|
|
modsecurity原本是Apache上的一款开源waf,可以有效的增强web安全性,目前已经支持nginx和IIS,配合nginx的灵活和高效,可以打造成生产级的WAF,是保护和审核web安全的利器。
! R+ R5 X9 G0 U7 T& J- _6 _$ ^& ^3 ?" O4 o
一.准备工作# x1 i' X3 G2 F7 n6 t. h# b
; n' \' k) Y9 l4 R- G, ?系统:centos 6.5 64位、 tengine 2.1.0, modsecurity 2.8.0
) @5 `) b+ S1 m
0 k$ m; A B4 \tengine : http://tengine.taobao.org/download/tengine-2.1.0.tar.gz
& ~& N/ r1 Q; e4 h/ B, N E
4 h% [# @( Q' n$ s2 C8 ymodsecurity for Nginx: https://www.modsecurity.org/tarball/2.8.0/modsecurity-2.8.0.tar.gz4 ?( |6 e) A$ E& E9 ?, i" X7 ~
4 j; U! A) q( S. q B: Q* _1 ~
OWASP规则集: https://github.com/SpiderLabs/owasp-modsecurity-crs
7 z( d, F: l/ _! ~/ N# u
7 K" }& A& c; T依赖关系:
4 D) w- }( Q! g. _tengine(nginx)依赖: pcre 、zlib、 openssl, 这三个包centos 6.5 系统源里都有:
2 o/ W# X- f, X& y
4 }; U% v+ Y$ \1 j; \yum install zlib zlib-devel openssl openssl-devel pcre pcre-devel
' ?2 f! S$ o+ i8 j6 z L) {modsecurty依赖的包:pcre httpd-devel libxml2 apr2 Q- B4 C8 i: ^
! Z: u2 ]- t& @3 T/ M T& Ryum install httpd-devel apr apr-util-devel apr-devel pcre pcre-devel libxml2 libxml2-devel
' C, ?5 U, o8 X: b5 a& x二.启用standalone模块并编译$ C- G/ q7 s( z, m
# _- I/ w* P2 T# d) ~2 C/ H$ R
下载modsecurity for nginx 解压,进入解压后目录执行:
5 \6 _" ~8 ^* {6 P( z# X
; k7 M' W% s3 \1 t9 b* B, P./autogen.sh5 W* u, ~" {/ W+ ]
./configure --enable-standalone-module --disable-mlogc
. b/ q/ k! i) u1 q- h1 y. Emake
: D8 f, {8 D& \2 S, ]( T三.nginx添加modsecurity模块0 P5 X( y/ s5 C1 @: I
& }% ]& j5 Q- t2 B0 p* `在编译standalone后,nginx编译时可以通过"--add-module"添加modsecurity模块:5 o6 m) G o9 z1 p8 {9 z* G% f
' N$ `8 A2 f/ c* Y! r% R# e./configure --add-module=/root/modsecurity-2.8.0/nginx/modsecurity/ --prefix=/opt/tengine
! T4 C1 S# P6 |% L/ n8 T* s! x0 nmake && make install! c( M4 P T8 x. G; `' ?
