找回密码
 立即注册

QQ登录

只需一步,快速开始

查看: 12736|回复: 0

nginx配合modsecurity实现WAF功能

[复制链接]
发表于 2017-10-19 16:53:31 | 显示全部楼层 |阅读模式
modsecurity原本是Apache上的一款开源waf,可以有效的增强web安全性,目前已经支持nginx和IIS,配合nginx的灵活和高效,可以打造成生产级的WAF,是保护和审核web安全的利器。" Q: g5 Y% p7 B( r5 a3 t" a0 V

' s+ d+ |3 m4 o一.准备工作
- Q) I  @! V( K. i3 N" K! t$ L8 L" x( f+ u
系统:centos 6.5 64位、 tengine 2.1.0, modsecurity 2.8.03 \5 f* q$ ~+ G+ ?! \4 E
: J" r/ \9 q) w- R
tengine : http://tengine.taobao.org/download/tengine-2.1.0.tar.gz( x) b0 M: K. ?: S% b
+ o3 t) j$ b0 i1 D. }
modsecurity for Nginx: https://www.modsecurity.org/tarball/2.8.0/modsecurity-2.8.0.tar.gz3 V& [; W' ^" L5 Q
4 d' |9 J1 _9 q4 }7 d5 [
OWASP规则集: https://github.com/SpiderLabs/owasp-modsecurity-crs9 h# W8 W% N9 S) Y8 U! r. a- X7 L: R
( i* u0 v3 ?! y# `1 h
依赖关系:
9 I8 U; M5 C( Q1 r2 u5 b/ ~tengine(nginx)依赖: pcre 、zlib、 openssl, 这三个包centos 6.5 系统源里都有:+ r/ O5 q! d+ e; O; G" ~$ o

. V* b, l. d) a' V  ^2 Cyum install zlib zlib-devel openssl openssl-devel  pcre pcre-devel) H' m  k1 J+ I
modsecurty依赖的包:pcre httpd-devel libxml2 apr1 Y- M/ C# P* e- j/ x) K7 I

4 T# |0 M6 R- W  {" Syum install httpd-devel apr apr-util-devel apr-devel  pcre pcre-devel  libxml2 libxml2-devel
$ _3 L1 k4 k$ f+ k! f二.启用standalone模块并编译8 O& [8 z- [/ m* G

; d$ c) H# I2 A7 }% k! Y8 j下载modsecurity for nginx 解压,进入解压后目录执行:6 h, E( [  i( ?1 n" i4 y' N

1 E6 i, Z; j$ M; O5 v  V./autogen.sh
6 C! S) j* o& v4 p8 J./configure --enable-standalone-module --disable-mlogc
9 u5 w3 s3 c' m1 ?4 Qmake & C  e5 d# M- D  ?" s1 z" x2 o- Q
三.nginx添加modsecurity模块
% c3 E$ Z8 D+ u) F0 h6 |( k/ U4 |3 C) A% V* m
在编译standalone后,nginx编译时可以通过"--add-module"添加modsecurity模块:6 Z3 d' L' c' i$ M& C* _. U( Q' H
6 v3 |9 ~5 Q) H
./configure --add-module=/root/modsecurity-2.8.0/nginx/modsecurity/  --prefix=/opt/tengine
" Y5 |& ^- V0 W6 d) Rmake && make install
. M' Z+ [% F$ U  [四.添加规则+ H1 v, b% v; q# P  t9 @
$ X3 A7 p2 I/ ?
modsecurity倾向于过滤和阻止web危险,之所以强大就在于规则,OWASP提供的规则是于社区志愿者维护的,被称为核心规则CRS(corerules),规则可靠强大,当然也可以自定义规则来满足各种需求。! b/ N* H' h- c6 {8 E7 k

