|
|
modsecurity原本是Apache上的一款开源waf,可以有效的增强web安全性,目前已经支持nginx和IIS,配合nginx的灵活和高效,可以打造成生产级的WAF,是保护和审核web安全的利器。: N) D+ Y, k& w3 j5 l# r' e; m) r F
" C; _+ k0 Q$ l7 h, h一.准备工作( i/ u$ w2 A- _" w7 w+ n7 n6 i6 P4 n
9 _& J% m& p& T, _
系统:centos 6.5 64位、 tengine 2.1.0, modsecurity 2.8.0" b( e5 v! u" \8 t
' ~. Z, B: Z/ g0 [& G& b0 T' K3 @* @+ stengine : http://tengine.taobao.org/download/tengine-2.1.0.tar.gz9 b, Q; I+ B# h
0 i0 _2 _+ c) m. b! }# T' kmodsecurity for Nginx: https://www.modsecurity.org/tarball/2.8.0/modsecurity-2.8.0.tar.gz) Y, `7 D7 x2 b1 G7 E
* u" d! o1 ~( O; d
OWASP规则集: https://github.com/SpiderLabs/owasp-modsecurity-crs
" T5 M# b: ]) a5 ~' ]( E7 T( c$ Y2 v2 F+ F7 i8 Y( z+ o
依赖关系:
2 g" G' s* F, V# W% j. ^tengine(nginx)依赖: pcre 、zlib、 openssl, 这三个包centos 6.5 系统源里都有:$ F3 ?3 d, q; W! ]- l- g
* r( [4 z+ J f+ e, o. f
yum install zlib zlib-devel openssl openssl-devel pcre pcre-devel9 Y* v) Y5 X+ ~. H$ {" G
modsecurty依赖的包:pcre httpd-devel libxml2 apr
! e" S& f% k+ J3 H5 w$ x' o% P' n' V6 Y0 N8 M/ w
yum install httpd-devel apr apr-util-devel apr-devel pcre pcre-devel libxml2 libxml2-devel
( A9 Q) z! g3 C/ W' Y7 J" `二.启用standalone模块并编译
0 \! U+ x9 o: g6 l! L2 z J( J! R1 f' ]4 Z3 E `
下载modsecurity for nginx 解压,进入解压后目录执行:
+ Z+ _4 Q' l; t% f# |1 U( m+ R3 G0 z
./autogen.sh
1 p T0 F v0 b2 H./configure --enable-standalone-module --disable-mlogc( x. y0 W3 P k/ n2 p8 h
make
% Z# ]! K8 j' p [三.nginx添加modsecurity模块
! f1 J8 g; z. t' o) Q w6 l" f& d% G+ a) T5 X
在编译standalone后,nginx编译时可以通过"--add-module"添加modsecurity模块:
_' s4 Z8 J! a6 v4 } W S6 Z( m6 H4 E; c6 n
./configure --add-module=/root/modsecurity-2.8.0/nginx/modsecurity/ --prefix=/opt/tengine2 F7 S2 _4 s3 D5 \8 }7 Z) C
make && make install
) w$ @+ W6 J* g9 m四.添加规则% w$ t3 C) d; e
+ ] Z2 q: y- ~: {
modsecurity倾向于过滤和阻止web危险,之所以强大就在于规则,OWASP提供的规则是于社区志愿者维护的,被称为核心规则CRS(corerules),规则可靠强大,当然也可以自定义规则来满足各种需求。0 x. x5 A' }( S; I
# B) w* J4 m+ K1 G. [) {
1.下载OWASP规则:
/ G( h- B- w( R' `/ B. E/ c8 [# S# {6 g1 C4 h
git clone https://github.com/SpiderLabs/owasp-modsecurity-crs" q, ?# j/ P! w, @( `' E9 n/ \3 K
8 h. {$ @) L9 @2 S1 |
mv owasp-modsecurity-crs /opt/tengine/conf/
0 y @+ W( o5 [, x! w6 S% Q& g8 |( p! ]' x5 D' o* L
