找回密码
 立即注册

QQ登录

只需一步,快速开始

查看: 12711|回复: 0

nginx配合modsecurity实现WAF功能

[复制链接]
发表于 2017-10-19 16:53:31 | 显示全部楼层 |阅读模式
modsecurity原本是Apache上的一款开源waf,可以有效的增强web安全性,目前已经支持nginx和IIS,配合nginx的灵活和高效,可以打造成生产级的WAF,是保护和审核web安全的利器。: }; \6 y0 I% B; J) S% G
6 Y) s* D# _0 R) ]% C
一.准备工作2 Y, ^' F. S' F* Q# N& q

  T3 t, R* f# h; M, |5 \系统:centos 6.5 64位、 tengine 2.1.0, modsecurity 2.8.0* p: v0 x0 f, f; m1 ?! u
# ^1 Z( e7 n4 u) `5 V2 a! P$ J; i
tengine : http://tengine.taobao.org/download/tengine-2.1.0.tar.gz4 \2 c% c9 j6 B$ r* L& I
: `) i8 h& X) Y, @2 i* q5 t. x
modsecurity for Nginx: https://www.modsecurity.org/tarball/2.8.0/modsecurity-2.8.0.tar.gz3 k' U0 Y1 G. R/ B' M! t5 k

' e6 E* u1 |' V0 l6 z  ^. aOWASP规则集: https://github.com/SpiderLabs/owasp-modsecurity-crs- n$ m% g7 j3 S' ]

% I' M3 S9 N1 @  ~7 |依赖关系:1 ?" K, S% C6 Q- i, v
tengine(nginx)依赖: pcre 、zlib、 openssl, 这三个包centos 6.5 系统源里都有:
7 H& r, Y0 Y1 N4 k7 |6 \9 ^1 H: I& l+ w' D" L/ m( [/ Q. g- T1 I
yum install zlib zlib-devel openssl openssl-devel  pcre pcre-devel
& G+ ^7 T8 {; D7 N( cmodsecurty依赖的包:pcre httpd-devel libxml2 apr
5 K3 y, r" c1 w1 U' \7 `5 r, c. B- C- R+ B
yum install httpd-devel apr apr-util-devel apr-devel  pcre pcre-devel  libxml2 libxml2-devel
& `* v2 g- B* x# \3 Z二.启用standalone模块并编译
# C: f7 m/ P" G9 r$ z+ a6 L
# W6 U1 O  |  v4 `- z$ o% K. b" k: _下载modsecurity for nginx 解压,进入解压后目录执行:; ]: p! b2 m- @, L6 x

( Y& a- T4 Y  H6 R./autogen.sh: p1 s( U  _$ E: f
./configure --enable-standalone-module --disable-mlogc% e' e$ f1 M# _
make
8 e6 W, |/ \+ m$ A5 G7 K" O三.nginx添加modsecurity模块: k6 A/ W! c7 {. N. X$ T

/ f; r6 }# g7 \在编译standalone后,nginx编译时可以通过"--add-module"添加modsecurity模块:
. G; b0 p6 h0 L6 R6 Q, C8 H3 B
4 R$ T' j, I+ x./configure --add-module=/root/modsecurity-2.8.0/nginx/modsecurity/  --prefix=/opt/tengine) Y8 q5 `1 c% z/ E) ~1 b
make && make install1 q! {; h# s/ Y" k, x
四.添加规则$ _3 K( h6 _" R3 }0 U0 x

4 P. o- q4 R7 X, j* H, E8 L: S6 amodsecurity倾向于过滤和阻止web危险,之所以强大就在于规则,OWASP提供的规则是于社区志愿者维护的,被称为核心规则CRS(corerules),规则可靠强大,当然也可以自定义规则来满足各种需求。" D8 {4 G" n0 M9 m6 ^" D4 K

" w- i2 f' k9 n1 [5 @3 q8 Z. ?  D1.下载OWASP规则:
/ w( t! l8 P. o2 c
* M) A# d. n4 b5 B/ Xgit clone https://github.com/SpiderLabs/owasp-modsecurity-crs
$ M$ a1 @6 m# q2 E+ v
4 s7 w0 d) d% f0 x6 imv owasp-modsecurity-crs /opt/tengine/conf/( N& K& p& |& I$ o4 p6 M/ N+ Q) e, `1 r

