|
|
modsecurity原本是Apache上的一款开源waf,可以有效的增强web安全性,目前已经支持nginx和IIS,配合nginx的灵活和高效,可以打造成生产级的WAF,是保护和审核web安全的利器。5 k i8 b$ ]; F [7 A0 v
7 N7 x9 T8 U, X4 N2 M* s! ]& h
一.准备工作
' ]9 Z/ p6 D& N" ^$ Z) j& E* t; G0 H
系统:centos 6.5 64位、 tengine 2.1.0, modsecurity 2.8.02 h1 _3 m; f! k8 Y
3 {% z: t2 ^: ]7 \7 Ctengine : http://tengine.taobao.org/download/tengine-2.1.0.tar.gz+ W% H, K. N4 r5 l, T1 T
- ?8 k& @% L0 _& |5 amodsecurity for Nginx: https://www.modsecurity.org/tarball/2.8.0/modsecurity-2.8.0.tar.gz
2 k1 A5 V0 `7 x& P6 D
2 M* q9 C- t7 c, Y) ?' b' T* ^8 mOWASP规则集: https://github.com/SpiderLabs/owasp-modsecurity-crs
5 v, ^9 M, P9 |" l
4 _( s% P, [& u4 w6 B4 _9 T" @. c依赖关系:
2 x3 N1 ?2 f0 `3 wtengine(nginx)依赖: pcre 、zlib、 openssl, 这三个包centos 6.5 系统源里都有:3 W; X* G/ s3 |) _) p
5 g4 w' b) F. j2 V& B$ a2 p7 Z1 v
yum install zlib zlib-devel openssl openssl-devel pcre pcre-devel/ c6 ^" d8 m, n5 d( ~4 ~5 L: M' ]" m
modsecurty依赖的包:pcre httpd-devel libxml2 apr6 S2 [3 e* O+ }: I5 y. u5 u3 n" {
3 H' f8 ? x) ]) B, @, F) tyum install httpd-devel apr apr-util-devel apr-devel pcre pcre-devel libxml2 libxml2-devel) N V9 ?+ Q# G9 W1 q+ t
二.启用standalone模块并编译
1 [7 w- h, d8 ~; |
& \' K$ s0 _. y下载modsecurity for nginx 解压,进入解压后目录执行:
' U6 M( n; m1 K, w+ s- I( z( J# P" `
& u! Q0 o# L- S/ ~. Q./autogen.sh$ N$ I; B5 v8 Q+ ^
./configure --enable-standalone-module --disable-mlogc
u2 \( [$ G8 E, rmake * X& Y3 P( ~! e0 R' w9 R
三.nginx添加modsecurity模块
1 j4 b) ~$ C8 B
5 b! X( p$ f6 {0 ~% Y! C在编译standalone后,nginx编译时可以通过"--add-module"添加modsecurity模块:
7 b$ [9 L+ g$ j- O# o$ h" g6 u* T6 f1 b ~
./configure --add-module=/root/modsecurity-2.8.0/nginx/modsecurity/ --prefix=/opt/tengine/ z! D, g& ]% g% a+ W* c2 r
make && make install
$ o$ L% U( Q; _, P* h四.添加规则
9 L1 ^- H4 z T# j& Y, x# W7 G* v6 j) G. p
modsecurity倾向于过滤和阻止web危险,之所以强大就在于规则,OWASP提供的规则是于社区志愿者维护的,被称为核心规则CRS(corerules),规则可靠强大,当然也可以自定义规则来满足各种需求。
; c, ]4 k9 |. p- ?" x& s) ?% W8 G, Z
1.下载OWASP规则:
! @" Y* }0 d: t& _' a9 {; R: ]# t9 s3 x; l! A4 ~5 } V5 m
git clone https://github.com/SpiderLabs/owasp-modsecurity-crs; b! s' g' @ L( j
; P' p6 K$ e: }; d; d0 {
mv owasp-modsecurity-crs /opt/tengine/conf/ t9 `9 H+ k/ g; n% j% i" V
9 Y1 }% V, n" acd /opt/tengine/conf/owasp-modsecurity-crs && mv modsecurity_crs_10_setup.conf.example modsecurity_crs_10_setup.conf
9 j1 g" v$ R) v2.启用OWASP规则:+ c7 K# r4 P, d; S
