|
|
modsecurity原本是Apache上的一款开源waf,可以有效的增强web安全性,目前已经支持nginx和IIS,配合nginx的灵活和高效,可以打造成生产级的WAF,是保护和审核web安全的利器。" Q: g5 Y% p7 B( r5 a3 t" a0 V
' s+ d+ |3 m4 o一.准备工作
- Q) I @! V( K. i3 N" K! t$ L8 L" x( f+ u
系统:centos 6.5 64位、 tengine 2.1.0, modsecurity 2.8.03 \5 f* q$ ~+ G+ ?! \4 E
: J" r/ \9 q) w- R
tengine : http://tengine.taobao.org/download/tengine-2.1.0.tar.gz( x) b0 M: K. ?: S% b
+ o3 t) j$ b0 i1 D. }
modsecurity for Nginx: https://www.modsecurity.org/tarball/2.8.0/modsecurity-2.8.0.tar.gz3 V& [; W' ^" L5 Q
4 d' |9 J1 _9 q4 }7 d5 [
OWASP规则集: https://github.com/SpiderLabs/owasp-modsecurity-crs9 h# W8 W% N9 S) Y8 U! r. a- X7 L: R
( i* u0 v3 ?! y# `1 h
依赖关系:
9 I8 U; M5 C( Q1 r2 u5 b/ ~tengine(nginx)依赖: pcre 、zlib、 openssl, 这三个包centos 6.5 系统源里都有:+ r/ O5 q! d+ e; O; G" ~$ o
. V* b, l. d) a' V ^2 Cyum install zlib zlib-devel openssl openssl-devel pcre pcre-devel) H' m k1 J+ I
modsecurty依赖的包:pcre httpd-devel libxml2 apr1 Y- M/ C# P* e- j/ x) K7 I
4 T# |0 M6 R- W {" Syum install httpd-devel apr apr-util-devel apr-devel pcre pcre-devel libxml2 libxml2-devel
$ _3 L1 k4 k$ f+ k! f二.启用standalone模块并编译8 O& [8 z- [/ m* G
; d$ c) H# I2 A7 }% k! Y8 j下载modsecurity for nginx 解压,进入解压后目录执行:6 h, E( [ i( ?1 n" i4 y' N
1 E6 i, Z; j$ M; O5 v V./autogen.sh
6 C! S) j* o& v4 p8 J./configure --enable-standalone-module --disable-mlogc
9 u5 w3 s3 c' m1 ?4 Qmake & C e5 d# M- D ?" s1 z" x2 o- Q
三.nginx添加modsecurity模块
% c3 E$ Z8 D+ u) F0 h6 |( k/ U4 |3 C) A% V* m
在编译standalone后,nginx编译时可以通过"--add-module"添加modsecurity模块:6 Z3 d' L' c' i$ M& C* _. U( Q' H
6 v3 |9 ~5 Q) H
./configure --add-module=/root/modsecurity-2.8.0/nginx/modsecurity/ --prefix=/opt/tengine
" Y5 |& ^- V0 W6 d) Rmake && make install
. M' Z+ [% F$ U [四.添加规则+ H1 v, b% v; q# P t9 @
$ X3 A7 p2 I/ ?
