找回密码
 立即注册

QQ登录

只需一步,快速开始

查看: 12723|回复: 0

nginx配合modsecurity实现WAF功能

[复制链接]
发表于 2017-10-19 16:53:31 | 显示全部楼层 |阅读模式
modsecurity原本是Apache上的一款开源waf,可以有效的增强web安全性,目前已经支持nginx和IIS,配合nginx的灵活和高效,可以打造成生产级的WAF,是保护和审核web安全的利器。9 ^9 L+ F. i& f% O9 F7 b

% V; K. q) j! k7 g  F% o一.准备工作
2 q( K' `7 \; {; w7 v, V) J7 r4 x, G& b. l4 P
系统:centos 6.5 64位、 tengine 2.1.0, modsecurity 2.8.01 N% D' I; w' Q1 g, G$ j

$ D7 y6 n+ w" p/ R% Etengine : http://tengine.taobao.org/download/tengine-2.1.0.tar.gz
3 k3 ^0 u, h# E  \  s, d1 V3 o( F: H6 G' u0 H. f( Y
modsecurity for Nginx: https://www.modsecurity.org/tarball/2.8.0/modsecurity-2.8.0.tar.gz
, h  ~2 u( S5 R# W
+ t! s  c" I: S5 l; YOWASP规则集: https://github.com/SpiderLabs/owasp-modsecurity-crs
& v! `8 C+ M) q; a% s3 u8 s7 p! h4 z! n  {# c% P! n7 O$ Y% S7 `) N) r' ^
依赖关系:+ S; n/ C3 U4 N- O8 e7 H
tengine(nginx)依赖: pcre 、zlib、 openssl, 这三个包centos 6.5 系统源里都有:
/ I6 a: x3 V" ]+ _1 L8 L; B, j& j5 ]  G+ D& ]% G3 m
yum install zlib zlib-devel openssl openssl-devel  pcre pcre-devel
- B4 W4 W( U% h' ]3 {modsecurty依赖的包:pcre httpd-devel libxml2 apr
: a) U* y3 C1 X/ \1 s$ T- Y: g- z* S4 j% M0 G6 E
yum install httpd-devel apr apr-util-devel apr-devel  pcre pcre-devel  libxml2 libxml2-devel6 F# R; A$ S; A. O0 ~* b) _
二.启用standalone模块并编译! }4 W8 f$ {: I2 E/ a

% T: e% C* ?. o! [4 W, `2 I: |! a下载modsecurity for nginx 解压,进入解压后目录执行:
, \6 s' E9 R2 P5 w3 x- P. }# X- e. Y4 ]9 a
./autogen.sh
+ T. D' F, n5 w% V3 E3 v9 T! J./configure --enable-standalone-module --disable-mlogc
. V& _: p' E1 Imake 0 Y3 ^* d# _2 W0 O+ ?! \9 {: o( }
三.nginx添加modsecurity模块
, F+ x3 ]2 d& M* x% [7 Y2 V' v, H" U- {4 s9 i2 S" _
在编译standalone后,nginx编译时可以通过"--add-module"添加modsecurity模块:8 R7 E  w* F4 |' J7 s( I

3 ^2 f7 q6 w" v7 Q6 W0 F9 n' W./configure --add-module=/root/modsecurity-2.8.0/nginx/modsecurity/  --prefix=/opt/tengine4 ^( C0 X4 c' V, v+ Z  W: S6 f
make && make install6 ~; A# W9 z' v% [
四.添加规则# g2 V. O$ s( @6 ~( P' x

: ^3 Y1 R5 P6 U: O% i: B: T! ~7 mmodsecurity倾向于过滤和阻止web危险,之所以强大就在于规则,OWASP提供的规则是于社区志愿者维护的,被称为核心规则CRS(corerules),规则可靠强大,当然也可以自定义规则来满足各种需求。
* i" A; M% T5 C7 B5 L, W+ O; ?6 t8 `+ d
1.下载OWASP规则:
1 x9 Y3 C% j1 V# H0 C
# j! f7 }' t; w+ w% f: I6 \2 V* cgit clone https://github.com/SpiderLabs/owasp-modsecurity-crs, _7 d, e( v3 Y) t( m+ ^8 T
3 H+ X0 F5 w( C& \) U  r
mv owasp-modsecurity-crs /opt/tengine/conf/
% b9 |, P" D" b: r/ b& c
; F/ r/ s6 [; j$ lcd /opt/tengine/conf/owasp-modsecurity-crs && mv modsecurity_crs_10_setup.conf.example modsecurity_crs_10_setup.conf& J* {$ ]* @8 e
2.启用OWASP规则:- Q' s5 n6 q( q9 @