cd /opt/tengine/conf/owasp-modsecurity-crs && mv modsecurity_crs_10_setup.conf.example modsecurity_crs_10_setup.conf
0 a* j% i# B. w5 H2.启用OWASP规则:% Y! E1 _, y2 _# o2 g5 b* P8 O
: P0 m8 ~9 J& H0 j X复制modsecurity源码目录下的modsecurity.conf-recommended和unicode.mapping到nginx的conf目录下,并将modsecurity.conf-recommended重新命名为modsecurity.conf。 b) c5 {: J2 m& s/ r
3 ?; U# [: {, Q. @, B
编辑modsecurity.conf 文件,将SecRuleEngine设置为 on. @+ M; H& }- |! F" F
* e+ S e" f3 o' Lowasp-modsecurity-crs下有很多存放规则的文件夹,例如base_rules、experimental_rules、optional_rules、slr_rules,里面的规则按需要启用,需要启用的规则使用Include进来即可。
! x* @% c! y" a9 D. ?; g9 w% }2 O/ W$ [& e$ Z6 } U% }! s- [
Include owasp-modsecurity-crs/modsecurity_crs_10_setup.conf
) v. w3 }# R. `" H. ?Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_sql_injection_attacks.conf6 @0 s; }8 P& J ~; I
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_xss_attacks.conf
$ P4 u& F. @' DInclude owasp-modsecurity-crs/base_rules/modsecurity_crs_40_generic_attacks.conf: i* Z) }/ j7 z/ [
Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_dos_protection.conf) `7 f, A, w* n+ W, M7 b9 k7 ]
Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_brute_force.conf& w( Y* t$ I5 f* ]
Include owasp-modsecurity-crs/optional_rules/modsecurity_crs_16_session_hijacking.conf% w% s1 y& ?+ a. T
五.配置nginx' r# J6 Z+ N- m0 X5 O' ^( l
; Z, L+ t# }$ L
在需要启用modsecurity的主机的location下面加入下面两行即可:
; s; x% ~" x* l, F8 P( u0 H( R2 C5 }, v j1 A6 G& k
ModSecurityEnabled on;
; [* z2 s! L0 J8 d* X) |& LModSecurityConfig modsecurity.conf;
. Y( Q3 Q$ a2 r' _% u+ P+ x下面是两个示例配置,php虚拟主机:
" @ P S7 v) A) U a2 {
6 [1 O* w9 m; n* d8 wserver {- F- g8 g& c; |* ]/ q5 B0 r
listen 80;
6 L5 h2 F: _4 F server_name 52os.net www.52os.net;
5 g0 n; |3 z) O* e) U% f , ]: n, m r/ y6 R5 l
location ~ \.php$ {
7 f% u) |/ M3 U) Y) N0 ]( L0 q ModSecurityEnabled on; U% v- G8 e5 H( A/ ?5 ]
ModSecurityConfig modsecurity.conf;3 ?) s% Q/ r" W, c6 r) T
3 }& O6 P- Y, J root /web/wordpress;
9 Q# _4 F ?- e) E6 }, { index index.php index.html index.htm;
F" Q: Y# f" y+ T 0 q- q2 W8 p7 H% b# Z6 d* g! A
fastcgi_pass 127.0.0.1:9000;
& S: G. | w E8 x: [ fastcgi_index index.php;
! S5 B: I' u4 I" G6 P fastcgi_param SCRIPT_FILENAME $Document_root$fastcgi_script_name;