modsecurity倾向于过滤和阻止web危险,之所以强大就在于规则,OWASP提供的规则是于社区志愿者维护的,被称为核心规则CRS(corerules),规则可靠强大,当然也可以自定义规则来满足各种需求。! b/ N* H' h- c6 {8 E7 k
' |8 s5 A- j1 H# _1.下载OWASP规则:, H( u: l* X' h' w: v# Q4 K
* S4 y( C8 C! h! l7 J& Xgit clone https://github.com/SpiderLabs/owasp-modsecurity-crs
" U; @1 _4 S; v9 ?1 r: F5 r C8 r* S" w7 R
mv owasp-modsecurity-crs /opt/tengine/conf/; {7 F- r1 R, X5 p3 R
L F2 l' S& m
cd /opt/tengine/conf/owasp-modsecurity-crs && mv modsecurity_crs_10_setup.conf.example modsecurity_crs_10_setup.conf
% M2 t [" L9 J! i2.启用OWASP规则:
0 C* e7 W" j" D/ ~" q- b' R( t6 O) t2 ]. T6 W
复制modsecurity源码目录下的modsecurity.conf-recommended和unicode.mapping到nginx的conf目录下,并将modsecurity.conf-recommended重新命名为modsecurity.conf。
& P6 l/ k' J# X
: [% L; G) W8 Q8 W) U8 @7 e编辑modsecurity.conf 文件,将SecRuleEngine设置为 on4 a: J I$ p( z( a2 e
1 ~7 V( ]: W3 Z y! r& I. l9 [' [% Z. @owasp-modsecurity-crs下有很多存放规则的文件夹,例如base_rules、experimental_rules、optional_rules、slr_rules,里面的规则按需要启用,需要启用的规则使用Include进来即可。
/ r7 X2 N2 L4 ?; ~$ }+ U# v4 V, l* ?, ~# H& H! \7 ]
Include owasp-modsecurity-crs/modsecurity_crs_10_setup.conf' T4 A9 T3 ]# N
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_sql_injection_attacks.conf$ A6 D7 ~" w' ?4 v
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_xss_attacks.conf
( L5 n6 T4 \; ?3 ]3 m( X! g% w. w! P: sInclude owasp-modsecurity-crs/base_rules/modsecurity_crs_40_generic_attacks.conf
0 P A% P" N2 \1 ~Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_dos_protection.conf6 @6 ^! B, J- ]; D5 R+ I
Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_brute_force.conf
/ r! t5 H; X O2 c% ?" TInclude owasp-modsecurity-crs/optional_rules/modsecurity_crs_16_session_hijacking.conf
9 @) B6 P7 ~1 B' c五.配置nginx& X& a D. q, B2 g
7 \% \- c6 n4 O: v7 M' j1 l, q! I在需要启用modsecurity的主机的location下面加入下面两行即可:
7 A l+ H. x' M: s" p8 b, R3 u4 e5 c5 T! M; ]4 R/ q
ModSecurityEnabled on; 9 T3 x. l" b2 y6 u
ModSecurityConfig modsecurity.conf;
9 f. H0 p, O& x1 }9 x下面是两个示例配置,php虚拟主机:
9 W7 O0 M# O& L) X8 |, H& g
u1 L2 u u, r' E3 ?/ F6 Bserver {
& E& _2 t! l5 p* _8 B( e) J6 Q0 ? listen 80; P. F6 r: L+ s: W
server_name 52os.net www.52os.net; r7 L* W7 B* V7 Q, `- g3 c0 l6 N
( I/ R+ B2 e3 v! |, m+ v' ~: c location ~ \.php$ {: V. p; t& M! L7 D' u7 h3 u
ModSecurityEnabled on;
5 _. k/ j8 {; C% }& b+ ~ ModSecurityConfig modsecurity.conf;1 x; G [2 V9 A' ~6 W
! Y0 j1 }, m$ |8 w _
root /web/wordpress;, R, w; f- c" b' X, ~( F* v( h$ ^