/ r$ ^" F% ?+ J7 Ocd /opt/tengine/conf/owasp-modsecurity-crs && mv modsecurity_crs_10_setup.conf.example modsecurity_crs_10_setup.conf
) T8 F* _1 H3 v3 e# n4 X( L; H! D2.启用OWASP规则:0 Y9 p0 X9 M5 }- K" A" f

) D* B% u1 E' l8 ]9 b* g8 ~复制modsecurity源码目录下的modsecurity.conf-recommended和unicode.mapping到nginx的conf目录下,并将modsecurity.conf-recommended重新命名为modsecurity.conf。; B$ g: k! h' X* |5 \
5 O9 p% @2 y( a( f4 w3 F; O5 n7 s
编辑modsecurity.conf 文件,将SecRuleEngine设置为 on7 k9 u9 l0 m5 n% g2 k8 `" c

% Z2 T* n  l) o* Q9 b1 Kowasp-modsecurity-crs下有很多存放规则的文件夹,例如base_rules、experimental_rules、optional_rules、slr_rules,里面的规则按需要启用,需要启用的规则使用Include进来即可。
- V& T0 m% |% K$ }$ y( t' ^) [( G2 m0 T
6 J0 n9 N+ _! A$ y6 \/ ]9 E% PInclude owasp-modsecurity-crs/modsecurity_crs_10_setup.conf. ~$ x. [3 R& F, l# \9 w
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_sql_injection_attacks.conf# s5 y+ u: ~% c
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_xss_attacks.conf
5 m, z( j/ [) G4 d5 {) |3 xInclude owasp-modsecurity-crs/base_rules/modsecurity_crs_40_generic_attacks.conf
' f; A5 ?4 v, |2 |Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_dos_protection.conf. m5 t3 r# q$ u( J# r
Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_brute_force.conf9 B& Y1 d$ Q8 r2 N; ~
Include owasp-modsecurity-crs/optional_rules/modsecurity_crs_16_session_hijacking.conf; f" r+ p" O( [
五.配置nginx3 L1 ]* ?8 U* w% t# o. B' A8 B
$ N6 G* e) L3 u) _! p* b( z
在需要启用modsecurity的主机的location下面加入下面两行即可:6 Z/ h/ M% f6 |7 k
- z8 H9 }$ C% `% }: e9 b
ModSecurityEnabled on;  + J. e) @  N' R; k2 o% ^
ModSecurityConfig modsecurity.conf;
4 \9 C. X: k* }* v" G下面是两个示例配置,php虚拟主机:9 [( n3 ~) o* C0 X; z

8 u! y$ [% u9 m( _$ w8 G3 fserver {' M$ W5 s9 [6 k. F. N+ w7 u
      listen      80;
0 W- A8 I" W- i; L      server_name 52os.net www.52os.net;+ o7 y8 @, t( M/ `4 R
     # ^1 B% p# x& g0 a1 j
      location ~ \.php$ {1 V" J+ t" u: }: a9 O
      ModSecurityEnabled on;  8 P3 K; S6 ]& O* m
      ModSecurityConfig modsecurity.conf;. i0 A( p% g+ v/ Y5 O
7 s& H* e7 O* |+ p$ z( ~5 y
      root /web/wordpress;& B2 p* n! P2 i. p: J
      index index.php index.html index.htm;' G# j) C4 `: _
  ; @! ]5 t/ t4 G, g; j
      fastcgi_pass   127.0.0.1:9000;0 D8 @1 Z: b5 p
      fastcgi_index  index.php;9 Q; d4 q& G/ u) a# T+ s
      fastcgi_param  SCRIPT_FILENAME  $Document_root$fastcgi_script_name;. z2 h( H6 Y8 p  g* [8 G
      include        fastcgi_params;
/ g3 j% Q, m, m. d3 |" }      }' {/ h3 U& R5 a5 ~5 X' V9 o* E
  }
! K) d0 ~8 W) u9 r8 R$ c) D3 |! U. iupstream负载均衡:5 C6 S. M7 z6 ^- V) ^4 y

