找回密码
 立即注册

QQ登录

只需一步,快速开始

查看: 12757|回复: 0

nginx配合modsecurity实现WAF功能

[复制链接]
发表于 2017-10-19 16:53:31 | 显示全部楼层 |阅读模式
modsecurity原本是Apache上的一款开源waf,可以有效的增强web安全性,目前已经支持nginx和IIS,配合nginx的灵活和高效,可以打造成生产级的WAF,是保护和审核web安全的利器。, e1 u. c3 c/ N" c9 l) M% H& t
( q% F+ Q3 @) Q1 a
一.准备工作$ |$ N7 Z) j( X* U2 z, r  k6 `

8 w* e  O7 b- \; y! J. J: o/ i系统:centos 6.5 64位、 tengine 2.1.0, modsecurity 2.8.0' D; m$ \4 R. z) R  [8 c
" `, M& C2 F: ^
tengine : http://tengine.taobao.org/download/tengine-2.1.0.tar.gz
+ ?9 A& w! \* ^' V4 n7 r- x. p4 r1 p$ I7 N! t. v4 s' O
modsecurity for Nginx: https://www.modsecurity.org/tarball/2.8.0/modsecurity-2.8.0.tar.gz
2 q& s$ ]! z: d6 ^
0 K9 K: E) i4 @8 eOWASP规则集: https://github.com/SpiderLabs/owasp-modsecurity-crs
9 p9 t$ a1 g. t6 _& j+ m5 P) B; u* M3 d
依赖关系:
& }- ?& d" |' Q0 e% K: ?) u& b" Rtengine(nginx)依赖: pcre 、zlib、 openssl, 这三个包centos 6.5 系统源里都有:
& w2 V- P2 ~3 R; n& [" W
) `9 h  \/ h: W7 Byum install zlib zlib-devel openssl openssl-devel  pcre pcre-devel7 \" O" j/ S3 Y4 ?: l$ _& x
modsecurty依赖的包:pcre httpd-devel libxml2 apr2 ~/ x! G8 Z0 G: I' d
1 J) C+ D# A, P/ c& a  j3 j
yum install httpd-devel apr apr-util-devel apr-devel  pcre pcre-devel  libxml2 libxml2-devel
3 z+ J" {  w! J二.启用standalone模块并编译
) l  h. P/ V. J! N0 c. i
3 ^+ d2 X/ d2 \  a8 y下载modsecurity for nginx 解压,进入解压后目录执行:  y- r; I0 c+ X' h
3 `7 i1 d+ s4 O1 `5 e* {
./autogen.sh$ Z) w  h( T9 `8 ~2 l  X7 U
./configure --enable-standalone-module --disable-mlogc
. W2 o5 U1 T1 L  Umake 3 |# q9 K2 @& d' @
三.nginx添加modsecurity模块* e/ Z1 ^( d* ]* ]( V1 z

/ K: R1 a; ~% j6 |# }' O  _; ^, w在编译standalone后,nginx编译时可以通过"--add-module"添加modsecurity模块:6 h: ?3 k+ k9 Z
6 `& H# v% ^- e' H
./configure --add-module=/root/modsecurity-2.8.0/nginx/modsecurity/  --prefix=/opt/tengine
6 `9 v/ `7 [0 i( G4 mmake && make install. Y* _: @  e  \+ ~
四.添加规则
# m6 c8 A% a; ]/ d
. W/ C# x( y* V' l9 umodsecurity倾向于过滤和阻止web危险,之所以强大就在于规则,OWASP提供的规则是于社区志愿者维护的,被称为核心规则CRS(corerules),规则可靠强大,当然也可以自定义规则来满足各种需求。2 u! ^$ j* L7 c3 I" C/ H