四.添加规则
% n& Z9 D' g; @
7 t9 I" Z6 a3 e% f" h# Rmodsecurity倾向于过滤和阻止web危险,之所以强大就在于规则,OWASP提供的规则是于社区志愿者维护的,被称为核心规则CRS(corerules),规则可靠强大,当然也可以自定义规则来满足各种需求。
% {1 {, Z4 r! y" s* b' n8 k( H
" C+ I8 {( Y0 m8 j: P1.下载OWASP规则:
& I! |/ f, j$ H! m; }( B& p, q! ~0 n% z+ J! \
git clone https://github.com/SpiderLabs/owasp-modsecurity-crs1 s/ p6 ^7 s. S* O/ z( r) b
$ G6 P' L& D" z0 z8 n
mv owasp-modsecurity-crs /opt/tengine/conf/1 S7 J' J1 X# h
& |3 s- N, n8 e: N: M9 d: i u) jcd /opt/tengine/conf/owasp-modsecurity-crs && mv modsecurity_crs_10_setup.conf.example modsecurity_crs_10_setup.conf8 Y; z- O8 C. \, \
2.启用OWASP规则:" j1 A$ I: c, [. F+ Q
8 S" c4 ]' L2 R% e复制modsecurity源码目录下的modsecurity.conf-recommended和unicode.mapping到nginx的conf目录下,并将modsecurity.conf-recommended重新命名为modsecurity.conf。
3 d3 T# N4 A! W* y
# J4 s, p" p5 ]7 Y. M编辑modsecurity.conf 文件,将SecRuleEngine设置为 on
3 D! U% @ R8 B$ T7 B1 m3 N0 U
! e* J& G \; I# P3 gowasp-modsecurity-crs下有很多存放规则的文件夹,例如base_rules、experimental_rules、optional_rules、slr_rules,里面的规则按需要启用,需要启用的规则使用Include进来即可。1 z1 T% C+ ~% N/ @' ^2 A6 D1 P% [0 ^
' B1 r1 t' \2 z* g& E
Include owasp-modsecurity-crs/modsecurity_crs_10_setup.conf
+ z2 T; E* X, a+ V( r- iInclude owasp-modsecurity-crs/base_rules/modsecurity_crs_41_sql_injection_attacks.conf
* k; I6 s. X9 P! u* g3 i: X$ lInclude owasp-modsecurity-crs/base_rules/modsecurity_crs_41_xss_attacks.conf6 D: r1 L6 l6 ~+ }3 m1 ^8 q
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_40_generic_attacks.conf
( L! O9 Q" I, I1 lInclude owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_dos_protection.conf: `4 g0 \1 Q' n% ]! j1 [5 l8 s
Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_brute_force.conf& N2 [; F3 A; x: h: d( r3 Z9 T
Include owasp-modsecurity-crs/optional_rules/modsecurity_crs_16_session_hijacking.conf
8 ^- U, c v) b r# {) t五.配置nginx
0 q# }% B: @5 l2 b1 ]& _1 u0 e( U2 H2 W( [
' m9 |% [3 F6 n3 r3 N5 o, H在需要启用modsecurity的主机的location下面加入下面两行即可:: o$ e+ v& I( s6 o% f9 {: D' R9 q) G
4 {1 E s8 p' H, B( z; C7 R
ModSecurityEnabled on; 1 b9 S l9 {' L, B! I2 _
ModSecurityConfig modsecurity.conf;
& k# T& a2 K& I c' U' |! F, e1 W下面是两个示例配置,php虚拟主机:6 ~0 u! W# U ^
9 D) D4 \. s7 A8 oserver {
5 k0 u, N2 {9 `9 ^: p listen 80;
6 ]- ^4 d8 B$ M* G. X" l6 C6 G server_name 52os.net www.52os.net;* Y( O$ |. p: b6 ]1 X* u: J
% V! v/ J- x: ]0 ` location ~ \.php$ { c" c' o5 U! v& w0 Q
ModSecurityEnabled on;
+ K- o8 Z: V5 g! Q ModSecurityConfig modsecurity.conf;
: U6 [& h7 B: d8 t
" A- s# W7 i' p6 e& g2 ?# f root /web/wordpress;. ?+ o" k, P) H% R' ~
index index.php index.html index.htm;
3 ?% P! m4 P9 ^$ A 6 ?% ?. f& P8 P, |# b, i
fastcgi_pass 127.0.0.1:9000;8 Z% b# |( x) X
fastcgi_index index.php;
. W: D5 e' B. i1 }9 B fastcgi_param SCRIPT_FILENAME $Document_root$fastcgi_script_name;
0 F% R4 F- r, S include fastcgi_params;% }" j* D2 m1 U3 W
}
5 B/ P3 U- ?7 X }
+ Q7 L- Q; f" G9 Vupstream负载均衡:
' c2 l* N. I4 o: g
2 o. D$ f5 L _, yupstream 52os.net {" y1 m( J7 t$ P0 [6 W: m
server 192.168.1.100:8080;
0 F* e6 [+ L$ M) }- P i server 192.168.1.101:8080 backup;3 U$ j ^) l+ t! V0 \3 i
}
1 `8 j4 z" S+ w7 [2 E
+ g3 ?3 g4 v, N: |/ O M6 h% Xserver {; B) m# n4 \, ^5 K& s, D* d( t# s
listen 80;
' H U1 s: d. B) R- `" zserver_name 52os.net www.52os.net;
& l4 ^* d- j7 r0 W! v
* x+ z' ^- a* U R$ \9 X8 o# Tlocation / {
1 ~7 y# C# |1 F- }4 b4 x& M ModSecurityEnabled on; . E3 x! u3 C7 o4 j
ModSecurityConfig modsecurity.conf; 7 U9 a& `, h1 i [7 F/ B0 w1 ?