; o0 @. x) v! D0 f9 gupstream 52os.net {
$ x- W. B2 \+ I    server 192.168.1.100:8080;
0 M; F- w7 v2 l7 {/ `: f    server 192.168.1.101:8080 backup;" H. c& E0 }8 Z+ K8 h
}7 }% O. I* U. d1 ]" U- y6 j

# C( ]& Z1 V) A( }8 Jserver {4 l2 m6 ]/ F( S+ w4 U# D1 \! o9 {
listen 80;- {( r# T; d, J  E% r( P4 \" m
server_name 52os.net www.52os.net;
0 t2 D" y9 k4 O- r( C1 g7 N
1 a/ w6 A7 T2 |0 ?# F6 P2 Wlocation / {% Y( W, h) ~* s) }1 `5 E" r4 E
    ModSecurityEnabled on;  # W2 @- e( N* H7 `6 N
    ModSecurityConfig modsecurity.conf;  4 N3 m$ @- u: Y3 R

/ S) ]3 D! B, M        proxy_pass http://online;
. h& \, r. b. `; Z        proxy_redirect         off;2 V4 a2 W; O' {3 h/ s* S; j% g
        proxy_set_header Host $host;
* r% A; ~& ~% B) p% T        proxy_set_header X-Real-IP $remote_addr;
$ t, a& x. k/ A1 j7 ^        proxy_set_header  X-Forwarded-For $proxy_add_x_forwarded_for;
& X  V/ s. m" C0 s6 G& E    }" _5 ?2 {# i" N2 d
}8 L7 ?$ k1 p4 o' @
六.测试
, g$ J% ?0 Y5 e) v
" v* Q5 a3 k% x$ U/ b0 d2 f我们启用了xss和sql注入的过滤,不正常的请求会直接返回403。以php环境为例,新建一个phpinfo.php内容为:
( v2 x% c0 _" @
7 g( S+ H1 }" @% Y<?php' F2 Z& x) I8 @
    phpinfo();   
# D# }2 s: N7 \7 j% ^+ K1 u?>
7 Z7 p% |5 Y8 O: Q7 i在浏览器中访问:
( X" A- v+ e8 [  j
2 ^; j# H& c- S$ L2 g+ ihttp://www.52os.net/phpinfo.php?id=1 正常显示。4 `8 k* V# `. e% V9 i/ V; V
http://www.52os.net/phpinfo.php?id=1 and 1=1  返回403。8 q* T2 F# A+ a
http://www.52os.net/phpinfo.php?search=<scritp>alert('xss');</script>  返回403。0 [2 l; v7 J" v
说明sql注入和xss已经被过滤了' _0 {2 i/ t6 Z! @* O( T

6 q3 N- d3 L1 }# `七、安装过程中排错
5 ]  s0 j! {2 l1 g' A6 P, X9 F" E8 p2 b) [) W
1.缺少APXS会报错! h) p5 K1 b: [8 {

) b  g/ C) G  b0 ]: a8 c5 qconfigure: looking for Apache module support via DSO through APXS
; v: E% e  J8 f$ H6 V5 u  f' O0 cconfigure: error: couldn't find APXS6 b+ K& B. i: T/ Q$ X! m
apxs是一个为Apache HTTP服务器编译和安装扩展模块的工具,用于编译一个或多个源程序或目标代码文件为动态共享对象。
! t* s, |6 f- D; i. J2 b( i解决方法:
" y# }$ l: _$ v( i6 k0 s6 f& O2 y* D0 O& N# I
yum install httpd-devel; x" S4 u! E+ F6 g. ?
2.没有pcre4 P. ^8 X0 a% [+ ]

