|
|
modsecurity原本是Apache上的一款开源waf,可以有效的增强web安全性,目前已经支持nginx和IIS,配合nginx的灵活和高效,可以打造成生产级的WAF,是保护和审核web安全的利器。: J; w. A6 h" n ^. M
+ O# d" @+ {: B& F( }
一.准备工作
; k3 J/ u( y" I7 g
6 U5 Q y& g D$ j系统:centos 6.5 64位、 tengine 2.1.0, modsecurity 2.8.0/ e: R( O* G" _/ y
8 E) B. b+ w- o
tengine : http://tengine.taobao.org/download/tengine-2.1.0.tar.gz2 o; Y9 l( J; |1 U0 g& O7 ~, p5 M
2 z/ z) S+ d) J& Z3 l3 E7 Tmodsecurity for Nginx: https://www.modsecurity.org/tarball/2.8.0/modsecurity-2.8.0.tar.gz
+ S) b: [& q6 |) r! I
) Q: G7 O9 ^0 H' X/ tOWASP规则集: https://github.com/SpiderLabs/owasp-modsecurity-crs) {4 ?7 Y" `5 Y6 s
8 q- o( [8 T: O8 b4 I. B. S) S依赖关系:9 O0 ?, t- \1 \. e" Q
tengine(nginx)依赖: pcre 、zlib、 openssl, 这三个包centos 6.5 系统源里都有:( l9 q3 E4 g+ U' O
7 P: M: H. D6 P, `6 h& j }yum install zlib zlib-devel openssl openssl-devel pcre pcre-devel
2 `# z5 F1 H' [1 Amodsecurty依赖的包:pcre httpd-devel libxml2 apr4 s- D/ ?( y1 c
! f3 q/ f1 ^/ j' O3 ^yum install httpd-devel apr apr-util-devel apr-devel pcre pcre-devel libxml2 libxml2-devel
! }! Q% N: f. Z& z; c( o3 Q# N& W3 o二.启用standalone模块并编译
7 H" a* s% o) O7 N
% w0 P! l. _4 b2 d* ?下载modsecurity for nginx 解压,进入解压后目录执行:
$ `) L7 |: O6 G4 ]% |: t$ R/ s _7 v$ K4 K% L- D5 {7 n
./autogen.sh
. K* F4 G4 K5 y8 q6 Q. W4 W+ [' A./configure --enable-standalone-module --disable-mlogc
; ]& }) P6 I |make
* A* |' _! `0 B( k+ q, e三.nginx添加modsecurity模块
4 b V4 M- G2 n# L( M$ s% Y0 w' h; g- z- @: p
在编译standalone后,nginx编译时可以通过"--add-module"添加modsecurity模块:
/ H& w5 F; V; y4 w+ O6 [1 T
3 r1 s+ z0 D* E" Y8 Z# B./configure --add-module=/root/modsecurity-2.8.0/nginx/modsecurity/ --prefix=/opt/tengine, q" W3 {5 [5 z r% z, a( ~7 f
make && make install8 f6 Q0 {# B$ G
四.添加规则
4 I' X; I1 G- T- W
( _! B# n- b$ X9 A7 O6 A) Jmodsecurity倾向于过滤和阻止web危险,之所以强大就在于规则,OWASP提供的规则是于社区志愿者维护的,被称为核心规则CRS(corerules),规则可靠强大,当然也可以自定义规则来满足各种需求。0 V& l! o+ Y3 j
/ f( ?/ @' k* ?. G m) H
1.下载OWASP规则:* a) e* ^/ H: h V6 g2 Q. ^5 l! A
! w5 B6 u- _; {4 f7 x1 {git clone https://github.com/SpiderLabs/owasp-modsecurity-crs# l8 A7 {) U* S; w2 t4 a1 r
7 X$ `5 u9 H9 d2 emv owasp-modsecurity-crs /opt/tengine/conf/, I9 l" g6 z* O g7 S
) U$ D# B2 a) ?5 o& R% [" X2 z* T% K% ~cd /opt/tengine/conf/owasp-modsecurity-crs && mv modsecurity_crs_10_setup.conf.example modsecurity_crs_10_setup.conf
