找回密码
 立即注册

QQ登录

只需一步,快速开始

查看: 12767|回复: 0

nginx配合modsecurity实现WAF功能

[复制链接]
发表于 2017-10-19 16:53:31 | 显示全部楼层 |阅读模式
modsecurity原本是Apache上的一款开源waf,可以有效的增强web安全性,目前已经支持nginx和IIS,配合nginx的灵活和高效,可以打造成生产级的WAF,是保护和审核web安全的利器。- ~$ ^+ x* K4 `, Z
  N8 Y2 b# X* R
一.准备工作
' B% z' g2 A% _2 N9 i- U' s
2 i" b3 D" N9 W' e6 u; c系统:centos 6.5 64位、 tengine 2.1.0, modsecurity 2.8.0
$ F' ~  R' L: L" Q5 J, ~8 E' T) k4 K3 I/ D: N4 ]& j6 O0 h
tengine : http://tengine.taobao.org/download/tengine-2.1.0.tar.gz8 u# |! }; S3 Y' F8 j

, C- Q! T" Q0 ^+ ^" A  h8 r8 {modsecurity for Nginx: https://www.modsecurity.org/tarball/2.8.0/modsecurity-2.8.0.tar.gz
: r. h3 t6 U: m0 |4 Z: g" w0 Z' N$ ^7 E4 k
OWASP规则集: https://github.com/SpiderLabs/owasp-modsecurity-crs
/ _% X& @8 V' V( G7 P* |1 J9 W' i7 u1 J- f+ R
依赖关系:3 W4 e8 {; d& e$ h, j& ]( p
tengine(nginx)依赖: pcre 、zlib、 openssl, 这三个包centos 6.5 系统源里都有:
$ U0 v& ]; W- e% y
& W$ b. z+ x* }) Oyum install zlib zlib-devel openssl openssl-devel  pcre pcre-devel  G7 Z* u) Y. e* i! E
modsecurty依赖的包:pcre httpd-devel libxml2 apr, K; d4 w. O9 P" I
" @4 P% f: F) M# I" v$ D. L( N. T
yum install httpd-devel apr apr-util-devel apr-devel  pcre pcre-devel  libxml2 libxml2-devel0 l" a3 @' K0 w1 \+ t
二.启用standalone模块并编译
. O* R+ R5 t; m; Y0 Z/ f; _5 p3 p. P3 |) h; j! x
下载modsecurity for nginx 解压,进入解压后目录执行:
  y) T# a: K: ~. [" a
! V' F2 D3 J$ G- H. C./autogen.sh# `- Y; z4 i8 B3 h9 o/ u% n
./configure --enable-standalone-module --disable-mlogc
$ v/ p2 ]' a0 {5 B% q0 X& @; K) mmake
6 r; D1 u0 ], g9 M* W4 h6 _三.nginx添加modsecurity模块9 s" A. e+ l4 d" I( \9 w. N
* I1 A! m4 _9 Y% q
在编译standalone后,nginx编译时可以通过"--add-module"添加modsecurity模块:2 H! F8 f1 Y5 Q4 i0 }9 d) B& `9 q
8 V7 k8 j. A, f4 m
./configure --add-module=/root/modsecurity-2.8.0/nginx/modsecurity/  --prefix=/opt/tengine
# E0 w+ a% W. C/ smake && make install/ K. P# y1 x7 L* Y9 c( z
四.添加规则  Y8 y& U) ^: e! g9 ~, G