" F `, I. e9 d2 ?, ? proxy_pass http://online;1 H# }; I' I8 x5 Y" E1 p" V- }5 ?9 q
proxy_redirect off;
* Y& ~ ^0 |. } proxy_set_header Host $host;
# F" K$ A: C3 K. b H% Y proxy_set_header X-Real-IP $remote_addr;
7 x2 p1 R5 J4 R( C proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
" H! S# a5 `% }1 w9 i, E9 ] }' K$ o6 v4 L3 B
}; _4 {' _$ j) m4 Z! T/ N
六.测试8 F3 ~: I0 w& a
+ Q5 s7 S" i6 f我们启用了xss和sql注入的过滤,不正常的请求会直接返回403。以php环境为例,新建一个phpinfo.php内容为:1 V! a2 b! Q2 n
/ U/ ^" C9 w c
<?php
% R% ?3 _5 ?1 u7 D* C, c. V phpinfo();
+ B% L& ^+ y# B7 N1 y$ J% H?>
+ [$ E/ W8 P# e0 R, s+ _7 i3 }在浏览器中访问:6 H( i B4 t) q
1 ?2 i! l% J3 h/ U9 k n6 Z. Phttp://www.52os.net/phpinfo.php?id=1 正常显示。
) h+ q6 u1 m+ @+ @http://www.52os.net/phpinfo.php?id=1 and 1=1 返回403。; {% S& ]8 L! m7 S
http://www.52os.net/phpinfo.php?search=<scritp>alert('xss');</script> 返回403。
$ m0 w a8 B* n/ P9 o* Y. F$ h: L说明sql注入和xss已经被过滤了: c5 b* n& X) b/ ]- _) ~- N0 x8 Z
. f0 n3 X2 c" h9 a: Q七、安装过程中排错* P% n: {6 t0 s! r" X5 A. y
; X$ c& l( q$ e; N1.缺少APXS会报错
! P7 C$ \6 `( I/ I9 R% U4 n5 Z& }, C: M. C6 t( T! N; _
configure: looking for Apache module support via DSO through APXS9 V6 ]5 Y7 m# A" {! h* T