* Z9 V6 Q4 o5 C  t1.下载OWASP规则:# j" l1 @( K* X# ^: y( {/ Q

, U+ i& l# n6 y  Dgit clone https://github.com/SpiderLabs/owasp-modsecurity-crs
5 J3 k: S& {' U
& K) z- y+ p  z: Q& hmv owasp-modsecurity-crs /opt/tengine/conf/
; B- x0 V1 H% E+ y# _
, d- N* C6 w# ~* b1 ncd /opt/tengine/conf/owasp-modsecurity-crs && mv modsecurity_crs_10_setup.conf.example modsecurity_crs_10_setup.conf; V; T! O( a; ~' E& N
2.启用OWASP规则:
9 n) W* ?! B1 u2 H) T- Y: Q# F$ i& E
复制modsecurity源码目录下的modsecurity.conf-recommended和unicode.mapping到nginx的conf目录下,并将modsecurity.conf-recommended重新命名为modsecurity.conf。
* f0 i) f) E2 p8 b0 A  |: b' O
+ _' a+ Q. [7 ~5 i) X7 v  j编辑modsecurity.conf 文件,将SecRuleEngine设置为 on
. \/ O  n- B( t. v
- \2 J* t; i( i1 A  Z: U. yowasp-modsecurity-crs下有很多存放规则的文件夹,例如base_rules、experimental_rules、optional_rules、slr_rules,里面的规则按需要启用,需要启用的规则使用Include进来即可。
  L" |% s* w5 W( i: v* u
5 H+ r6 M- }! Z4 O4 _Include owasp-modsecurity-crs/modsecurity_crs_10_setup.conf8 d7 }( ?/ ]# \0 e5 I8 U$ [
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_sql_injection_attacks.conf" K# z7 p8 p* a
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_xss_attacks.conf6 t7 D3 a, F1 n& i0 R9 B& E4 u/ F2 Q
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_40_generic_attacks.conf
( |# y' x- \7 T' x7 RInclude owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_dos_protection.conf- l( o5 l! S7 E7 h7 N. p0 k
Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_brute_force.conf
* B! `( H- F3 J* s7 p: R/ P8 a- Q/ tInclude owasp-modsecurity-crs/optional_rules/modsecurity_crs_16_session_hijacking.conf+ Y& I& P6 y5 x7 g- i( y+ ^5 D
五.配置nginx
8 N% y& v8 E; w. g$ _& W
+ b4 U( a5 F, O2 Q7 `  `# m, w& _在需要启用modsecurity的主机的location下面加入下面两行即可:
. B7 s" k6 s- L3 u7 R1 k
9 p  U* V, s4 [( e7 Y" @ModSecurityEnabled on;  
5 y! J  k9 O% {! w9 WModSecurityConfig modsecurity.conf;' t- q9 L8 C( x
下面是两个示例配置,php虚拟主机:
; O2 ]: O$ M7 h+ F0 f, }# ~: U3 q) @& v2 p
server {
6 y% J( r. v% d# I' I% Q      listen      80;
$ ?8 H5 q' M( m9 R' U      server_name 52os.net www.52os.net;
2 i7 @2 F8 x2 F- z3 d4 ?     & L  {% S+ |: p5 C7 |6 t* `
      location ~ \.php$ {
# v1 h+ ]1 F6 w9 R2 p. d' p      ModSecurityEnabled on;  , C1 }6 R6 X. Y' w' e/ \8 Q3 _" h9 F
      ModSecurityConfig modsecurity.conf;; _, R+ [! _' U# ^3 Y
$ z' E" r. u% x8 B) |3 n
      root /web/wordpress;$ t/ b; P' _& K! u1 S
      index index.php index.html index.htm;* n+ S: i* w2 M+ {1 G; S+ a. `
  
