i! d& ]2 _0 t
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity for nginx (STABLE)/2.8.0 () configured./ h: b0 T8 |4 E$ I" r0 R6 K' g- Y
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: APR compiled version="1.5.0"; loaded version="1.3.9"
; T, N% u9 w4 q6 d. P: t2015/01/26 02:04:18 [warn] 29036#0: ModSecurity: Loaded APR do not match with compiled!
/ o8 ?, L- R. V, G! K- s3 r2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: PCRE compiled version="7.8 "; loaded version="7.8 2008-09-05"
" q" f1 A9 [# v. i; z2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: LIBXML compiled version="2.7.6"
$ U/ d% g- S& J3 s( U2015/01/26 02:04:18 [notice] 29036#0: Status engine is currently disabled, enable it by set SecStatusEngine to On.
6 f6 d$ }- [0 S2 C* q) C. A. J4 N解决方法,移除低版本的APR (1.3.9)
K) p/ r) N. u2 y, a% L
+ [& C1 n- E Qyum remove apr
5 F0 `: i. l4 K0 {" _. D5.Error.log中有: Audit log: Failed to lock global mutex
$ z4 c7 P* |4 @" G3 u$ R0 {8 L% @: s- S0 }
2015/01/26 04:15:42 [error] 61610#0: [client 10.11.15.161] ModSecurity: Audit log: Failed to lock
0 {! d3 @2 O: ?' u& T" B; Rglobal mutex: Permission denied [hostname ""] [uri "/i.php"] [unique_id "AcAcAcAcAcAcAcA4DcA7AcAc"]
' w+ b. m7 J1 z+ z+ D; g4 i解决方法:
8 G; p" ]$ Y; O: s8 x编辑modsecurity.conf,注释掉默认的SecAuditLogType和SecAuditLog,添加以下内容:" N; ^- U% i& f, H- \# d1 e6 n
- ~3 j! _3 e+ L E
SecAuditLogDirMode 0777
, a3 T- ]) q4 p7 s3 eSecAuditLogFileMode 0550 @) b: b( I0 p' H' c$ r, y) k
SecAuditLogStorageDir /var/log/modsecurity
8 m1 |& W# x- p* u. s3 h0 S- `SecAuditLogType Concurrent5 O2 L$ i5 }4 ^1 Z
参考文章:
4 ?7 Y0 y$ j9 u6 T* S9 ?5 {https://github.com/SpiderLabs/ModSecurity/wiki/Reference-Manual#Installation_for_NGINX
7 q9 g# ~+ \' U' }9 b( {: X3 l }3 ~' Lhttp://drops.wooyun.org/tips/2614 |
|