找回密码
 立即注册

QQ登录

只需一步,快速开始

查看: 12725|回复: 0

nginx配合modsecurity实现WAF功能

[复制链接]
发表于 2017-10-19 16:53:31 | 显示全部楼层 |阅读模式
modsecurity原本是Apache上的一款开源waf,可以有效的增强web安全性,目前已经支持nginx和IIS,配合nginx的灵活和高效,可以打造成生产级的WAF,是保护和审核web安全的利器。
: V) N: \. {. s! |9 y& `
7 m) V1 m" O4 b" C1 H一.准备工作$ x9 h! F  {& ?/ ^4 L

+ A% h3 [$ y* D& T系统:centos 6.5 64位、 tengine 2.1.0, modsecurity 2.8.0
1 l# N  V4 f2 I6 I$ T% F2 p7 n( q  j" W0 U; p- U7 q
tengine : http://tengine.taobao.org/download/tengine-2.1.0.tar.gz
! J) d4 Y* y- S( o" L9 i: ?, `$ x# s
" U! @9 Z) F7 Z7 K  D$ [" T' \modsecurity for Nginx: https://www.modsecurity.org/tarball/2.8.0/modsecurity-2.8.0.tar.gz
( M& o6 J' M. N" o9 w  b; b3 ~( q5 R% A" L- U& W' q  W
OWASP规则集: https://github.com/SpiderLabs/owasp-modsecurity-crs
" C' r6 d* U6 L
( o( @) B# n4 |. T* s; Q7 Y依赖关系:: ?2 f& E  C" M" m& Y2 m
tengine(nginx)依赖: pcre 、zlib、 openssl, 这三个包centos 6.5 系统源里都有:0 D0 q$ I, F) g4 }! ]0 H4 y
6 D2 I" G- D; ]8 Q/ G( ^
yum install zlib zlib-devel openssl openssl-devel  pcre pcre-devel
/ z' p& W, J' l/ z' Z8 L8 bmodsecurty依赖的包:pcre httpd-devel libxml2 apr$ h4 @( X: \9 `4 [
  M9 Q, b7 Y+ N7 }& \
yum install httpd-devel apr apr-util-devel apr-devel  pcre pcre-devel  libxml2 libxml2-devel
: p" ~) ^1 I4 y4 g6 K# _  i0 D3 E二.启用standalone模块并编译
2 z0 C: y, D; K) p- W: s1 A
6 G; Z; f' p4 i6 a; F! o/ ]下载modsecurity for nginx 解压,进入解压后目录执行:! b7 \% g! ^2 U- d, m# w
4 m) }1 k1 R) e" c6 I9 c+ q1 ]
./autogen.sh
3 k2 u* H, E5 X7 J: `./configure --enable-standalone-module --disable-mlogc
2 F  i( a9 n6 k  {/ Rmake
- L4 y$ ?% O) z6 a+ e三.nginx添加modsecurity模块
1 z+ _* [; O! r5 K0 ?# G- f- j; J! o3 o4 p, h& H- x" b
在编译standalone后,nginx编译时可以通过"--add-module"添加modsecurity模块:1 p6 U  A9 q* [  a. \& D5 U  `/ f

0 [2 ~' f/ A- d7 L* h3 v! u./configure --add-module=/root/modsecurity-2.8.0/nginx/modsecurity/  --prefix=/opt/tengine- s/ S- {8 w9 c1 y
make && make install( d( Y% f5 l! O$ R3 k0 Y
四.添加规则
, l' w( B5 i. P/ q. M
1 `9 D; {' w: D* }5 Kmodsecurity倾向于过滤和阻止web危险,之所以强大就在于规则,OWASP提供的规则是于社区志愿者维护的,被称为核心规则CRS(corerules),规则可靠强大,当然也可以自定义规则来满足各种需求。' Z1 }* D6 g- Z7 D& H

$ x  O: \4 d, |$ J1.下载OWASP规则:" w, c  N/ k1 r! q: N7 D" s6 q

3 g0 u, c- n) B$ egit clone https://github.com/SpiderLabs/owasp-modsecurity-crs
, g" A1 R' K: s; u( A$ U6 N  O6 w/ w8 g* }
mv owasp-modsecurity-crs /opt/tengine/conf// }4 [9 F) t, b# g7 q- Z