' |8 s5 A- j1 H# _1.下载OWASP规则:, H( u: l* X' h' w: v# Q4 K

* S4 y( C8 C! h! l7 J& Xgit clone https://github.com/SpiderLabs/owasp-modsecurity-crs
" U; @1 _4 S; v9 ?1 r: F5 r  C8 r* S" w7 R
mv owasp-modsecurity-crs /opt/tengine/conf/; {7 F- r1 R, X5 p3 R
  L  F2 l' S& m
cd /opt/tengine/conf/owasp-modsecurity-crs && mv modsecurity_crs_10_setup.conf.example modsecurity_crs_10_setup.conf
% M2 t  [" L9 J! i2.启用OWASP规则:
0 C* e7 W" j" D/ ~" q- b' R( t6 O) t2 ]. T6 W
复制modsecurity源码目录下的modsecurity.conf-recommended和unicode.mapping到nginx的conf目录下,并将modsecurity.conf-recommended重新命名为modsecurity.conf。
& P6 l/ k' J# X
: [% L; G) W8 Q8 W) U8 @7 e编辑modsecurity.conf 文件,将SecRuleEngine设置为 on4 a: J  I$ p( z( a2 e

1 ~7 V( ]: W3 Z  y! r& I. l9 [' [% Z. @owasp-modsecurity-crs下有很多存放规则的文件夹,例如base_rules、experimental_rules、optional_rules、slr_rules,里面的规则按需要启用,需要启用的规则使用Include进来即可。
/ r7 X2 N2 L4 ?; ~$ }+ U# v4 V, l* ?, ~# H& H! \7 ]
Include owasp-modsecurity-crs/modsecurity_crs_10_setup.conf' T4 A9 T3 ]# N
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_sql_injection_attacks.conf$ A6 D7 ~" w' ?4 v
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_xss_attacks.conf
( L5 n6 T4 \; ?3 ]3 m( X! g% w. w! P: sInclude owasp-modsecurity-crs/base_rules/modsecurity_crs_40_generic_attacks.conf
0 P  A% P" N2 \1 ~Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_dos_protection.conf6 @6 ^! B, J- ]; D5 R+ I
Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_brute_force.conf
/ r! t5 H; X  O2 c% ?" TInclude owasp-modsecurity-crs/optional_rules/modsecurity_crs_16_session_hijacking.conf
9 @) B6 P7 ~1 B' c五.配置nginx& X& a  D. q, B2 g

7 \% \- c6 n4 O: v7 M' j1 l, q! I在需要启用modsecurity的主机的location下面加入下面两行即可:
7 A  l+ H. x' M: s" p8 b, R3 u4 e5 c5 T! M; ]4 R/ q
ModSecurityEnabled on;  9 T3 x. l" b2 y6 u
ModSecurityConfig modsecurity.conf;
9 f. H0 p, O& x1 }9 x下面是两个示例配置,php虚拟主机:
9 W7 O0 M# O& L) X8 |, H& g
  u1 L2 u  u, r' E3 ?/ F6 Bserver {
& E& _2 t! l5 p* _8 B( e) J6 Q0 ?      listen      80;  P. F6 r: L+ s: W
      server_name 52os.net www.52os.net;  r7 L* W7 B* V7 Q, `- g3 c0 l6 N
     
( I/ R+ B2 e3 v! |, m+ v' ~: c      location ~ \.php$ {: V. p; t& M! L7 D' u7 h3 u
      ModSecurityEnabled on;  
5 _. k/ j8 {; C% }& b+ ~      ModSecurityConfig modsecurity.conf;1 x; G  [2 V9 A' ~6 W
! Y0 j1 }, m$ |8 w  _
      root /web/wordpress;, R, w; f- c" b' X, ~( F* v( h$ ^
      index index.php index.html index.htm;
5 y8 Q1 B; f' \8 z) Q0 I9 n- G  
2 X8 b2 i0 q# r      fastcgi_pass   127.0.0.1:9000;
, a' T2 E7 v' B+ q4 R3 E) M# |+ r      fastcgi_index  index.php;# c( C6 V- J. B4 _9 Y  H) L
      fastcgi_param  SCRIPT_FILENAME  $Document_root$fastcgi_script_name;
$ @  ~9 i! {! w3 z+ N      include        fastcgi_params;  i2 A" _" K1 k! P$ y* I- I7 c* G
      }
3 M6 [7 G: l* \. u% }  }
6 I: g* ?5 i0 d6 H- \upstream负载均衡:
- i4 A/ I( s  y1 R
% V. n: K! y, g2 m3 pupstream 52os.net {
* M8 }9 F* e+ L8 X    server 192.168.1.100:8080;
: `$ u4 G  H; k) t9 ^# Z    server 192.168.1.101:8080 backup;
# V$ d( {0 X9 o0 L/ J}
/ D  N7 G/ B+ U% t! c
  X! [9 L; k! H2 }server {
! E6 ~: Q9 m* V5 E  alisten 80;8 }- J1 ]; c: g2 W* i$ G
server_name 52os.net www.52os.net;9 D& o6 ]. [/ f7 x  U- g