  U. h6 k, e6 k/ u1 q2 s2 u      fastcgi_pass   127.0.0.1:9000;
8 Z. r3 S( y; n% |4 D( a6 V      fastcgi_index  index.php;
* c% y+ z) V7 @2 H      fastcgi_param  SCRIPT_FILENAME  $Document_root$fastcgi_script_name;
) x# {$ `; P5 R; a+ d      include        fastcgi_params;& T$ X  O, f# |
      }; h. {; i# G5 J* |) J8 R. m
  }, O$ Q5 o# P# y, j' Z2 h
upstream负载均衡:
3 E8 c. k( [( L7 m
. ~$ [, m: z6 i. a! Hupstream 52os.net {
7 |, }# h' m( Q( o8 @    server 192.168.1.100:8080;% q, E. _# i$ D' s, j% N
    server 192.168.1.101:8080 backup;1 c' ?, i- B. u6 t6 y* `4 X) z
}
' x1 Q: {* O& [) Y6 J
0 K7 J$ y. Q& r1 Q" E) Z0 H& rserver {
& F% _' F5 |0 R7 ?listen 80;# V. K: I4 R; q' ^8 K4 q
server_name 52os.net www.52os.net;' \8 g7 k+ a' L% N3 Y6 E
# O8 g9 M/ g. D0 V1 j4 K
location / {
, {2 F! X2 X$ n& M4 C% m1 V    ModSecurityEnabled on;  
" y6 p( p# L, j" v    ModSecurityConfig modsecurity.conf;  
; w: B: I5 F) @7 v" U
) h4 o8 B6 ^  V$ |8 ^& k3 ]        proxy_pass http://online;( u6 Q' }4 g9 _9 @6 X
        proxy_redirect         off;
, s8 s; Q" b: S        proxy_set_header Host $host;
5 g9 X2 B! z: ?, g        proxy_set_header X-Real-IP $remote_addr;
' D4 z' a% i. f- H9 E        proxy_set_header  X-Forwarded-For $proxy_add_x_forwarded_for;2 a/ w# M) ^. S* M- n/ b6 a
    }
  I6 ?4 M; Q( w' s5 V& D2 A}; I+ g& j5 r- J4 ]7 R8 R
六.测试
) x+ p3 z  }& b* L$ s
# l" f/ n) S/ C) U- c  S+ ^- o我们启用了xss和sql注入的过滤,不正常的请求会直接返回403。以php环境为例,新建一个phpinfo.php内容为:+ F3 U9 u2 A' ~7 E

+ G/ j- X6 l/ x  k( Q) W<?php3 k1 u. H3 H. w1 e6 B
    phpinfo();   
( S" [* l" W# B8 [2 }( h. n) e7 X2 n8 k- Y?>5 j" t9 r/ k) R1 y
在浏览器中访问:
! y$ }& t9 p6 \; z: p% O# J7 z) V. L4 ^. S4 @2 N
http://www.52os.net/phpinfo.php?id=1 正常显示。
$ `0 e4 r8 [' c  s: @" k  Nhttp://www.52os.net/phpinfo.php?id=1 and 1=1  返回403。
3 G6 G; j) A) A2 ?: s) shttp://www.52os.net/phpinfo.php?search=<scritp>alert('xss');</script>  返回403。
& \" M$ c9 W% v9 m" p7 V9 ]说明sql注入和xss已经被过滤了
0 Q4 F3 J/ i2 \7 A* U: Y& y  O) S! c3 o' x  L9 y9 S2 b& k  f7 V! ~
七、安装过程中排错- w' j4 ~  B; N1 B+ d
/ b* }4 @. _  j4 V# x/ t
1.缺少APXS会报错
% w9 _1 O4 Q5 z' _: u) U
. k9 I: x0 N3 {, X+ T4 tconfigure: looking for Apache module support via DSO through APXS0 a! P9 X- B! o5 n
configure: error: couldn't find APXS* W4 s. m' z- H+ K
apxs是一个为Apache HTTP服务器编译和安装扩展模块的工具,用于编译一个或多个源程序或目标代码文件为动态共享对象。- e7 e# k7 D6 l$ N
解决方法:
" f; c3 Z* [0 d& U* k. G7 U! j7 v1 Z+ k$ A0 J
yum install httpd-devel
3 C. G  p7 z& \) M9 L2.没有pcre
- K6 L9 H5 @( \
* E% j2 P& w. C2 I1 T; P6 R7 aconfigure: *** pcre library not found.
6 A% k8 @# O( f2 ?4 S$ j! [6 v; bconfigure: error: pcre library is required
1 t5 T8 t8 |1 n" e% _  L. J解决方法:
, [: x* v- m/ B0 b* [$ B# N4 v# j8 }3 W! O7 H; O7 @
yum install pcre pcre-devel7 Z5 L  J' f, E; L) [
3.没有libxml28 E2 W; M0 [  Z) Z" n+ L  l6 `
1 {1 Y" i3 `- z5 i2 [8 D! F