; E' N0 w' W* \% gcd /opt/tengine/conf/owasp-modsecurity-crs && mv modsecurity_crs_10_setup.conf.example modsecurity_crs_10_setup.conf
) t, Z/ _% i" t! W0 l& s2.启用OWASP规则:
% S2 y5 n# q* I& @+ G& W4 n
  A+ @9 e( B* X复制modsecurity源码目录下的modsecurity.conf-recommended和unicode.mapping到nginx的conf目录下,并将modsecurity.conf-recommended重新命名为modsecurity.conf。6 y+ j4 L+ n4 k( B1 f& g6 i

5 r/ z6 @5 l8 w  z2 A) e3 w编辑modsecurity.conf 文件,将SecRuleEngine设置为 on8 ^" ~- L& S: B- v

9 z/ S; s" I/ |, @. B& Eowasp-modsecurity-crs下有很多存放规则的文件夹,例如base_rules、experimental_rules、optional_rules、slr_rules,里面的规则按需要启用,需要启用的规则使用Include进来即可。. B; c) M1 v4 ]9 Z. f1 ?9 a0 g

1 b8 _( c4 h& i, H: c3 FInclude owasp-modsecurity-crs/modsecurity_crs_10_setup.conf
. u/ g$ M. @* \) K9 G8 t# e3 OInclude owasp-modsecurity-crs/base_rules/modsecurity_crs_41_sql_injection_attacks.conf! u+ `% ?0 L. g9 N0 w6 j0 C
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_xss_attacks.conf; \: f$ E2 _" C+ M1 e
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_40_generic_attacks.conf
/ O" @6 I' G& E0 R. d) a4 ~Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_dos_protection.conf
- Y4 s* Z6 |1 E( ?" HInclude owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_brute_force.conf/ Z4 m1 h) H2 T% G, S; N
Include owasp-modsecurity-crs/optional_rules/modsecurity_crs_16_session_hijacking.conf$ d$ J/ v( z# C& Q
五.配置nginx
1 [" X3 [- @6 O- q
! o5 a( S( M$ [' I% w0 l' V在需要启用modsecurity的主机的location下面加入下面两行即可:
, w" W# D9 e3 `0 L1 k# s" l) `3 \' c0 N
ModSecurityEnabled on;  4 I1 X! y) a( Q8 B8 e2 e" a
ModSecurityConfig modsecurity.conf;
* \1 S6 }0 Y) t  R下面是两个示例配置,php虚拟主机:
5 `6 u1 k% x& q- F, h% H
; o: X/ b4 x6 l! J  V" ?) mserver {
( _; C1 x* b9 |8 h" w$ U      listen      80;
' @4 F6 R0 a$ s2 I, k# f' Z      server_name 52os.net www.52os.net;
9 |4 j" ]5 r* R/ G5 n9 P1 Y4 A     
- `, B' V5 Z) T" ^& V      location ~ \.php$ {$ @0 g" k% A& Y
      ModSecurityEnabled on;  
8 ]$ A# d0 j, `: D; l, t' W      ModSecurityConfig modsecurity.conf;: a/ B9 D7 a7 N( g9 p' V3 y

$ @" G7 {/ L9 G2 D  ]: I      root /web/wordpress;1 N' |; ?/ C! ~" A2 q. b' b; |
      index index.php index.html index.htm;
1 G, j8 V, p3 O0 O( `6 v  
; t. l2 W; Y. i. B2 |# g2 ?7 ]      fastcgi_pass   127.0.0.1:9000;) k6 i) c+ R- V  W
      fastcgi_index  index.php;5 i. v( \( b9 ^* f1 s3 ]
      fastcgi_param  SCRIPT_FILENAME  $Document_root$fastcgi_script_name;$ x  W: g/ H; ?% |% l. q, m
      include        fastcgi_params;
4 i8 J5 l( T3 V      }
1 k$ o+ I  s* B( E: i5 ]; i  }7 C4 _! Y( y1 d
upstream负载均衡:6 l% @* i6 D; y$ n0 q