( s9 ~8 G0 C+ n$ I. M# I1 E% @4 V复制modsecurity源码目录下的modsecurity.conf-recommended和unicode.mapping到nginx的conf目录下,并将modsecurity.conf-recommended重新命名为modsecurity.conf。* {' ]& d1 |0 S: Q. ^5 L" f1 }
+ @- V; A# r* f- D: h0 c: P l
编辑modsecurity.conf 文件,将SecRuleEngine设置为 on
0 x! H; G- ? ~6 y8 s+ g) k! s4 W+ p% Z* U( v* T6 Y$ }! j- K
owasp-modsecurity-crs下有很多存放规则的文件夹,例如base_rules、experimental_rules、optional_rules、slr_rules,里面的规则按需要启用,需要启用的规则使用Include进来即可。2 {& G$ x' O3 O* u; A. N
; y- _5 q) _3 q, XInclude owasp-modsecurity-crs/modsecurity_crs_10_setup.conf
( n5 \ I1 B8 z' |* n6 aInclude owasp-modsecurity-crs/base_rules/modsecurity_crs_41_sql_injection_attacks.conf7 ?1 {/ A- L8 D. v7 j
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_xss_attacks.conf
8 @2 ~5 @% ^" \) x' CInclude owasp-modsecurity-crs/base_rules/modsecurity_crs_40_generic_attacks.conf; a$ S1 J/ o$ k- M- z
Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_dos_protection.conf9 d2 g" T; Q! D9 N6 W+ N& w$ l' k
Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_brute_force.conf/ |+ ]/ S1 a) O
Include owasp-modsecurity-crs/optional_rules/modsecurity_crs_16_session_hijacking.conf# C' A. w; k( M9 [" x$ L7 J) D
五.配置nginx3 I7 r4 Z# R2 i1 A
# m0 L I0 @. s
在需要启用modsecurity的主机的location下面加入下面两行即可:; n$ O# N! X5 q! o) Q7 C+ q+ c
) d" X3 p8 E5 K# {( {5 g2 a
ModSecurityEnabled on;
. i, ?" }+ _- J1 p- o" S4 i2 ?$ `ModSecurityConfig modsecurity.conf;' Q0 y/ Z. s% R0 j% C
下面是两个示例配置,php虚拟主机:
4 r- Y; i& v2 c7 h8 D5 u [
, {; R+ G2 g5 \8 \2 l, [server {
& n3 u; Y, b- Q- l listen 80;6 |; r/ A. M, p+ V4 ~
server_name 52os.net www.52os.net;0 ^' m |2 _) }' F8 u, J5 o) _
8 x( ]2 @$ v* i) m- c. u4 K: A4 l
location ~ \.php$ {
- i% Y) r3 Y( \& w3 o1 T6 t; G ModSecurityEnabled on; 3 P8 @! F6 `. u3 y
ModSecurityConfig modsecurity.conf;
$ `% S) u/ h( d, F) {) E) p. y E* b; H6 V* v5 `
root /web/wordpress;+ h2 G# y; V5 i4 e8 Q
index index.php index.html index.htm;) }) p- K9 T- o
! a% u5 T6 w$ v0 w fastcgi_pass 127.0.0.1:9000;8 n9 n" l7 E2 F9 T, f
fastcgi_index index.php;4 b6 v& g' Q s0 w( X+ J# B0 z$ H
fastcgi_param SCRIPT_FILENAME $Document_root$fastcgi_script_name;1 s# E3 P# [/ e [/ @5 G f
include fastcgi_params;
7 M7 ]" R: f6 v! t }
$ i+ G3 ]4 f1 `5 p7 t! N+ x }
$ ^6 e4 w& u7 `, xupstream负载均衡:
; O4 M L0 f% _0 t7 @& \4 e9 O4 z# D) ]2 c2 P! a
upstream 52os.net {2 y D3 X1 G: z: x6 ? \, v
server 192.168.1.100:8080;# {0 {0 f; M3 D4 e5 T( [( {
server 192.168.1.101:8080 backup;. ^ I! H/ w) a L9 c! ?