' g# C) {* u* [7 h+ i" {2.启用OWASP规则:- Y- R5 T/ i" H9 m( @8 i
5 ^6 v- w5 W- r5 ?$ t3 F! K复制modsecurity源码目录下的modsecurity.conf-recommended和unicode.mapping到nginx的conf目录下,并将modsecurity.conf-recommended重新命名为modsecurity.conf。
" ^4 U8 ^- Q& _' e. o' j/ N6 o0 n% V
编辑modsecurity.conf 文件,将SecRuleEngine设置为 on
+ i. ]4 D9 U; S. j4 \0 ]. R. f: v' x# z0 w8 ?4 \5 M4 J) W
owasp-modsecurity-crs下有很多存放规则的文件夹,例如base_rules、experimental_rules、optional_rules、slr_rules,里面的规则按需要启用,需要启用的规则使用Include进来即可。- s% C1 b6 ^( j; z/ S
9 A: \. L0 W4 X# [! [Include owasp-modsecurity-crs/modsecurity_crs_10_setup.conf* l) x/ @! M" c1 p k1 B
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_sql_injection_attacks.conf
4 t$ e, T t9 V; E" mInclude owasp-modsecurity-crs/base_rules/modsecurity_crs_41_xss_attacks.conf& N: Y0 m7 w) j1 {
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_40_generic_attacks.conf: W- y: K7 v1 M, r& _
Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_dos_protection.conf4 r( Z7 w J; M0 r& {( O0 Z! j+ o B
Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_brute_force.conf
* {. [& y$ }" s, q2 B/ JInclude owasp-modsecurity-crs/optional_rules/modsecurity_crs_16_session_hijacking.conf
# Y& p# @& w. G# t1 ]五.配置nginx
3 b$ t% a ]2 C E
' k: v4 T5 ^7 a5 r% }) K* ~1 g& E) V在需要启用modsecurity的主机的location下面加入下面两行即可:
+ {- l( W' X' r1 W4 b5 a
: y8 \. e0 A2 @# g: h/ P& }+ yModSecurityEnabled on; / U$ q0 N3 \! m. ^1 V9 f1 R
ModSecurityConfig modsecurity.conf;' ^, Q0 W s: q0 l
下面是两个示例配置,php虚拟主机:
0 l& @* w: B9 S% u) _7 b A2 N. [9 J' r! q5 y( `
server {
3 h2 U$ Q S# Q* H/ m7 b1 H: u+ g listen 80;: }/ w: [, y! L
server_name 52os.net www.52os.net;& I: ^ O+ j4 n% f6 v2 o
& m& P0 j' s2 p$ [
location ~ \.php$ {& ]; D4 N) q6 ]& C
ModSecurityEnabled on;
7 c8 \* r$ d; O$ A ModSecurityConfig modsecurity.conf;
6 ^/ u- n2 i$ r5 f
! ~$ @6 ]( r$ ~" H# ]1 ~8 d root /web/wordpress;0 T4 o# M+ q1 W5 C
index index.php index.html index.htm;
' ~2 E8 D8 H7 e6 P/ G/ Y( c5 X5 q- Z
5 i5 A5 W& M% c$ B( j/ Y fastcgi_pass 127.0.0.1:9000;0 W+ K4 s1 H2 \
fastcgi_index index.php;
% Z, `. s1 `$ |( U" w fastcgi_param SCRIPT_FILENAME $Document_root$fastcgi_script_name;