9 a4 y/ @# H, Supstream 52os.net {2 h" F' ~& t2 W* e9 T
    server 192.168.1.100:8080;
2 T/ s- ~4 _4 Y8 m% a    server 192.168.1.101:8080 backup;
9 D' s5 ?; W4 P; S; U& Q" a}1 N0 P2 A! E+ M- \& H$ d  q* }
4 Q' i6 p* b, |# u8 j
server {
8 D: c! N' b- x5 R5 \listen 80;
4 |: [$ ~# S+ @# R9 qserver_name 52os.net www.52os.net;  C, x* D8 g2 `3 |
: C" y2 t3 M* W/ k% q
location / {4 j  ]7 I8 {( t; V9 T- r" N& D/ R
    ModSecurityEnabled on;  
: x# C: t% x- Q+ Q9 d4 L- i, c    ModSecurityConfig modsecurity.conf;  
. F( N* |; c2 f+ |7 X* ^& f4 a) z
        proxy_pass http://online;
' C7 j- S, \- v: h6 J        proxy_redirect         off;
% |1 t* y+ D; g  X& R        proxy_set_header Host $host;& l! |, M, Z4 y6 S& Y' ?. i
        proxy_set_header X-Real-IP $remote_addr;; L2 x, @% }# N% i6 w, H2 s- p1 u
        proxy_set_header  X-Forwarded-For $proxy_add_x_forwarded_for;
- T. T9 K* Y# n% e1 g    }
# }: \, S$ F, s}, m* v2 [/ S- m" b! k- O
六.测试
7 ~% `" o- b$ B2 t' r' v* s9 T  {8 d1 }* C8 L! r! e% @8 b
我们启用了xss和sql注入的过滤,不正常的请求会直接返回403。以php环境为例,新建一个phpinfo.php内容为:
) O' C( ^, _' o* c6 ?4 |$ X" j, q) o! o" m% _6 w3 x
<?php
9 n5 t5 n+ a; K    phpinfo();   
+ x" U/ ~9 D" G! p8 Y: \) }* D?>  L. V: W" W: Y2 L4 x. M/ k, }
在浏览器中访问:
: ~! t" [0 j2 I7 B4 `  h" \; r3 Y! o
http://www.52os.net/phpinfo.php?id=1 正常显示。
( k8 z7 e+ y% T) E- o; |2 {http://www.52os.net/phpinfo.php?id=1 and 1=1  返回403。
0 ~4 T2 v3 x) s, _  c4 j+ Ahttp://www.52os.net/phpinfo.php?search=<scritp>alert('xss');</script>  返回403。7 S- ~# F% l' b- v
说明sql注入和xss已经被过滤了7 d/ j9 ~# Q/ Z3 ]- U
; v6 \& o, \" i0 S! q
七、安装过程中排错
# \5 w- t) g2 ?* U; u. b# e, N0 ^6 L% J! @5 k  g1 x, w/ N" }
1.缺少APXS会报错5 {; i+ [! o; U, t5 o1 y2 e( s6 h
6 f3 {7 `6 R: I
configure: looking for Apache module support via DSO through APXS3 f; X% P; @: \  H% W" @8 I
configure: error: couldn't find APXS9 ]) _/ L' J. ]3 r/ M
apxs是一个为Apache HTTP服务器编译和安装扩展模块的工具,用于编译一个或多个源程序或目标代码文件为动态共享对象。
6 ?! q5 R' o# a6 W6 N解决方法:
+ ^! Z3 \- X0 H; y  G  Z/ }: x# D8 o
yum install httpd-devel
! N$ m4 f1 o# Q; s" H8 V1 b) B2.没有pcre+ D4 z6 @; o& U+ r. e