) w, a; `2 T  H2 n8 ~modsecurity倾向于过滤和阻止web危险,之所以强大就在于规则,OWASP提供的规则是于社区志愿者维护的,被称为核心规则CRS(corerules),规则可靠强大,当然也可以自定义规则来满足各种需求。
4 A) m$ L8 u3 v8 [
8 @9 [9 h: O7 g1 A+ \$ g1.下载OWASP规则:% ^' o5 u) e* J7 }* H- R
- N2 o* g0 G  Q& \
git clone https://github.com/SpiderLabs/owasp-modsecurity-crs
/ m3 \" Z% L$ f2 Z% H( T
$ o6 `* x8 |- O- ]$ ^mv owasp-modsecurity-crs /opt/tengine/conf/
4 }  q* T  q* a
! l; p! ~3 m- F) ^& Ocd /opt/tengine/conf/owasp-modsecurity-crs && mv modsecurity_crs_10_setup.conf.example modsecurity_crs_10_setup.conf
4 K, P; P  N! f2.启用OWASP规则:
; |) D9 {: r, J8 O, m7 R! W
4 L8 Q$ T0 X) I. U- |0 I% q复制modsecurity源码目录下的modsecurity.conf-recommended和unicode.mapping到nginx的conf目录下,并将modsecurity.conf-recommended重新命名为modsecurity.conf。% i2 J3 E8 w2 H

! e. y% L6 d+ x9 R2 k7 Z编辑modsecurity.conf 文件,将SecRuleEngine设置为 on
. g# b9 t% X8 m0 E" l
1 S; k* A3 Y" A" C. s& L. @  _$ }owasp-modsecurity-crs下有很多存放规则的文件夹,例如base_rules、experimental_rules、optional_rules、slr_rules,里面的规则按需要启用,需要启用的规则使用Include进来即可。
+ W& j# C/ n5 O, c, G; T; I- W) b$ T" J  e
Include owasp-modsecurity-crs/modsecurity_crs_10_setup.conf, q+ s6 M" B+ d: d) q4 w; f
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_sql_injection_attacks.conf
# w) a1 f, a  r5 ?9 {% YInclude owasp-modsecurity-crs/base_rules/modsecurity_crs_41_xss_attacks.conf  Z  s; @" e: k6 K6 V$ n
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_40_generic_attacks.conf
) X. q9 E8 I" s. B0 A- tInclude owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_dos_protection.conf7 ]) v6 _2 N3 _) w
Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_brute_force.conf
6 V* b' l" d& W# N) v" JInclude owasp-modsecurity-crs/optional_rules/modsecurity_crs_16_session_hijacking.conf$ O" {0 N9 V' V( ^  _( T% m+ N
五.配置nginx" E" d4 `9 W8 \( V0 W/ p

8 r! S" D( J' ^在需要启用modsecurity的主机的location下面加入下面两行即可:
" R# u+ W5 u# v6 y( \  ?# ~! G) N7 [6 C$ ]
ModSecurityEnabled on;  , f" X3 ^9 ^) a( e& z
ModSecurityConfig modsecurity.conf;- i* ~& ~1 _9 d  V! c1 L, x8 V3 m6 k
下面是两个示例配置,php虚拟主机:
  K5 ?6 Y, q* D* F3 y5 D8 j3 g. p) r* g8 X+ }: [* m
server {$ Q5 x  e+ }  m  [% W$ y
      listen      80;
! R0 q/ b0 s( ?- |- s# _' J5 X      server_name 52os.net www.52os.net;
: }9 I5 ?2 Q' @: a% }5 z; I7 \     1 p- g9 E1 h9 {2 D  N! B( G
      location ~ \.php$ {
6 R1 f5 c2 y- w8 Z      ModSecurityEnabled on;  
9 l9 H8 J0 J, R& l4 O" Z% `$ F      ModSecurityConfig modsecurity.conf;6 E; F9 P3 }9 n' h' @! \' ]
% W% F1 u, d$ W/ I  v
      root /web/wordpress;& \- ?8 j  V, D) l& M7 s: ^5 F3 ^1 P
      index index.php index.html index.htm;  z& L! |9 ?  m+ K
  . `  ?. ?: _& U% I+ y- n- e$ ?
      fastcgi_pass   127.0.0.1:9000;
1 r9 G5 l2 o. O) [  g      fastcgi_index  index.php;
( K, {4 l  j; a' P" i, V; ~% o      fastcgi_param  SCRIPT_FILENAME  $Document_root$fastcgi_script_name;+ h  s* r- M* ?, h: Q3 h( S  k
      include        fastcgi_params;' P+ f/ K. I* X/ |2 W
      }2 m( g, d1 N' h- t" M8 s
  }& \+ k  i- Y4 w$ i1 O$ J* U( W
upstream负载均衡:
5 k; W& K4 q, ^% v. R* Z! a3 e
9 C9 W( n; e# i6 ]5 I* Zupstream 52os.net {1 a9 Z5 l, r1 j3 a' z2 x4 s
    server 192.168.1.100:8080;9 o9 `7 \2 A" G9 Z' l
    server 192.168.1.101:8080 backup;
. a" g0 V1 U  `% `}6 r/ @( {, w% ]6 ]2 j1 X
/ }* c* i* s; L$ ^
server {
7 {" k6 r1 v' O( q, j  E( @$ Nlisten 80;+ \" P- C5 m& N$ d* z( x# K
server_name 52os.net www.52os.net;
& |7 S: k- ]# A. e! y* ~' a- u3 `* @* m- A0 H. g1 G  v( d
location / {2 @1 {/ y: N' |: \, G
    ModSecurityEnabled on;  
$ F3 D, J1 \" ]    ModSecurityConfig modsecurity.conf;  5 I" Q2 W7 P) u; w' w
2 Q2 O& u* d. h+ D% a& K
        proxy_pass http://online;+ X: z# A$ B7 g# E$ H
        proxy_redirect         off;8 _0 M. x1 T+ S
        proxy_set_header Host $host;; ]0 h* U- o% C* a- h3 C5 T
        proxy_set_header X-Real-IP $remote_addr;
: c5 {! |3 F: n5 N7 x/ o# g$ ^+ ]        proxy_set_header  X-Forwarded-For $proxy_add_x_forwarded_for;* ^9 ?4 J4 Y/ n1 H2 }
    }
& e7 p3 Q( e. j9 c# o7 T! J}2 r, L4 ~3 U3 T
六.测试3 \: W, x5 _7 J3 z( f