) @4 X" H. t; L& Z( c6 k% [& x% [ include fastcgi_params;
5 Q5 Z3 S, D: }% O6 o" }. `- a9 ` }" |: N# ^+ ?/ F: U
}
) v1 M. S& T* D7 N8 k( Lupstream负载均衡:$ ]6 v" F) `3 {: r- Z* f& A
4 N6 h: i# ~5 Z% ]+ xupstream 52os.net {$ ]+ Y: y I; F. a
server 192.168.1.100:8080;4 Q @6 A( d2 l$ `# f7 E6 a: I4 e
server 192.168.1.101:8080 backup;& d* U# U9 ?2 J6 a' u$ a
}
& h( ?$ B) B) N" Y7 f! W- L0 K; S& r3 ?) }" |# Z9 f
server {
8 j0 _4 l6 I9 E8 H+ t! C7 Ilisten 80;
. r' O: B$ A7 u: d9 v: D: mserver_name 52os.net www.52os.net;1 V* f9 D& R2 U; u, }
( }; K2 ~$ Y/ P' x9 Q6 P
location / {1 _4 T3 L: {' u6 R. a+ w
ModSecurityEnabled on;
- H& P6 C/ ?3 j3 {1 P d: \ ModSecurityConfig modsecurity.conf; 6 Y1 R5 a) E' ?* B" {/ m. _% Q
; r- x% S5 k# ^0 z1 z proxy_pass http://online;
* I, X! Q% W \6 r* Y/ O. N proxy_redirect off;% V- t* A6 }2 k! n5 l
proxy_set_header Host $host;. ?+ g; J+ M6 ^. I
proxy_set_header X-Real-IP $remote_addr;
+ M1 A1 m7 ?' d9 r5 F7 _ proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; ]. w' F# j& H7 M# H
}3 }% h: l j; j% K( U/ A1 c$ }" _
}% v: K& E$ W0 m7 l; p
六.测试! }, w& G+ ?" T$ X# u" [
3 a- q' F& v) r3 W! y! l' f$ W; b
我们启用了xss和sql注入的过滤,不正常的请求会直接返回403。以php环境为例,新建一个phpinfo.php内容为:: [2 t9 o0 e d; P# x0 V+ i3 ]4 q
0 A% P0 E% i0 [" h' v1 t# g
<?php8 I" w" {- \; i: x9 [( n/ ~2 Q
phpinfo(); * ~& p' e* p6 Z4 Q- \
?>3 ]: e+ h, k0 H6 x. ]) o
在浏览器中访问:
' Y; \% a: V- ~" q
! s) R& Z% y4 y; m7 W. Bhttp://www.52os.net/phpinfo.php?id=1 正常显示。
E2 l$ o- T" k, w2 `( X* x4 Khttp://www.52os.net/phpinfo.php?id=1 and 1=1 返回403。
7 A+ w1 y+ g' _: Hhttp://www.52os.net/phpinfo.php?search=<scritp>alert('xss');</script> 返回403。
! _0 d9 k0 h& l# k$ e说明sql注入和xss已经被过滤了
q0 g* W% F- ]3 V$ f
5 b. d( ^. N' R8 }2 `七、安装过程中排错
( M$ s: j* U W2 s( q9 }" }# I. V- E
1.缺少APXS会报错
/ Z1 h6 o. c0 ?' d Z
( }# {* P( G4 i E/ E- ?8 D) E4 i. oconfigure: looking for Apache module support via DSO through APXS4 z! C! n: i: O
configure: error: couldn't find APXS
9 ?7 O( z" i; _8 l7 Xapxs是一个为Apache HTTP服务器编译和安装扩展模块的工具,用于编译一个或多个源程序或目标代码文件为动态共享对象。: p. Q+ N0 j. ]3 q* u# m
解决方法:& O. @' g0 X3 d+ n- m# Z( }2 G
, A h! Y6 Y" k+ T; K7 P8 q8 H
yum install httpd-devel
. [: p; _# B! ]+ [9 e; b2.没有pcre
$ C; g" Y, x4 `+ Y P; |: F
; Y! |5 ~1 p, z2 Cconfigure: *** pcre library not found.