0 X5 `3 X/ v2 n' ^复制modsecurity源码目录下的modsecurity.conf-recommended和unicode.mapping到nginx的conf目录下,并将modsecurity.conf-recommended重新命名为modsecurity.conf。
( \1 `7 u$ D6 O+ X1 H7 \3 \% p1 j: D4 Y8 r$ k- q- x4 O2 D
编辑modsecurity.conf 文件,将SecRuleEngine设置为 on4 y  O4 v% D9 u' U( @9 j  z
  W. a/ _: h6 ^$ G; m
owasp-modsecurity-crs下有很多存放规则的文件夹,例如base_rules、experimental_rules、optional_rules、slr_rules,里面的规则按需要启用,需要启用的规则使用Include进来即可。
' C" ^. \# ?* K2 v! ~0 \9 ^; Q- O4 |# h( h, f2 V! I* X0 O
Include owasp-modsecurity-crs/modsecurity_crs_10_setup.conf
: {+ `6 Z9 `) i& {9 p( N4 ?Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_sql_injection_attacks.conf" E4 k* z4 c, M7 w3 ]
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_xss_attacks.conf
6 y  }1 k1 a3 l. ]Include owasp-modsecurity-crs/base_rules/modsecurity_crs_40_generic_attacks.conf& U( O( a. u3 E! r7 Q
Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_dos_protection.conf
0 I5 ^- d8 n" |: WInclude owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_brute_force.conf3 I% _5 `4 ?1 V& _$ O7 V' g$ h
Include owasp-modsecurity-crs/optional_rules/modsecurity_crs_16_session_hijacking.conf
) A+ p! Q! @8 n! x8 [4 ?( L  R. N; v五.配置nginx% o( ~4 j/ C  R( B

! W4 S0 H' R4 |6 `. I: n: G在需要启用modsecurity的主机的location下面加入下面两行即可:0 o0 f# u, M7 ^2 e/ G+ d" Y5 ~

6 O1 N9 D/ }) Z4 h2 S# kModSecurityEnabled on;  
0 Q" ^+ n. D6 n9 m! Q2 j! o: B6 UModSecurityConfig modsecurity.conf;/ {) @* r, \! v* z" [
下面是两个示例配置,php虚拟主机:
1 D; u2 n* H6 P+ v5 y! U
; J. B9 R/ ~0 H1 Z3 b7 Xserver {) r6 `$ E7 `3 s0 e# k
      listen      80;% P5 p9 A* U" ], M% N/ w. b$ o
      server_name 52os.net www.52os.net;
& c/ [) x$ M* T# t6 p     
- ?6 F: W% e. y      location ~ \.php$ {
" v, Q) e& Z; @) r- r0 G      ModSecurityEnabled on;  % z0 Z6 B; g1 \" Z. G$ @
      ModSecurityConfig modsecurity.conf;8 p! m4 U  S( H# x8 k

! F$ t2 Y1 c- @7 s2 Q; ?9 X      root /web/wordpress;6 Q5 H1 l' n# y  x: I
      index index.php index.html index.htm;
$ g3 _# J  {; C: A. ~* C  $ ]& M* [0 Z- Y' d+ J
      fastcgi_pass   127.0.0.1:9000;
9 T' ?2 H( F1 {8 g& y% g: l      fastcgi_index  index.php;
9 Y3 ~, \9 m& {* |0 S      fastcgi_param  SCRIPT_FILENAME  $Document_root$fastcgi_script_name;
& f* Z: n2 x1 |/ I4 D      include        fastcgi_params;
. ~9 j" W4 t! P      }
/ b2 ?) m( ^( Z' w& ~" z7 }7 r  }$ O. E' y. a8 g( f7 S0 r
upstream负载均衡:
. }) ]- V, t4 P" o- O$ z4 a  y2 k) [% A7 z$ S( I
upstream 52os.net {. L$ C1 p* N) v8 }1 U8 K
    server 192.168.1.100:8080;
3 V# d6 h: Q; _  B" d3 Z    server 192.168.1.101:8080 backup;( y& h! c$ Z! \! C' |* P
}
8 G  [. ?7 V& i5 A' l9 E
- ^* o" w: x9 y" J. Lserver {
$ N) G3 ~, \! J: Hlisten 80;, p  }1 _; ^! o; O/ Y) j
server_name 52os.net www.52os.net;0 N! b4 q1 D; O+ C