" C% j& O6 o" xconfigure: *** xml library not found.2 T$ j5 X+ H( Y( p! z* W3 K
configure: error: libxml2 is required' F! Q& X! N, c5 H9 U: h& ~
解决方法:
# d. Y* F0 k: W6 i' f0 r& s: s0 E8 D3 R  E- T
yum install  libxml2 libxml2-devel
& `: ?& V: f7 m5 E! Q& }4.执行 /opt/tengine/sbin/nginx -m 时有警告/ Z" W* W5 \' C# M  g' Y& @' a

% I" ?8 B( h# P  U& A( S! X; j- N( aTengine version: Tengine/2.1.0 (nginx/1.6.2)6 i# v5 F; T5 Q6 R% K. R% ^
nginx: [warn] ModSecurity: Loaded APR do not match with compiled!& |+ |, G# h4 {6 i! w& s# B
原因:modsecurity编译时和加载时的apr版本不一致造成的,并且会有以下error.log, D8 \7 q, q) z, Z( k

8 e- W5 N+ ~/ r2015/01/26 02:04:18 [notice] 29036#0: ModSecurity for nginx (STABLE)/2.8.0 () configured.
# ^" B' t$ j" q2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: APR compiled version="1.5.0"; loaded     version="1.3.9"
* W/ m  b/ d8 L) i  k2015/01/26 02:04:18 [warn] 29036#0: ModSecurity: Loaded APR do not match with compiled!
2 F4 k  Q2 E% Y! E" R2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: PCRE compiled version="7.8 "; loaded version="7.8 2008-09-05"
. k" @7 O' T4 w: B) l: B9 ]2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: LIBXML compiled version="2.7.6"
( w4 o' F1 x) x7 m7 `; D/ T2015/01/26 02:04:18 [notice] 29036#0: Status engine is currently disabled, enable it by set SecStatusEngine to On.
8 [+ D/ ?( G4 E( H+ _解决方法,移除低版本的APR (1.3.9)0 ]! J5 L7 v$ b7 h

- W6 L" ~% Y( Hyum remove apr9 E8 i6 J- W2 t  m
5.Error.log中有: Audit log: Failed to lock global mutex
, C2 b% M4 ^6 E/ |
/ p! b$ ^% N: n3 q2015/01/26 04:15:42 [error] 61610#0: [client 10.11.15.161] ModSecurity: Audit log: Failed to lock     + s7 q: f7 h' F. |. m
global mutex: Permission denied [hostname ""] [uri "/i.php"] [unique_id "AcAcAcAcAcAcAcA4DcA7AcAc"]
9 J; f* E9 j' R- F$ F解决方法:
7 [8 b+ ^; p4 S  Y编辑modsecurity.conf,注释掉默认的SecAuditLogType和SecAuditLog,添加以下内容:# x' d, C) F! K. g! _" J. H
1 }4 G+ o5 z, r# E& I
SecAuditLogDirMode 0777
# C) }% {- j* M8 O# d2 W- tSecAuditLogFileMode 05500 f, c/ w7 \& F# m5 o. t
SecAuditLogStorageDir /var/log/modsecurity4 V* ]4 e5 y4 i& k3 V. a0 }) G
SecAuditLogType Concurrent/ R7 ^7 i) r& `' w. G
参考文章:& {9 X1 G3 y2 \& t6 x
https://github.com/SpiderLabs/ModSecurity/wiki/Reference-Manual#Installation_for_NGINX7 G# [% U# B; K& {. J
http://drops.wooyun.org/tips/2614
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

QQ|Archiver|手机版|小黑屋|第一站论坛 ( 蜀ICP备06004864号-6 )

GMT+8, 2026-10-7 19:04 , Processed in 0.049842 second(s), 19 queries .

Powered by Discuz! X3.5

© 2001-2026 Discuz! Team.

快速回复 返回顶部 返回列表