7 I/ w, V/ C0 olocation / {
3 [; t6 L2 q1 d3 H5 E! [    ModSecurityEnabled on;  / U8 \; z1 I8 u
    ModSecurityConfig modsecurity.conf;  
$ G' m6 m: S4 N" J4 T2 U& d# t' k0 K
( O" l5 |% t! h4 K        proxy_pass http://online;% H, F( s! H1 e/ ^  D8 k& @
        proxy_redirect         off;% i/ O& y6 m7 f3 m2 S$ ?2 R
        proxy_set_header Host $host;" J  R- u. a+ I+ i5 a5 m
        proxy_set_header X-Real-IP $remote_addr;
  t1 `$ r  V8 y1 @6 l* {) `, [        proxy_set_header  X-Forwarded-For $proxy_add_x_forwarded_for;
" _) N' U; @! l& ], e9 G& @    }% j' R8 L/ |+ T% r- \
}, `$ ^( l# v0 r, F4 f0 F  S
六.测试3 d0 M# y3 C5 F; H2 o7 w
1 i) v7 t5 l# c  k
我们启用了xss和sql注入的过滤,不正常的请求会直接返回403。以php环境为例,新建一个phpinfo.php内容为:
5 U' a% m# K( g/ _1 |* `4 H
, P9 J% y% X* A<?php$ ?1 s# q% G) m; o+ u
    phpinfo();    # N; N7 W7 R. w# M  [
?>
$ D8 C4 o. ^7 C' z在浏览器中访问:
- c( G: `1 a' r6 Q! E0 Y2 v9 Y- b+ N
http://www.52os.net/phpinfo.php?id=1 正常显示。3 L5 W# W3 \3 M! E* _  u
http://www.52os.net/phpinfo.php?id=1 and 1=1  返回403。7 x. A4 X/ c- Q3 S9 J
http://www.52os.net/phpinfo.php?search=<scritp>alert('xss');</script>  返回403。: F7 w& Y; G! E& b
说明sql注入和xss已经被过滤了
, _: P2 A' Y. N7 ~9 b' I" W- e  C# [. c/ ^, @) [! |) O" W' ^
七、安装过程中排错
" d9 f& r3 S" p3 C% Q" {; Q! Z( a$ v  o/ K: p/ W
1.缺少APXS会报错. S5 O8 L# H$ S/ u* }9 a' f! T5 T9 |
3 ?3 u' ^" y6 y  n/ m8 ^: y9 x
configure: looking for Apache module support via DSO through APXS
. p- h8 w9 E  N& k) t! J. k+ t2 [* u1 Hconfigure: error: couldn't find APXS1 J, i# `% S4 u
apxs是一个为Apache HTTP服务器编译和安装扩展模块的工具,用于编译一个或多个源程序或目标代码文件为动态共享对象。$ Q. l" w# P2 ?6 U8 m
解决方法:
8 \0 ~3 U3 j1 S/ v- r* o/ @7 r# m. B) ^
yum install httpd-devel
" \1 j' s* g8 w& ]/ J7 B7 l2.没有pcre. w" y1 }! Z) g: B2 P  X5 G! i, i8 }
3 r4 s6 n4 F; {
configure: *** pcre library not found.
3 w0 b1 M6 p, w5 q5 Sconfigure: error: pcre library is required
1 Y5 Y4 X' e  y4 Y解决方法:  I+ b- r5 R. k% H" x
1 F! \( \0 Y) T) Z4 t
yum install pcre pcre-devel
/ n7 z' j$ ]5 A! R; V3.没有libxml2/ p  d5 j( M: [. S5 o' R% a& F) h/ ]! I
8 _/ W1 \+ g3 w/ t' c; x

