|
|
modsecurity原本是Apache上的一款开源waf,可以有效的增强web安全性,目前已经支持nginx和IIS,配合nginx的灵活和高效,可以打造成生产级的WAF,是保护和审核web安全的利器。- t( T: x; U; p' e* f
) a4 V6 d' T5 I( R' Y: |8 O
一.准备工作
6 m6 S6 K; @' V3 j+ c6 D/ w+ n; k+ k3 N+ ~
系统:centos 6.5 64位、 tengine 2.1.0, modsecurity 2.8.0& T0 l8 K$ `% F- B7 V
3 V. ~" z1 P3 h) a6 q/ Z" F9 r7 F. |3 btengine : http://tengine.taobao.org/download/tengine-2.1.0.tar.gz
2 N8 L$ Z: F7 [! M3 ?# C; i8 ^ H1 O; r% u0 N
modsecurity for Nginx: https://www.modsecurity.org/tarball/2.8.0/modsecurity-2.8.0.tar.gz$ q% u. M/ V1 x( L4 t# M
- A8 Q4 g; y' T3 _& P' I$ L( w
OWASP规则集: https://github.com/SpiderLabs/owasp-modsecurity-crs. j1 l+ g9 t0 @1 y. r
% C" p. U7 C4 J) z
依赖关系:
" V4 K: q1 c# g F$ v6 q/ Z2 _tengine(nginx)依赖: pcre 、zlib、 openssl, 这三个包centos 6.5 系统源里都有:
% E! }2 A, d2 m/ U
% Z. `8 t i1 X5 Oyum install zlib zlib-devel openssl openssl-devel pcre pcre-devel
3 ?8 G9 p% Y! r: b' f6 y+ Qmodsecurty依赖的包:pcre httpd-devel libxml2 apr
" M+ [& d: a7 M
* I1 _/ T- k: r/ F3 H; ryum install httpd-devel apr apr-util-devel apr-devel pcre pcre-devel libxml2 libxml2-devel
6 D2 z6 J/ K# H- M Z" A二.启用standalone模块并编译
/ R/ j& |; h D" ?) i, r) A8 i6 |% G4 }0 _# d8 @5 G% q. {7 ~
下载modsecurity for nginx 解压,进入解压后目录执行:4 F% ]0 G9 c! a) u* [, ~( {$ }/ v
( i8 H- Q' n4 s+ b9 r+ [./autogen.sh/ v; P" l* U; O# x/ D, U/ O
./configure --enable-standalone-module --disable-mlogc4 L* U7 c8 g" W* [ h3 P. i
make % d7 e j! \0 G- s/ y7 ~
三.nginx添加modsecurity模块
, |% G+ B* Y+ a4 A) \9 Z, P. E, n" o+ P3 J2 [$ ?. u
在编译standalone后,nginx编译时可以通过"--add-module"添加modsecurity模块:4 W/ v u! v0 L" H7 j, R' X
/ l3 H7 t- H. E./configure --add-module=/root/modsecurity-2.8.0/nginx/modsecurity/ --prefix=/opt/tengine: f( R6 T3 J* X3 u5 `
make && make install
* E4 d, X! I4 `# s2 o0 b四.添加规则, U! i1 ]5 V6 a; j
( T# B, B. d' D9 a/ T% N/ lmodsecurity倾向于过滤和阻止web危险,之所以强大就在于规则,OWASP提供的规则是于社区志愿者维护的,被称为核心规则CRS(corerules),规则可靠强大,当然也可以自定义规则来满足各种需求。; m$ r* s7 H0 M7 l+ B( k
0 d+ [. R9 l" q0 B2 F1.下载OWASP规则:7 N: P3 @0 s, B! C6 |
, ~; r; X7 ?0 ?* |git clone https://github.com/SpiderLabs/owasp-modsecurity-crs5 S( L4 Q: E: Y4 }. `8 \! \
8 D) W8 K6 X* I; T
mv owasp-modsecurity-crs /opt/tengine/conf/: @5 |3 o+ o! c- M% E