. H) x' Y! @6 r include fastcgi_params;
/ B9 `: `. W( f, N }% N0 c. i% T! r& a, z
}
# g+ k; {0 a; I% k9 Pupstream负载均衡:7 Z8 U" e4 y! Z: h7 ]
2 ]9 l: r( Q4 A1 {
upstream 52os.net {
5 l/ R4 o' |& ~5 `/ J9 V server 192.168.1.100:8080;
7 @+ `% c% O1 U server 192.168.1.101:8080 backup;
- t( h" m* P4 `* [6 J/ q* {+ H}3 F2 |# v' ~5 ]
$ \' w$ B3 S6 V1 i* Hserver {8 y, Y3 |+ R; ~0 P$ T' [3 N
listen 80;; e7 }% I; w3 ?- X
server_name 52os.net www.52os.net;
3 m4 E* _+ b7 e- p) Z" a, k1 c; p( [9 ]- | y) j
location / {% k8 ~& Y& o) @# [* ^
ModSecurityEnabled on; % S( Q) M2 S4 Z5 v
ModSecurityConfig modsecurity.conf;
% I* Z8 B6 K9 |, h/ v! X2 ]
6 M% l0 k+ J$ O4 N0 K proxy_pass http://online;+ ^* h) D) M J/ s
proxy_redirect off;; m0 K& K4 p* f5 s
proxy_set_header Host $host;
/ t/ V! U- r' E& o; H; c$ `$ i proxy_set_header X-Real-IP $remote_addr;
( @( G# V9 N% ]8 J F$ l$ J proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;% o* U* t% { }7 j" K* V/ a
}/ g, G' n* M4 d4 M
}# I+ H+ c8 i2 W+ V+ E8 J t
六.测试
4 P% |- x. B4 |, Z* Y1 f* R# N {$ U6 q
我们启用了xss和sql注入的过滤,不正常的请求会直接返回403。以php环境为例,新建一个phpinfo.php内容为:
@' V9 O; E, b \5 Z6 w+ I# Q" _# q* ?, ]0 Y, h. h
<?php7 K' G. D4 [0 V \/ j9 Q e
phpinfo(); 2 A) L( B5 K v j! p% g
?>
+ ]9 N+ a4 N( S+ a5 Y- l% P0 }, C( `在浏览器中访问:4 o7 i6 Z& X% O' M" {* d9 S) b$ Q" T
9 S$ t B. }4 bhttp://www.52os.net/phpinfo.php?id=1 正常显示。9 _1 j5 Y ~9 l& @+ {, `2 H, D2 T
http://www.52os.net/phpinfo.php?id=1 and 1=1 返回403。
6 R4 D3 J1 n" L+ {6 Whttp://www.52os.net/phpinfo.php?search=<scritp>alert('xss');</script> 返回403。
" k' K4 \% s E说明sql注入和xss已经被过滤了
& f7 o; j. W/ t6 s" g3 s8 g$ m. @9 ]
) z' n. C: v6 G- h x七、安装过程中排错
# Q' p8 n/ J5 @5 \; Y/ E' @: Z+ U
1.缺少APXS会报错: @/ l8 W- t" e( j2 \6 j* X
$ D7 v' ]9 Q* M9 X& b* ~$ cconfigure: looking for Apache module support via DSO through APXS
0 I( ]: z. W4 K* e) X! C7 V1 dconfigure: error: couldn't find APXS; D* B9 D2 v9 J. _0 d# v' f9 F
apxs是一个为Apache HTTP服务器编译和安装扩展模块的工具,用于编译一个或多个源程序或目标代码文件为动态共享对象。5 b+ r' C9 g& _1 o; o
解决方法:
' |) L K( G6 |/ i7 @3 o0 J+ p
* D0 m( l+ U7 `) u" F" M7 h" Hyum install httpd-devel
, u5 W1 ~- }4 i4 |: `" e4 ]2.没有pcre
! n$ K- M2 N! @, |; b$ Q9 H5 A, V6 t. L1 H$ t) s/ {1 ]+ l/ ?; t
configure: *** pcre library not found.