% X( S9 K5 P2 n1 d/ J% {0 @configure: *** xml library not found.
) D. u. s& h! G( N  Y& econfigure: error: libxml2 is required/ b) W/ N) D* y4 g$ s5 R0 r) B
解决方法:6 \, J' |4 e  }% K/ Q. U# q" w

% F" v# P/ }( e6 G. tyum install  libxml2 libxml2-devel
$ T  a9 R  _5 b% L9 N4.执行 /opt/tengine/sbin/nginx -m 时有警告
' A+ g9 ^7 p3 k5 |' w7 F' v4 m' ?+ u6 {/ z6 Y8 U  O+ s" r- `
Tengine version: Tengine/2.1.0 (nginx/1.6.2); M- z4 D8 S9 F- \. ~
nginx: [warn] ModSecurity: Loaded APR do not match with compiled!
, m0 g, R* C6 c' S原因:modsecurity编译时和加载时的apr版本不一致造成的,并且会有以下error.log
  s& S3 V: \2 k+ [: Q  l0 N
  c" F; r; {8 X! u0 J, k8 Y* A6 y2015/01/26 02:04:18 [notice] 29036#0: ModSecurity for nginx (STABLE)/2.8.0 () configured.
6 ~7 M/ \# T% {2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: APR compiled version="1.5.0"; loaded     version="1.3.9"6 q; J2 Q/ l  j4 A; ^
2015/01/26 02:04:18 [warn] 29036#0: ModSecurity: Loaded APR do not match with compiled!
/ ?+ Z1 X( T& F2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: PCRE compiled version="7.8 "; loaded version="7.8 2008-09-05"; N6 S% D; @/ ?- ?
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: LIBXML compiled version="2.7.6"
8 j! x3 l' b9 Z# B% k; B1 C( A2015/01/26 02:04:18 [notice] 29036#0: Status engine is currently disabled, enable it by set SecStatusEngine to On.# s/ B# c) m" X$ y! v# j6 m
解决方法,移除低版本的APR (1.3.9)
9 A$ }4 V) W, W
+ t. U  I; Y' j' Yyum remove apr  M2 b4 M1 j+ M% A2 v: Y" j
5.Error.log中有: Audit log: Failed to lock global mutex
+ ~5 N) t) k, t& Y/ W
4 \$ J( |: Y; l+ A# ^2015/01/26 04:15:42 [error] 61610#0: [client 10.11.15.161] ModSecurity: Audit log: Failed to lock     
+ g' g7 y: C( S8 Fglobal mutex: Permission denied [hostname ""] [uri "/i.php"] [unique_id "AcAcAcAcAcAcAcA4DcA7AcAc"]8 j& v5 Y, C$ m4 H% x9 O" N
解决方法:/ p& V2 l% L* @. g- a. P
编辑modsecurity.conf,注释掉默认的SecAuditLogType和SecAuditLog,添加以下内容:! S4 A1 @! ~# ], ^& Z. m

( b9 P* f6 j8 i6 j* B! J, NSecAuditLogDirMode 0777
! Y9 N# C+ t0 E$ Y& ASecAuditLogFileMode 0550
1 ]7 ?* R3 F6 J! NSecAuditLogStorageDir /var/log/modsecurity
! e1 h7 u  N  G8 MSecAuditLogType Concurrent
9 T. _- K0 u4 ]参考文章:* O2 K( e- ~7 ]
https://github.com/SpiderLabs/ModSecurity/wiki/Reference-Manual#Installation_for_NGINX
3 j+ i# J) ^2 b$ n0 |, phttp://drops.wooyun.org/tips/2614
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

QQ|Archiver|手机版|小黑屋|第一站论坛 ( 蜀ICP备06004864号-6 )

GMT+8, 2026-10-5 17:10 , Processed in 0.108535 second(s), 19 queries .

Powered by Discuz! X3.5

© 2001-2026 Discuz! Team.

快速回复 返回顶部 返回列表