+ _5 H- R# `5 Z7 x! Nconfigure: *** pcre library not found.6 n1 L! t" \% y; G1 [
configure: error: pcre library is required" U5 l5 {5 Q/ \6 X2 I
解决方法:
8 Z+ C7 B- r9 q& S; b4 P
' _8 A+ A4 O" I' p9 r2 O; qyum install pcre pcre-devel( Y! w% i/ t* o2 J& r2 E
3.没有libxml2- R+ K3 b4 |* i7 D# l2 W& _5 J
. z- E$ ]( ]  D* W$ p
0 ~9 k+ M; n( W4 z7 m
configure: *** xml library not found.4 A- j( M9 u' `5 H2 C
configure: error: libxml2 is required
+ E# l! D; w$ U+ Z解决方法:
  b- I- m6 L3 D3 U6 J6 ~9 s6 X3 W2 Z9 F; t5 b  d
yum install  libxml2 libxml2-devel# c9 r( |9 I% A
4.执行 /opt/tengine/sbin/nginx -m 时有警告! f7 I! t4 D% P( j  Y
% ?2 N7 M% f# i; j/ i; a
Tengine version: Tengine/2.1.0 (nginx/1.6.2)3 m9 X$ c* X( i: v5 c" E
nginx: [warn] ModSecurity: Loaded APR do not match with compiled!
& H; D; f! J' Q原因:modsecurity编译时和加载时的apr版本不一致造成的,并且会有以下error.log# x" w" j& i0 b1 p3 M: ~) p
; u9 S2 w) q1 h6 \2 ]* a
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity for nginx (STABLE)/2.8.0 () configured.
% U  t" M/ J  T9 A0 T! Z: Y% B2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: APR compiled version="1.5.0"; loaded     version="1.3.9"
% e. d0 f( h; |2 N8 S2015/01/26 02:04:18 [warn] 29036#0: ModSecurity: Loaded APR do not match with compiled!2 g; }& |4 Z" v! o
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: PCRE compiled version="7.8 "; loaded version="7.8 2008-09-05"- Y( D$ p% c0 h- |
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: LIBXML compiled version="2.7.6"
2 V6 |7 z, y& B+ t3 k5 @2015/01/26 02:04:18 [notice] 29036#0: Status engine is currently disabled, enable it by set SecStatusEngine to On.
' g" Z& V& N4 v* f) l解决方法,移除低版本的APR (1.3.9)0 n5 b3 _7 s# z9 o  ]

: `4 n) b) N/ I, U3 @0 Byum remove apr
* P2 Q- M8 ^  b7 {5.Error.log中有: Audit log: Failed to lock global mutex- y6 M8 T* P: ?) h* U) e# K. e
, h! _9 |# O3 O' e% J8 C
2015/01/26 04:15:42 [error] 61610#0: [client 10.11.15.161] ModSecurity: Audit log: Failed to lock     6 m! E1 Z; O+ d
global mutex: Permission denied [hostname ""] [uri "/i.php"] [unique_id "AcAcAcAcAcAcAcA4DcA7AcAc"]! D- K2 P& E( g1 }; V4 _
解决方法:" L$ G. E! J5 ^8 I7 N" o( w
编辑modsecurity.conf,注释掉默认的SecAuditLogType和SecAuditLog,添加以下内容:9 E% E4 n3 k9 @) b" f( B
$ v- x3 D( j% s3 o- q
SecAuditLogDirMode 0777
" [/ v8 n8 M. O5 ^! z2 x) i0 eSecAuditLogFileMode 0550
6 j4 N' g' W' U4 o0 R! P4 `SecAuditLogStorageDir /var/log/modsecurity
# k4 Y+ l2 A1 {5 g$ ^- DSecAuditLogType Concurrent0 W5 i: @3 E; p
参考文章:& h* x  h% G) {% f( P8 ^2 m7 P; R& Z/ I
https://github.com/SpiderLabs/ModSecurity/wiki/Reference-Manual#Installation_for_NGINX
' y( s' M$ H2 B( K% dhttp://drops.wooyun.org/tips/2614
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

QQ|Archiver|手机版|小黑屋|第一站论坛 ( 蜀ICP备06004864号-6 )

GMT+8, 2026-10-2 17:04 , Processed in 0.063535 second(s), 19 queries .

Powered by Discuz! X3.5

© 2001-2026 Discuz! Team.

快速回复 返回顶部 返回列表