index index.php index.html index.htm;
5 y8 Q1 B; f' \8 z) Q0 I9 n- G
2 X8 b2 i0 q# r fastcgi_pass 127.0.0.1:9000;
, a' T2 E7 v' B+ q4 R3 E) M# |+ r fastcgi_index index.php;# c( C6 V- J. B4 _9 Y H) L
fastcgi_param SCRIPT_FILENAME $Document_root$fastcgi_script_name;
$ @ ~9 i! {! w3 z+ N include fastcgi_params; i2 A" _" K1 k! P$ y* I- I7 c* G
}
3 M6 [7 G: l* \. u% } }
6 I: g* ?5 i0 d6 H- \upstream负载均衡:
- i4 A/ I( s y1 R
% V. n: K! y, g2 m3 pupstream 52os.net {
* M8 }9 F* e+ L8 X server 192.168.1.100:8080;
: `$ u4 G H; k) t9 ^# Z server 192.168.1.101:8080 backup;
# V$ d( {0 X9 o0 L/ J}
/ D N7 G/ B+ U% t! c
X! [9 L; k! H2 }server {
! E6 ~: Q9 m* V5 E alisten 80;8 }- J1 ]; c: g2 W* i$ G
server_name 52os.net www.52os.net;9 D& o6 ]. [/ f7 x U- g
7 I/ w, V/ C0 olocation / {
3 [; t6 L2 q1 d3 H5 E! [ ModSecurityEnabled on; / U8 \; z1 I8 u
ModSecurityConfig modsecurity.conf;
$ G' m6 m: S4 N" J4 T2 U& d# t' k0 K
( O" l5 |% t! h4 K proxy_pass http://online;% H, F( s! H1 e/ ^ D8 k& @
proxy_redirect off;% i/ O& y6 m7 f3 m2 S$ ?2 R
proxy_set_header Host $host;" J R- u. a+ I+ i5 a5 m
proxy_set_header X-Real-IP $remote_addr;
t1 `$ r V8 y1 @6 l* {) `, [ proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
" _) N' U; @! l& ], e9 G& @ }% j' R8 L/ |+ T% r- \
}, `$ ^( l# v0 r, F4 f0 F S
六.测试3 d0 M# y3 C5 F; H2 o7 w
1 i) v7 t5 l# c k
我们启用了xss和sql注入的过滤,不正常的请求会直接返回403。以php环境为例,新建一个phpinfo.php内容为:
5 U' a% m# K( g/ _1 |* `4 H
, P9 J% y% X* A<?php$ ?1 s# q% G) m; o+ u
phpinfo(); # N; N7 W7 R. w# M [
?>
$ D8 C4 o. ^7 C' z在浏览器中访问:
- c( G: `1 a' r6 Q! E0 Y2 v9 Y- b+ N
http://www.52os.net/phpinfo.php?id=1 正常显示。3 L5 W# W3 \3 M! E* _ u
http://www.52os.net/phpinfo.php?id=1 and 1=1 返回403。7 x. A4 X/ c- Q3 S9 J
http://www.52os.net/phpinfo.php?search=<scritp>alert('xss');</script> 返回403。: F7 w& Y; G! E& b
说明sql注入和xss已经被过滤了
, _: P2 A' Y. N7 ~9 b' I" W- e C# [. c/ ^, @) [! |) O" W' ^
七、安装过程中排错
" d9 f& r3 S" p3 C% Q" {; Q! Z( a$ v o/ K: p/ W
1.缺少APXS会报错. S5 O8 L# H$ S/ u* }9 a' f! T5 T9 |
3 ?3 u' ^" y6 y n/ m8 ^: y9 x
configure: looking for Apache module support via DSO through APXS
. p- h8 w9 E N& k) t! J. k+ t2 [* u1 Hconfigure: error: couldn't find APXS1 J, i# `% S4 u
apxs是一个为Apache HTTP服务器编译和安装扩展模块的工具,用于编译一个或多个源程序或目标代码文件为动态共享对象。$ Q. l" w# P2 ?6 U8 m
解决方法:
8 \0 ~3 U3 j1 S/ v- r* o/ @7 r# m. B) ^
yum install httpd-devel
" \1 j' s* g8 w& ]/ J7 B7 l2.没有pcre. w" y1 }! Z) g: B2 P X5 G! i, i8 }
3 r4 s6 n4 F; {
configure: *** pcre library not found.