( O7 u5 N' g% `+ I3 K/ hconfigure: error: pcre library is required
2 u- b3 s1 d3 {/ |* n2 f解决方法:
h+ ~) A5 V0 n) u7 X& q
$ |, M/ ^, g; j" H; i/ }8 kyum install pcre pcre-devel
2 r2 _0 |- i( Q) v4 B3.没有libxml2% U4 o0 ]3 O& u$ |6 E- z0 I" r
6 r: ]! j3 q _6 r3 p' y0 ]
1 {+ }" V. `5 d. t8 d. r& D8 bconfigure: *** xml library not found.
* V# S3 O4 W0 S. a3 ?) aconfigure: error: libxml2 is required- e0 w3 a I L3 Y, j
解决方法:& E4 X8 R# e3 E4 R1 e5 Z
: x8 ?( M7 ?4 b/ u5 s
yum install libxml2 libxml2-devel
& c+ }; L: U3 N. ?4.执行 /opt/tengine/sbin/nginx -m 时有警告& D$ c& }( |; H( ?: r
/ B2 b) I/ j8 x6 v) T7 XTengine version: Tengine/2.1.0 (nginx/1.6.2)1 q2 O6 `8 f0 _9 @9 \
nginx: [warn] ModSecurity: Loaded APR do not match with compiled!
2 w( f4 [- i! D& V3 d原因:modsecurity编译时和加载时的apr版本不一致造成的,并且会有以下error.log
- C9 I L2 Z" W- e# j% b' s8 U! D/ @5 H+ ^0 H' U4 r
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity for nginx (STABLE)/2.8.0 () configured.' k5 x: M e |" @
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: APR compiled version="1.5.0"; loaded version="1.3.9"& n$ |: _( {6 H/ z* M
2015/01/26 02:04:18 [warn] 29036#0: ModSecurity: Loaded APR do not match with compiled!
0 m) @% O. f8 S% i4 W8 {& w$ b2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: PCRE compiled version="7.8 "; loaded version="7.8 2008-09-05"7 t+ K& y6 s; [+ i9 b8 e/ V
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: LIBXML compiled version="2.7.6"
5 X m5 F/ o% o5 l( C' E9 _2015/01/26 02:04:18 [notice] 29036#0: Status engine is currently disabled, enable it by set SecStatusEngine to On.
0 l) b/ C/ f5 T& M; o% U解决方法,移除低版本的APR (1.3.9)) A+ |- B0 s+ D% l) x
. O1 |+ V% x5 q" }0 f) i
yum remove apr$ Y' B% g ?& @1 q8 \3 f% G. }
5.Error.log中有: Audit log: Failed to lock global mutex2 T/ B4 l) E" a
( L( x4 A c5 X7 d/ R2015/01/26 04:15:42 [error] 61610#0: [client 10.11.15.161] ModSecurity: Audit log: Failed to lock # J' h y a" C
global mutex: Permission denied [hostname ""] [uri "/i.php"] [unique_id "AcAcAcAcAcAcAcA4DcA7AcAc"]
. w+ d; r( k6 d, y7 B$ {解决方法:2 B7 l, B; f' u4 Z
编辑modsecurity.conf,注释掉默认的SecAuditLogType和SecAuditLog,添加以下内容:( Z# H. k- L: t: R3 a0 b* D
9 ]. M' r- q& `; v5 \0 CSecAuditLogDirMode 0777( u0 I9 A. A2 Y5 N' D C8 I
SecAuditLogFileMode 0550, ^) \' r% _2 z B- f
SecAuditLogStorageDir /var/log/modsecurity
) ]( E) t) h- J E% x; v- L5 ]SecAuditLogType Concurrent
8 V6 R+ W( v2 B) u: `. w参考文章:9 c9 h0 _& H. U: Y( j9 c% y) V
https://github.com/SpiderLabs/ModSecurity/wiki/Reference-Manual#Installation_for_NGINX% ~8 m' [! L1 e! R" U
http://drops.wooyun.org/tips/2614 |
|