( b$ S5 O* e0 f7 v我们启用了xss和sql注入的过滤,不正常的请求会直接返回403。以php环境为例,新建一个phpinfo.php内容为:1 z; _1 o9 z2 _! [+ D

. Y3 T+ n7 R1 ^+ S1 }<?php
7 F) p5 I( n7 S9 t" a    phpinfo();    ' S8 f/ ?5 M! Y# l) i6 a
?>
& e; D5 x, e9 _$ e/ X  O在浏览器中访问:
% _; Q/ _, Q" z- G- b. x' A; W3 s! z, f8 w% e  J
http://www.52os.net/phpinfo.php?id=1 正常显示。
1 Y4 o8 E( \( d4 _5 o1 O& Yhttp://www.52os.net/phpinfo.php?id=1 and 1=1  返回403。
3 e8 f3 ?! I6 thttp://www.52os.net/phpinfo.php?search=<scritp>alert('xss');</script>  返回403。
/ E0 f" V7 P6 p  f说明sql注入和xss已经被过滤了: ?/ _9 e9 ]* e5 S4 B; W& A! n( w+ ]
/ L: V2 A" P5 U; F
七、安装过程中排错& b1 Q/ `2 V0 @$ E4 X( ]

. t! c1 m6 ^3 I& E: z* V- E, h1.缺少APXS会报错
; c. R; n* u/ |+ ~' B+ I
& {& l4 R" Z- _+ @* Lconfigure: looking for Apache module support via DSO through APXS  M5 D7 ~2 {9 y, I: T
configure: error: couldn't find APXS
. ]" K* r5 ]! C( E# a$ T+ q6 Rapxs是一个为Apache HTTP服务器编译和安装扩展模块的工具,用于编译一个或多个源程序或目标代码文件为动态共享对象。5 v5 G* D( H, n9 h0 x
解决方法:! X2 W7 w; T5 d- r5 \5 n, q& Q' {

1 b. Y- E% \" G" Oyum install httpd-devel3 B$ v! m* L; J% h$ r$ G( R7 E
2.没有pcre8 H  z2 U/ O; U

: `9 {3 i7 t! S$ @% ]" b) |configure: *** pcre library not found.
' u8 u& q/ a* K* ]" X9 _7 X+ oconfigure: error: pcre library is required4 I% v) |7 u( A- t9 Z. q
解决方法:' Q" _% S' a9 s( X5 k