3 w0 b1 M6 p, w5 q5 Sconfigure: error: pcre library is required
1 Y5 Y4 X' e y4 Y解决方法: I+ b- r5 R. k% H" x
1 F! \( \0 Y) T) Z4 t
yum install pcre pcre-devel
/ n7 z' j$ ]5 A! R; V3.没有libxml2/ p d5 j( M: [. S5 o' R% a& F) h/ ]! I
8 _/ W1 \+ g3 w/ t' c; x
% X( S9 K5 P2 n1 d/ J% {0 @configure: *** xml library not found.
) D. u. s& h! G( N Y& econfigure: error: libxml2 is required/ b) W/ N) D* y4 g$ s5 R0 r) B
解决方法:6 \, J' |4 e }% K/ Q. U# q" w
% F" v# P/ }( e6 G. tyum install libxml2 libxml2-devel
$ T a9 R _5 b% L9 N4.执行 /opt/tengine/sbin/nginx -m 时有警告
' A+ g9 ^7 p3 k5 |' w7 F' v4 m' ?+ u6 {/ z6 Y8 U O+ s" r- `
Tengine version: Tengine/2.1.0 (nginx/1.6.2); M- z4 D8 S9 F- \. ~
nginx: [warn] ModSecurity: Loaded APR do not match with compiled!
, m0 g, R* C6 c' S原因:modsecurity编译时和加载时的apr版本不一致造成的,并且会有以下error.log
s& S3 V: \2 k+ [: Q l0 N
c" F; r; {8 X! u0 J, k8 Y* A6 y2015/01/26 02:04:18 [notice] 29036#0: ModSecurity for nginx (STABLE)/2.8.0 () configured.
6 ~7 M/ \# T% {2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: APR compiled version="1.5.0"; loaded version="1.3.9"6 q; J2 Q/ l j4 A; ^
2015/01/26 02:04:18 [warn] 29036#0: ModSecurity: Loaded APR do not match with compiled!
/ ?+ Z1 X( T& F2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: PCRE compiled version="7.8 "; loaded version="7.8 2008-09-05"; N6 S% D; @/ ?- ?
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: LIBXML compiled version="2.7.6"
8 j! x3 l' b9 Z# B% k; B1 C( A2015/01/26 02:04:18 [notice] 29036#0: Status engine is currently disabled, enable it by set SecStatusEngine to On.# s/ B# c) m" X$ y! v# j6 m
解决方法,移除低版本的APR (1.3.9)
9 A$ }4 V) W, W
+ t. U I; Y' j' Yyum remove apr M2 b4 M1 j+ M% A2 v: Y" j
5.Error.log中有: Audit log: Failed to lock global mutex
+ ~5 N) t) k, t& Y/ W
4 \$ J( |: Y; l+ A# ^2015/01/26 04:15:42 [error] 61610#0: [client 10.11.15.161] ModSecurity: Audit log: Failed to lock
+ g' g7 y: C( S8 Fglobal mutex: Permission denied [hostname ""] [uri "/i.php"] [unique_id "AcAcAcAcAcAcAcA4DcA7AcAc"]8 j& v5 Y, C$ m4 H% x9 O" N
解决方法:/ p& V2 l% L* @. g- a. P
编辑modsecurity.conf,注释掉默认的SecAuditLogType和SecAuditLog,添加以下内容:! S4 A1 @! ~# ], ^& Z. m
( b9 P* f6 j8 i6 j* B! J, NSecAuditLogDirMode 0777
! Y9 N# C+ t0 E$ Y& ASecAuditLogFileMode 0550
1 ]7 ?* R3 F6 J! NSecAuditLogStorageDir /var/log/modsecurity
! e1 h7 u N G8 MSecAuditLogType Concurrent
9 T. _- K0 u4 ]参考文章:* O2 K( e- ~7 ]
https://github.com/SpiderLabs/ModSecurity/wiki/Reference-Manual#Installation_for_NGINX
3 j+ i# J) ^2 b$ n0 |, phttp://drops.wooyun.org/tips/2614 |
|