) Y+ q3 }' S% C$ T' Ylocation / {$ \( X. l/ u, u: c
    ModSecurityEnabled on;  , W( R: I! `/ \: z6 }5 U
    ModSecurityConfig modsecurity.conf;  
" I+ \9 R4 @5 ^0 a( o  g) Q
/ {( L/ t* l5 i+ M        proxy_pass http://online;
" j$ ?$ @2 K  e1 t" z9 }" J  `        proxy_redirect         off;: Y& X4 v: t8 z' C1 U& z7 {
        proxy_set_header Host $host;
$ t8 f/ Z3 t  @# u' y( V+ Z. W7 E        proxy_set_header X-Real-IP $remote_addr;% E# f: v7 A9 f2 d
        proxy_set_header  X-Forwarded-For $proxy_add_x_forwarded_for;7 _, c) Y& s! w$ Y' h' j
    }
" P9 w# R3 K8 T. O1 v0 H' a}8 w. V9 U; h' S5 q+ ^! l+ {
六.测试" S9 z* F. K4 p) t9 O" e( ]* F' A3 A
% E9 E0 `9 e: ?& l, d* e) S
我们启用了xss和sql注入的过滤,不正常的请求会直接返回403。以php环境为例,新建一个phpinfo.php内容为:' A5 d1 q$ c1 @1 G+ B! `
$ ?9 k* v" w4 K
<?php
% N; O2 r# w: v5 J, P4 k% ^% T7 D    phpinfo();   
- h) @' v4 }2 N) |) w9 }+ p0 y?>: ~# |% [. i& t1 }* ?8 s+ L0 w2 l
在浏览器中访问:
. q% P: Y2 c' Y) A: w* b6 d  k! U( e+ V; m# t+ k$ I5 \6 @7 J2 f
http://www.52os.net/phpinfo.php?id=1 正常显示。/ f( _4 i; y# G% G: P
http://www.52os.net/phpinfo.php?id=1 and 1=1  返回403。
: a) p. Q* Q: V0 H. S1 e) \http://www.52os.net/phpinfo.php?search=<scritp>alert('xss');</script>  返回403。9 C( d6 `! {4 V1 w0 r" C# K* |
说明sql注入和xss已经被过滤了+ p( h: g+ u1 R* I

2 p% z/ L* `- r七、安装过程中排错# s* _! {' g" X5 I" E2 \: _( @- [6 R9 ^
/ X: \% T" I2 ], L
1.缺少APXS会报错, {, j1 C* m0 Z
: Z6 U) r& @3 X
configure: looking for Apache module support via DSO through APXS
* i1 p* w$ O/ ]! _/ j( u( hconfigure: error: couldn't find APXS7 R# v4 ^/ [; Q
apxs是一个为Apache HTTP服务器编译和安装扩展模块的工具,用于编译一个或多个源程序或目标代码文件为动态共享对象。( ^! d9 g' j5 t2 B# r8 U
解决方法:2 g4 S$ M% T  ~3 V1 S7 i% O" C0 T

7 k* v& x& a/ m1 Q7 R" h6 yyum install httpd-devel
* F' O; q/ E8 b8 W5 k" b2.没有pcre4 [1 o6 k( A1 y7 k

7 l6 E+ ]) {) m% I7 L  Mconfigure: *** pcre library not found.
/ J8 B, R: I* D8 f# K- E% Y$ y3 Qconfigure: error: pcre library is required" n' |5 {) p! ?7 B' u- o
解决方法:) v5 y2 M9 Z$ D+ D( j
: M+ H. Z' t0 }- K! z
yum install pcre pcre-devel
5 _. Y  e6 X" v! H  V3.没有libxml2
, c: s4 a' g8 t. }* V% _% b; q1 d4 z* d: z8 h: t) J