5 L, L9 l" @& Tcd /opt/tengine/conf/owasp-modsecurity-crs && mv modsecurity_crs_10_setup.conf.example modsecurity_crs_10_setup.conf$ L4 p* u$ {+ `
2.启用OWASP规则:
, }8 o! ^' i/ t# ~6 [# X6 j+ r2 N- U, t; w# Y6 C3 g; k7 U( \& \; H% l
复制modsecurity源码目录下的modsecurity.conf-recommended和unicode.mapping到nginx的conf目录下,并将modsecurity.conf-recommended重新命名为modsecurity.conf。1 Q/ w, P% o( k& E
% Y% w9 c& G# q {. e6 V
编辑modsecurity.conf 文件,将SecRuleEngine设置为 on
' F3 n3 ], V e1 @+ U& t; }/ l: a4 d
owasp-modsecurity-crs下有很多存放规则的文件夹,例如base_rules、experimental_rules、optional_rules、slr_rules,里面的规则按需要启用,需要启用的规则使用Include进来即可。. Y* }0 d4 L- {$ [' {: X) h7 A
) t) `$ i+ U0 S* l" k* E; ?
Include owasp-modsecurity-crs/modsecurity_crs_10_setup.conf8 ]/ }8 G% `6 T
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_sql_injection_attacks.conf
! d& L& ~* U. t" \+ o) D9 a* K( vInclude owasp-modsecurity-crs/base_rules/modsecurity_crs_41_xss_attacks.conf/ A" q* O2 {% k; K
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_40_generic_attacks.conf/ p: x# s9 n, M
Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_dos_protection.conf
( H3 ~ P" g* T* nInclude owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_brute_force.conf
& {; V+ D3 t$ E+ Q) ?' u( WInclude owasp-modsecurity-crs/optional_rules/modsecurity_crs_16_session_hijacking.conf
" E! d" c$ n0 I1 C. p \五.配置nginx$ O0 S# L5 w9 i& u% @0 `
& b/ r+ `6 T! L; S4 I6 T
在需要启用modsecurity的主机的location下面加入下面两行即可:
) a0 v. C0 B; O. x2 B
! ?- _9 X! N2 J# AModSecurityEnabled on; ' U c: C7 @: W1 D# x
ModSecurityConfig modsecurity.conf;4 W* L6 ^/ }" E3 n9 I
下面是两个示例配置,php虚拟主机:
4 d* \( g( P- k$ L# y3 t
+ r' w5 U$ v# F( aserver {9 J3 m$ O- a6 Z1 I- |# Y% U
listen 80;
8 x& l# ^. J$ |: l* [3 u server_name 52os.net www.52os.net;8 A% o/ y* j" _- E- r( f6 U
$ T% r" T0 b6 I6 ~ location ~ \.php$ { {. b+ k1 Q% `0 y5 ~5 O3 B
ModSecurityEnabled on;
1 v4 Q7 y% z& ~. w8 W$ t ModSecurityConfig modsecurity.conf;7 d4 H! p0 l# x( g# U; J+ n
& M0 M7 ]3 Z2 k! O) s3 O
root /web/wordpress;, R0 w& u* B3 _/ [' m5 x0 P
index index.php index.html index.htm;) f5 `$ }# `. p' Z
( W# Z, v g! ?; q; U5 T fastcgi_pass 127.0.0.1:9000;: i9 x9 P7 t5 _ n8 L' M) F
fastcgi_index index.php;
6 ^: i- u0 k& p' N( [# _ fastcgi_param SCRIPT_FILENAME $Document_root$fastcgi_script_name;+ ?7 r2 g! S, c, C: o6 i. j