% d1 W* d: S: Qyum install pcre pcre-devel7 ~8 l; j% B" E! R* }( T1 a
3.没有libxml2
! P) x9 m# N. o( w6 ]5 l# u
& Z" v$ H, O2 O: X+ A, K' Y3 a! D0 R% [3 j
configure: *** xml library not found.
4 q& G) k! a3 q- c- `. _$ j% k# X; ~configure: error: libxml2 is required4 X3 c" A7 u' r3 E- N4 ^8 H8 P1 \0 K
解决方法:8 U  _' f! D9 J. F
* t! |, T; ]$ V- I
yum install  libxml2 libxml2-devel
; D1 F9 D3 e* P( c& j4 q% n4.执行 /opt/tengine/sbin/nginx -m 时有警告6 p  R* k& a4 ]3 b
( c7 }" \* m, Z$ c. p3 U
Tengine version: Tengine/2.1.0 (nginx/1.6.2)" {* f; i8 F! ~& h
nginx: [warn] ModSecurity: Loaded APR do not match with compiled!3 C1 d1 Z4 ?8 b, P
原因:modsecurity编译时和加载时的apr版本不一致造成的,并且会有以下error.log7 u4 Y* v1 T1 |; G; J
1 R. b& F4 z7 s# D. I; s
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity for nginx (STABLE)/2.8.0 () configured.4 C& `  X0 A* Q' `  m
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: APR compiled version="1.5.0"; loaded     version="1.3.9"8 w8 Q) s1 Y. Z" ]
2015/01/26 02:04:18 [warn] 29036#0: ModSecurity: Loaded APR do not match with compiled!
2 [, @0 Q( h/ B9 I& D! }2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: PCRE compiled version="7.8 "; loaded version="7.8 2008-09-05"4 e7 {5 g5 M2 J
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: LIBXML compiled version="2.7.6"
3 ?  h( @0 O# ]. [2 X5 p! S+ N2015/01/26 02:04:18 [notice] 29036#0: Status engine is currently disabled, enable it by set SecStatusEngine to On.9 v# U7 m) ^2 M8 Y/ Y8 C
解决方法,移除低版本的APR (1.3.9): T/ ~! ]3 u2 J1 p. \

+ W6 o' |1 F* {yum remove apr8 x" U3 }. X3 I' u6 r& D- z
5.Error.log中有: Audit log: Failed to lock global mutex8 N; g7 H5 w! f6 W+ T! T" l

" ~$ W! i$ Q, I, a' W2015/01/26 04:15:42 [error] 61610#0: [client 10.11.15.161] ModSecurity: Audit log: Failed to lock     
) Q2 [( E! [  o4 mglobal mutex: Permission denied [hostname ""] [uri "/i.php"] [unique_id "AcAcAcAcAcAcAcA4DcA7AcAc"]
, [5 U+ O/ [' F解决方法:! B+ [) V+ V, W
编辑modsecurity.conf,注释掉默认的SecAuditLogType和SecAuditLog,添加以下内容:
5 r3 X3 q7 e9 x8 }
& \4 a3 [- r; GSecAuditLogDirMode 0777
& M+ o2 Y6 }% q; H( u. _% A; N7 n3 ySecAuditLogFileMode 05507 }# Z1 J0 d3 w. P, q/ i
SecAuditLogStorageDir /var/log/modsecurity
; P2 q2 A5 U4 N* l, S' lSecAuditLogType Concurrent4 z6 l5 [" c. N- f' p: y2 B
参考文章:, R  ^. [1 x7 e
https://github.com/SpiderLabs/ModSecurity/wiki/Reference-Manual#Installation_for_NGINX  Q  B# f$ \- ~4 `5 X' P) B
http://drops.wooyun.org/tips/2614
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

QQ|Archiver|手机版|小黑屋|第一站论坛 ( 蜀ICP备06004864号-6 )

GMT+8, 2026-10-9 23:12 , Processed in 0.133713 second(s), 19 queries .

Powered by Discuz! X3.5

© 2001-2026 Discuz! Team.

快速回复 返回顶部 返回列表