! P' n% _* n- bconfigure: *** xml library not found.
! z. u7 d2 C; x1 P3 }: kconfigure: error: libxml2 is required* }* s. }" V5 \: G3 l' W
解决方法:; E1 D/ T% R, H1 B8 H0 L

. ~, s) V6 c1 _yum install  libxml2 libxml2-devel3 d( K5 _; n5 W& e0 h' K) L
4.执行 /opt/tengine/sbin/nginx -m 时有警告; j6 X& x7 z. F! L' K

* E! U# e9 z5 t; C0 ^% F7 gTengine version: Tengine/2.1.0 (nginx/1.6.2)  ]) X5 u; a. `$ [+ |) N( H% r
nginx: [warn] ModSecurity: Loaded APR do not match with compiled!: h, `/ V+ n9 P- t& e4 X% E
原因:modsecurity编译时和加载时的apr版本不一致造成的,并且会有以下error.log
- U& q4 Q. t" Y" {! }+ w( s% d4 B3 Z% ]9 g
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity for nginx (STABLE)/2.8.0 () configured.5 K1 F0 }1 X0 h2 _/ n
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: APR compiled version="1.5.0"; loaded     version="1.3.9"
& E/ h5 v" o  J1 G- z  v! P* w7 W4 ^+ o2015/01/26 02:04:18 [warn] 29036#0: ModSecurity: Loaded APR do not match with compiled!0 S5 }6 t4 \# V: \! S2 j- s
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: PCRE compiled version="7.8 "; loaded version="7.8 2008-09-05"
, v& |7 D4 U. T/ M2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: LIBXML compiled version="2.7.6"
+ a$ k  o6 X1 R6 ~2 R9 a/ z* x2015/01/26 02:04:18 [notice] 29036#0: Status engine is currently disabled, enable it by set SecStatusEngine to On.
5 D9 S3 E- x4 t7 w, u解决方法,移除低版本的APR (1.3.9)
$ Y' g8 Z7 x6 V/ ?8 k+ R7 n$ ?, [: b) A  p7 ^$ Y5 z
yum remove apr
  ]5 p) [5 ?2 u6 Y6 e4 f5.Error.log中有: Audit log: Failed to lock global mutex
; M6 V/ `! A1 E# C# h5 K
- ]) o! @! m6 Y$ c) r% m; f. y2015/01/26 04:15:42 [error] 61610#0: [client 10.11.15.161] ModSecurity: Audit log: Failed to lock     
3 e1 p4 u( n2 [) jglobal mutex: Permission denied [hostname ""] [uri "/i.php"] [unique_id "AcAcAcAcAcAcAcA4DcA7AcAc"]8 p& S# D) i$ p! A: M: t* T6 ~7 f
解决方法:" J; N) `2 Y+ S- s. f$ M
编辑modsecurity.conf,注释掉默认的SecAuditLogType和SecAuditLog,添加以下内容:
& y  P4 {3 o* K1 g
2 @" l8 Y" c. e" ]' Y+ uSecAuditLogDirMode 0777
6 |3 L6 U, ]) rSecAuditLogFileMode 05505 F) `2 Z8 c* K$ W# ?
SecAuditLogStorageDir /var/log/modsecurity: m' u; f; I. \8 a
SecAuditLogType Concurrent
/ M, @5 ]* N1 c# n5 s* }参考文章:2 ?3 B& I4 f: f) \
https://github.com/SpiderLabs/ModSecurity/wiki/Reference-Manual#Installation_for_NGINX) J7 e2 q: ]9 R( H; i' q
http://drops.wooyun.org/tips/2614
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

QQ|Archiver|手机版|小黑屋|第一站论坛 ( 蜀ICP备06004864号-6 )

GMT+8, 2026-10-4 07:06 , Processed in 0.065376 second(s), 19 queries .

Powered by Discuz! X3.5

© 2001-2026 Discuz! Team.

快速回复 返回顶部 返回列表