}
- E! i+ w, l4 T9 B5 ?! o5 N2 B& T/ j: S7 U7 ?# R# J% L/ Y' \
server {
2 Q1 J% `: N3 [listen 80;1 R/ _2 E9 o& }$ ~8 q9 k# e7 Q$ y
server_name 52os.net www.52os.net;
1 e! X, M8 g1 f% g: `; u
% e: F/ v3 G1 plocation / {
% M9 Z) H# d2 O6 t( ^5 Q3 L: Q$ S ModSecurityEnabled on;
$ b) f& r/ T1 _! {. B' E8 |5 P8 r/ s ModSecurityConfig modsecurity.conf; 6 R! o9 Z1 L0 M" e [' |' U
/ v+ Q x& s5 L
proxy_pass http://online;" e: n) U! f0 y5 f/ Y" ^
proxy_redirect off;6 l9 [. k) H6 u9 o3 J& |+ [
proxy_set_header Host $host;
6 L& E: a9 a& ~- i# \( w( D proxy_set_header X-Real-IP $remote_addr;* n$ D. j8 w/ [ Y) J. M5 }
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
7 A: g) P. v. W+ x2 W5 ` }
. G# u$ W; P F& @- k$ M9 e}
0 |# a# j1 {8 a$ A0 u六.测试
- c+ l9 i+ M5 b( E7 i$ ?- ^
( z9 R [9 H; Y我们启用了xss和sql注入的过滤,不正常的请求会直接返回403。以php环境为例,新建一个phpinfo.php内容为:
, J! c s4 F# |# q9 [% c* R& P3 F/ T2 p4 f- N" e& ]( _
<?php
. v; k( j7 b( E: O phpinfo(); : u) | L2 B8 z4 p( n- z
?>
k } [- ?* o2 H3 S8 m4 b$ @/ q在浏览器中访问:
" M, K1 A4 X) W+ Z* B {
7 L ], J* H& W& shttp://www.52os.net/phpinfo.php?id=1 正常显示。
# e0 V% y( o' b' ~9 Q' q6 Rhttp://www.52os.net/phpinfo.php?id=1 and 1=1 返回403。$ @7 e z6 i. |# l$ o6 G
http://www.52os.net/phpinfo.php?search=<scritp>alert('xss');</script> 返回403。& B0 k2 \2 V% b( k- M7 g
说明sql注入和xss已经被过滤了. ?& H( z( E% r' A* E ^0 C
2 b, j8 `/ j' L1 }
七、安装过程中排错
6 f7 M, M) H# j' q% B0 E3 r- D! e# c7 A7 f; A- Y
1.缺少APXS会报错0 b- Q( W# @4 ?& u
/ f E, x F' ?: X
configure: looking for Apache module support via DSO through APXS
) D& T% Y, y( e! i3 Yconfigure: error: couldn't find APXS' a2 k, `/ H. L" W$ Q! {
apxs是一个为Apache HTTP服务器编译和安装扩展模块的工具,用于编译一个或多个源程序或目标代码文件为动态共享对象。: @' W- l$ F, m3 \1 \3 C
解决方法:7 ]$ i; e% Q) I; E/ S/ @: X
6 L! \4 r+ o( u( o l
yum install httpd-devel) H' k6 X! A; @1 X. Z, R& S
2.没有pcre
( ?; Y) G1 b+ p5 V r @
) i' I. C2 }) h6 hconfigure: *** pcre library not found.& B" W7 S0 V% i% ?# _( D/ N
configure: error: pcre library is required) ~$ A% k8 ` X' F8 @
解决方法:
: b: W6 k3 X5 }" r
% M$ ]0 R( @6 ^( t6 r! N Pyum install pcre pcre-devel$ w6 i0 i: w2 v" y* v
3.没有libxml2
+ w% D. W" b! a+ Y
7 W" u1 c* x( E; v, B% t- h5 f8 O. {" P5 Z) s2 J
configure: *** xml library not found.! Q2 a( {7 E+ o2 J8 ~* s
configure: error: libxml2 is required% ^% j4 S c& k. b/ a6 i8 ]
解决方法:8 o% b( S# r8 J+ D1 [. e# J* l
( l7 B/ a, u' ^! J8 k eyum install libxml2 libxml2-devel
: H' ]3 U; z: B' V. A }; Y4.执行 /opt/tengine/sbin/nginx -m 时有警告
& n9 m9 H9 ~2 @7 S- R9 L. K3 ]! @. P7 p. K( z# @9 {' h6 U
Tengine version: Tengine/2.1.0 (nginx/1.6.2)