  z6 Y  d# i. G. r$ h8 [& Fconfigure: *** pcre library not found.
8 W* [2 x9 _  K; ~, E. Bconfigure: error: pcre library is required
7 q  s1 z' V% ?2 j3 \! c5 |0 ^解决方法:
8 A& Y1 h' e1 h& J) L0 c" _' \7 m7 H
yum install pcre pcre-devel7 d' c  k2 n& u# f4 C1 @
3.没有libxml2
4 H7 f0 ?" a1 f
% n" R; y+ }2 {. W
, [1 f4 p  C; R( U- p' mconfigure: *** xml library not found.
+ ^6 m& r9 _; S' _configure: error: libxml2 is required
9 Q1 b4 Z( d0 h- y  E解决方法:, p  p. Z: S5 }
4 o& d; t) m" P0 o( u
yum install  libxml2 libxml2-devel
  l) z- T! D2 l" \2 b3 e5 K4.执行 /opt/tengine/sbin/nginx -m 时有警告* B- b0 R  l- E$ Q1 B! X6 `2 Y5 W

! n" U! e9 H8 I: h; gTengine version: Tengine/2.1.0 (nginx/1.6.2)4 c, e* ~" ]& y. c
nginx: [warn] ModSecurity: Loaded APR do not match with compiled!/ o5 E, ~' k: e5 ]( d2 _- E
原因:modsecurity编译时和加载时的apr版本不一致造成的,并且会有以下error.log4 |: t7 j4 N* X# t/ L3 e

* S* w2 J. v0 A' F' b5 a2015/01/26 02:04:18 [notice] 29036#0: ModSecurity for nginx (STABLE)/2.8.0 () configured.
: j' d6 t( I5 y( {2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: APR compiled version="1.5.0"; loaded     version="1.3.9"
( p: h; v! j) U/ g% [3 O; `2015/01/26 02:04:18 [warn] 29036#0: ModSecurity: Loaded APR do not match with compiled!
: Q4 Z" H" \5 L2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: PCRE compiled version="7.8 "; loaded version="7.8 2008-09-05", p. T2 N; E) |$ L- b
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: LIBXML compiled version="2.7.6"6 y  Y6 I, j. T- X3 ~2 i
2015/01/26 02:04:18 [notice] 29036#0: Status engine is currently disabled, enable it by set SecStatusEngine to On.
2 R# W) V, U6 a3 o6 ^( _; ?8 S. I解决方法,移除低版本的APR (1.3.9)
; c- Z$ A9 I8 e/ o& P6 j0 ~* t1 g
; K! }% R- n* g" P( \2 Pyum remove apr! N+ f/ v3 o% [. I- o- o; J/ y, @
5.Error.log中有: Audit log: Failed to lock global mutex
9 \/ Q3 ]; p, u5 i/ Q$ g& @% Z; t, p9 h; P, T
2015/01/26 04:15:42 [error] 61610#0: [client 10.11.15.161] ModSecurity: Audit log: Failed to lock     
3 u( v5 A2 y: X' \: d& A1 x- Gglobal mutex: Permission denied [hostname ""] [uri "/i.php"] [unique_id "AcAcAcAcAcAcAcA4DcA7AcAc"]
+ K9 x  e& ]$ r, `! }: W2 n解决方法:
# p: [- |) ]! ]8 H编辑modsecurity.conf,注释掉默认的SecAuditLogType和SecAuditLog,添加以下内容:8 u# n& L1 s) J

" [8 H  M$ H; h) G/ O2 NSecAuditLogDirMode 0777
4 a1 a. k7 s, F( ySecAuditLogFileMode 0550  F( u, d3 \4 X: O
SecAuditLogStorageDir /var/log/modsecurity( C; P: r1 [: l- |
SecAuditLogType Concurrent
. u! I$ s2 _* P$ H" N+ o1 Q8 n参考文章:
+ c. K; C2 K: \9 r: Lhttps://github.com/SpiderLabs/ModSecurity/wiki/Reference-Manual#Installation_for_NGINX: h! U/ h& `6 e
http://drops.wooyun.org/tips/2614
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

QQ|Archiver|手机版|小黑屋|第一站论坛 ( 蜀ICP备06004864号-6 )

GMT+8, 2026-10-4 13:27 , Processed in 0.078874 second(s), 19 queries .

Powered by Discuz! X3.5

© 2001-2026 Discuz! Team.

快速回复 返回顶部 返回列表