include fastcgi_params;
6 v/ n- z) }6 ~4 ? }
0 y1 ^0 _/ `6 _4 ^ y0 w* j7 q }( s7 A% e0 A6 J/ Z) C: w
upstream负载均衡:. c7 a+ n. \- }( v/ P7 n
: X9 Y" ~1 N7 g# ]7 v& F- ]0 w
upstream 52os.net {
' V. o' N4 n' w& B! [7 l! a server 192.168.1.100:8080;4 r/ d6 l( B' f! W
server 192.168.1.101:8080 backup;
& ^0 k" N3 v; B6 `}5 @- p. g% K4 ~# W8 a
8 J% F. [' @1 X) l/ w
server {! I8 a* }& [2 ~, Y, q, e
listen 80;
: N, n. S* c5 dserver_name 52os.net www.52os.net;4 A: z, V7 B# C9 M
7 ^. R5 R3 w$ @
location / {
* W! d7 z, @& `1 Q ModSecurityEnabled on;
. V& w( b; {: A1 r- {% [ ModSecurityConfig modsecurity.conf; 0 Z+ c" ]; I2 |. @5 v) @
+ y$ k4 e4 i/ G2 m3 e6 Z1 R proxy_pass http://online;
: M& S9 W& ^* f$ L% p proxy_redirect off;
) m0 P! v8 r, @% | proxy_set_header Host $host;
T2 k% i+ {+ O proxy_set_header X-Real-IP $remote_addr;" V- M) o* \ _9 |& |+ @7 l0 w
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;5 d6 U! _0 f% B, Y: { I" ?
}
- K1 ~2 ]4 U( t# I) l: Z7 A$ Z}+ u a( l6 t8 R( F
六.测试9 m# u! R/ A+ a9 \* w
, M! M3 E" g0 b
我们启用了xss和sql注入的过滤,不正常的请求会直接返回403。以php环境为例,新建一个phpinfo.php内容为:1 ^' N9 n9 U2 i% B3 _4 O# E4 F- @: r
. L+ F6 i6 Q9 S0 A" o
<?php
0 M$ N* C' V0 f# E8 d" m phpinfo();
! J' q- z3 T* \) k& x* ~' M?>+ ?9 W; O$ o& J8 l( g, o+ S3 s
在浏览器中访问:. R K: E$ ?: O/ \$ ~* J
& ^. K, i3 L* U) w# L0 n- W
http://www.52os.net/phpinfo.php?id=1 正常显示。
, Z% F+ S- Q- R3 O5 w$ l6 `% thttp://www.52os.net/phpinfo.php?id=1 and 1=1 返回403。) H) K% z: U6 A6 V
http://www.52os.net/phpinfo.php?search=<scritp>alert('xss');</script> 返回403。- L0 a0 S8 @; I# j
说明sql注入和xss已经被过滤了7 \" Y" V6 ^( z8 {/ f
5 K9 S; n, s. d$ r3 G0 c* ~1 h七、安装过程中排错
q$ C ^" K% G. Q1 S0 L4 T7 ^# B# p
8 u* _7 B/ l' e; T9 }8 k1.缺少APXS会报错
9 l7 R2 X; `9 D- N- T/ d2 t7 \) n6 ]( E- p* h8 c5 _
configure: looking for Apache module support via DSO through APXS& o2 o1 u% V- y$ O! [3 j2 d% p
configure: error: couldn't find APXS# a/ j: R/ \8 O4 Y4 v
apxs是一个为Apache HTTP服务器编译和安装扩展模块的工具,用于编译一个或多个源程序或目标代码文件为动态共享对象。! p) R% j- ]( s$ |- {6 E
解决方法:! ]: w, e5 Y& A
5 O/ i* c9 J: t7 v
yum install httpd-devel7 p$ C$ m0 B( g& X! |4 N i
2.没有pcre# b; r% @* r# N, W6 f$ ?, [6 f
/ X. }4 M9 s3 E* k5 L+ c
configure: *** pcre library not found.