configure: error: couldn't find APXS+ z$ }; l+ `- C/ x/ v
apxs是一个为Apache HTTP服务器编译和安装扩展模块的工具,用于编译一个或多个源程序或目标代码文件为动态共享对象。
. U [( L/ y+ q解决方法:! j1 i8 T) i) \# ~3 J% z1 [
' _' G: D/ C% ]4 h0 S$ b; iyum install httpd-devel
+ n9 X6 e& t4 D2.没有pcre5 }2 I9 ?- Y7 [. Y3 @
$ U! y; k3 f; a- v! L5 t( T) V8 f
configure: *** pcre library not found.; s& R g# m U- T X/ h
configure: error: pcre library is required
2 ?$ D7 E- X9 k解决方法:. e& }/ |& _- ^1 G
% m1 h5 ?. Q) N3 R) R/ Hyum install pcre pcre-devel
+ ^- I A, M& h* g$ F3 c# k/ A3.没有libxml2- g2 g7 e! b4 g% v. w
" w* n$ x1 j/ q, k
# a9 ]$ ?' A$ v* i! M$ U2 V2 Dconfigure: *** xml library not found.
W/ R2 X0 u( b# S( Z/ kconfigure: error: libxml2 is required& m/ X! B2 h* b9 O' w/ \+ {$ m
解决方法:
9 e7 j: ]; ~& b4 w' D9 I: K% W4 `
+ ]$ i5 ]7 q) Y( j, Q, b i4 I3 byum install libxml2 libxml2-devel
, t2 M2 Q( c4 r7 J8 T2 H4.执行 /opt/tengine/sbin/nginx -m 时有警告# ~0 D I+ X* o/ s8 w8 I( N I
: J. l9 [* Q+ j
Tengine version: Tengine/2.1.0 (nginx/1.6.2)/ V/ |5 q7 }# _' S' N# |
nginx: [warn] ModSecurity: Loaded APR do not match with compiled!
& n. l5 c& @7 f. e' m+ z& y原因:modsecurity编译时和加载时的apr版本不一致造成的,并且会有以下error.log
9 _8 W/ D R3 V7 M, X2 m6 ^/ p$ i' Q8 m
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity for nginx (STABLE)/2.8.0 () configured.
4 @! V* r8 c3 P2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: APR compiled version="1.5.0"; loaded version="1.3.9"! k7 L) z9 H+ y% _
2015/01/26 02:04:18 [warn] 29036#0: ModSecurity: Loaded APR do not match with compiled!
) m, c9 ^" m! C/ k: g6 l# n2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: PCRE compiled version="7.8 "; loaded version="7.8 2008-09-05"
; I7 H0 Y# ?( s+ c5 A- E a2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: LIBXML compiled version="2.7.6"
* {0 K, C6 f- ?0 }. j2015/01/26 02:04:18 [notice] 29036#0: Status engine is currently disabled, enable it by set SecStatusEngine to On.
. Y7 f" K! f/ c4 F5 P3 i- k* w" r* Z解决方法,移除低版本的APR (1.3.9)
9 W9 o# b- q- F9 p
: H3 x1 c: b4 F2 Zyum remove apr1 C2 @5 z6 o' Q+ c8 X
5.Error.log中有: Audit log: Failed to lock global mutex$ M# z) I" H. ]
; |% o) k6 D9 I1 g3 ]- ?2015/01/26 04:15:42 [error] 61610#0: [client 10.11.15.161] ModSecurity: Audit log: Failed to lock ' V8 q$ S; E. i9 }: O* W
global mutex: Permission denied [hostname ""] [uri "/i.php"] [unique_id "AcAcAcAcAcAcAcA4DcA7AcAc"], E. a5 E, N6 s4 [# ^
解决方法:
) Y6 ~3 M6 T: Z- B编辑modsecurity.conf,注释掉默认的SecAuditLogType和SecAuditLog,添加以下内容:7 ` d8 H- b) G# `; m
, S& j# o! ?' N% YSecAuditLogDirMode 0777
3 L% H: N. b. u" _+ Z* I3 |; ~( e# ]SecAuditLogFileMode 0550
% [+ ?0 E/ [0 c8 E) X- S# m1 s1 wSecAuditLogStorageDir /var/log/modsecurity6 E% E+ t1 l8 C9 P! ^ O0 c
SecAuditLogType Concurrent2 @# V. L1 K6 S, j0 a7 e! {$ D
参考文章:5 {4 K. ^ |4 N X
https://github.com/SpiderLabs/ModSecurity/wiki/Reference-Manual#Installation_for_NGINX' o" h* h! S6 a/ z9 e
http://drops.wooyun.org/tips/2614 |
|