F+ ]" E, b0 g5 Fconfigure: error: pcre library is required
3 K9 I+ `& G& d+ e, l/ L1 w, L( g解决方法:
1 F: T' @# `1 @1 \% h& q8 z6 j' `" o. F& a. M5 Q
yum install pcre pcre-devel
4 O) v( W* C; ], {; f' u3.没有libxml2* [5 x* j7 ?% s
5 O ~# U6 Q8 J0 N
" I" ?1 [ D1 X7 Q$ `" nconfigure: *** xml library not found.
3 }: b* K2 u, _) v5 m7 O2 Q+ n, yconfigure: error: libxml2 is required
- |: B' T3 x* l3 k解决方法:3 |7 e1 Y& ]& ~# o, E2 O8 H
% C$ O3 e. E( _2 B2 a b2 a* Dyum install libxml2 libxml2-devel. n ~; C# \4 t$ j! c
4.执行 /opt/tengine/sbin/nginx -m 时有警告+ E% W. h. I5 @3 F" v
( _( p0 L6 T1 @7 M% G' DTengine version: Tengine/2.1.0 (nginx/1.6.2)0 l# p+ b' }2 V
nginx: [warn] ModSecurity: Loaded APR do not match with compiled!
" m* h/ r/ o% [' }) b' h原因:modsecurity编译时和加载时的apr版本不一致造成的,并且会有以下error.log
0 {/ B, a; z2 ]5 L0 y4 h' V
, u- V& m E- t- b; M( `3 s/ g2015/01/26 02:04:18 [notice] 29036#0: ModSecurity for nginx (STABLE)/2.8.0 () configured.
0 r3 Q& f7 b6 b% }6 G8 f- T2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: APR compiled version="1.5.0"; loaded version="1.3.9"/ Y2 Q# X3 \+ j4 R+ V; I
2015/01/26 02:04:18 [warn] 29036#0: ModSecurity: Loaded APR do not match with compiled!
$ T. ?( D3 T! v$ G) |; ]5 B6 |1 o' Q2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: PCRE compiled version="7.8 "; loaded version="7.8 2008-09-05"
$ D5 Q3 u+ t! Y# A+ ?' b2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: LIBXML compiled version="2.7.6"% |$ [) B. Y9 S& X: G M# S
2015/01/26 02:04:18 [notice] 29036#0: Status engine is currently disabled, enable it by set SecStatusEngine to On.1 u! D; Q) T; T1 [0 g
解决方法,移除低版本的APR (1.3.9)
+ m7 [4 e1 }+ c; l# u
* u! J( ~7 z. } v3 O* K+ |8 z4 }yum remove apr
: y% @" z$ R. t5.Error.log中有: Audit log: Failed to lock global mutex
" C, s( S" U2 O3 l4 o2 W
( x9 k/ l# o( T P/ o) b- G5 W2015/01/26 04:15:42 [error] 61610#0: [client 10.11.15.161] ModSecurity: Audit log: Failed to lock
3 e% o& R# ]: S, |5 p) x7 s4 A, R" Dglobal mutex: Permission denied [hostname ""] [uri "/i.php"] [unique_id "AcAcAcAcAcAcAcA4DcA7AcAc"]( u! U1 E: }+ `/ n3 G& I) X4 a
解决方法:1 P! s& v' r4 E( X) E ^
编辑modsecurity.conf,注释掉默认的SecAuditLogType和SecAuditLog,添加以下内容:) w( S5 b& J6 w4 p8 I1 ^, F2 o3 B7 a: T
1 J: j9 n8 o6 |# p) G5 _. \
SecAuditLogDirMode 0777
5 b& r- [1 U" a# VSecAuditLogFileMode 05500 p6 J0 @; p; u3 y4 {
SecAuditLogStorageDir /var/log/modsecurity
1 ]5 L/ }' t$ i4 t E+ i3 xSecAuditLogType Concurrent
5 W; }1 |( j: J9 m+ S3 F参考文章:/ x6 x: O5 B% ?" P/ b
https://github.com/SpiderLabs/ModSecurity/wiki/Reference-Manual#Installation_for_NGINX
5 |; R5 c5 t) T' \5 ]# v% X" Uhttp://drops.wooyun.org/tips/2614 |
|