9 E/ m! u8 o2 Z+ m N1 Pnginx: [warn] ModSecurity: Loaded APR do not match with compiled!
5 H& R& x! Y' f2 b原因:modsecurity编译时和加载时的apr版本不一致造成的,并且会有以下error.log
' S) @) ?$ S( X4 _, x, W) V! H4 U
& w4 `4 {2 a$ ^8 m" U4 Y' ~2015/01/26 02:04:18 [notice] 29036#0: ModSecurity for nginx (STABLE)/2.8.0 () configured.9 Z6 H2 x: r8 H3 [
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: APR compiled version="1.5.0"; loaded version="1.3.9", `3 w0 _7 b1 B0 Y6 `. ] b0 P
2015/01/26 02:04:18 [warn] 29036#0: ModSecurity: Loaded APR do not match with compiled!
1 R" |% s4 A k; m2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: PCRE compiled version="7.8 "; loaded version="7.8 2008-09-05"
3 U' o& A! C' h) v- X! T0 k2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: LIBXML compiled version="2.7.6"
* F! b' W2 t" m$ n2 P) T2015/01/26 02:04:18 [notice] 29036#0: Status engine is currently disabled, enable it by set SecStatusEngine to On.
' X& J( p5 v0 b3 w解决方法,移除低版本的APR (1.3.9), s/ W0 D, H+ l# X4 ]: t
o8 ]5 J4 e/ b8 m, [/ {- Iyum remove apr
. P3 P, k/ a( ^1 J, Z% A4 c/ N/ I5.Error.log中有: Audit log: Failed to lock global mutex; S- O8 y3 e7 z7 O0 _: }
9 j' \, }, H5 H) L6 B0 J1 M; G
2015/01/26 04:15:42 [error] 61610#0: [client 10.11.15.161] ModSecurity: Audit log: Failed to lock : C. M: a0 h+ _
global mutex: Permission denied [hostname ""] [uri "/i.php"] [unique_id "AcAcAcAcAcAcAcA4DcA7AcAc"]
) y( O; R( n8 K) K4 U6 G0 b) r8 C解决方法:( e7 W3 T& W5 L& J1 f$ }
编辑modsecurity.conf,注释掉默认的SecAuditLogType和SecAuditLog,添加以下内容:3 S# N% Y/ u; g, a4 L* W) n
' m2 I3 I! W0 uSecAuditLogDirMode 0777- T' R0 v6 w/ y1 f6 a
SecAuditLogFileMode 05508 z: s' F$ v% q; W. |! I; J0 _5 i" P! J
SecAuditLogStorageDir /var/log/modsecurity
. B4 b/ p, |& |1 ]8 M/ u# ]) e' Z) OSecAuditLogType Concurrent7 u. X8 l+ T: M. R1 g* N0 T
参考文章:, h5 M- U- S! w
https://github.com/SpiderLabs/ModSecurity/wiki/Reference-Manual#Installation_for_NGINX
6 o2 [. p6 n- r: I) Whttp://drops.wooyun.org/tips/2614 |
|