' m6 `+ I6 s- H) nconfigure: error: pcre library is required1 K0 X8 u9 l" H2 [6 p" ^* F) o
解决方法:
. L% P ?% E ?3 |8 m# ]9 W$ `( ^# Q4 ]0 F. g
yum install pcre pcre-devel( g% t6 k2 D; f4 P- k( u7 [% Q( A
3.没有libxml26 ~8 q0 v' q5 j3 {
$ d& ?. T. ]* ]0 T
+ J+ G- S6 d9 g# g
configure: *** xml library not found.
, B' {' s: |& [# A7 v) O1 x9 J7 wconfigure: error: libxml2 is required% v. I5 o% v, F! D0 i
解决方法:6 v8 l0 w) |# K" k2 s* c1 k4 E( G
1 n2 j. |) A4 p4 A- c1 u: fyum install libxml2 libxml2-devel% U8 \0 P2 T: N8 c9 H
4.执行 /opt/tengine/sbin/nginx -m 时有警告8 D1 ]5 e8 ]( I7 j1 |4 C
8 f; F9 S: M% S
Tengine version: Tengine/2.1.0 (nginx/1.6.2)- {1 i2 \5 i6 V# A
nginx: [warn] ModSecurity: Loaded APR do not match with compiled!, S3 d" S8 _# _1 ]' f4 _
原因:modsecurity编译时和加载时的apr版本不一致造成的,并且会有以下error.log
: ^5 |7 F2 X m, A8 n4 r
) l. e+ {5 a# J0 [: b- ~2015/01/26 02:04:18 [notice] 29036#0: ModSecurity for nginx (STABLE)/2.8.0 () configured. ?; ~9 E& C1 i% `4 `
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: APR compiled version="1.5.0"; loaded version="1.3.9"% g* P- D1 d* X
2015/01/26 02:04:18 [warn] 29036#0: ModSecurity: Loaded APR do not match with compiled!" h) k" a, [+ B) |( S$ {7 l
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: PCRE compiled version="7.8 "; loaded version="7.8 2008-09-05"
1 B( k/ S6 Z" Q2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: LIBXML compiled version="2.7.6"
; t3 y, ?* O. j5 F D2015/01/26 02:04:18 [notice] 29036#0: Status engine is currently disabled, enable it by set SecStatusEngine to On.
1 {, Y( k2 K$ ~2 }4 z" n# k3 R9 j解决方法,移除低版本的APR (1.3.9)' n h& w+ t" _/ s6 }7 I' L
* D1 ?9 ^' V# E# [! [
yum remove apr$ ^. m: {) f3 D3 z$ [
5.Error.log中有: Audit log: Failed to lock global mutex: C, z6 v* E5 L% ~! m
+ u% Q' i# n V# b5 z/ B a& }0 \2015/01/26 04:15:42 [error] 61610#0: [client 10.11.15.161] ModSecurity: Audit log: Failed to lock 9 g0 K. s) V# u2 ?0 _0 W) T
global mutex: Permission denied [hostname ""] [uri "/i.php"] [unique_id "AcAcAcAcAcAcAcA4DcA7AcAc"]0 m$ o* r4 S( `8 y$ u* E$ o
解决方法:% P, Y) z# z1 X
编辑modsecurity.conf,注释掉默认的SecAuditLogType和SecAuditLog,添加以下内容:
+ n. J, M1 q% @; e; U2 D0 g/ r. U# f: w% ~% t& D
SecAuditLogDirMode 07775 Q3 j% u r* L ]; h' _
SecAuditLogFileMode 0550& b- j) A% O+ f+ `6 r* |
SecAuditLogStorageDir /var/log/modsecurity
& z7 }2 l9 K$ F4 s* DSecAuditLogType Concurrent5 ` ?, F$ X' Z) U+ N
参考文章:
+ R. W3 m% t6 _( R8 Z( k6 ]https://github.com/SpiderLabs/ModSecurity/wiki/Reference-Manual#Installation_for_NGINX
) Q$ ?( ~7 Y5 f" ?) H! t; ]http://drops.wooyun.org/tips/2614 |
|