找回密码
 立即注册

QQ登录

只需一步,快速开始

查看: 12694|回复: 0

nginx配合modsecurity实现WAF功能

[复制链接]
发表于 2017-10-19 16:53:31 | 显示全部楼层 |阅读模式
modsecurity原本是Apache上的一款开源waf,可以有效的增强web安全性,目前已经支持nginx和IIS,配合nginx的灵活和高效,可以打造成生产级的WAF,是保护和审核web安全的利器。
3 P  w, z5 I- W) G( h4 e
$ M' b* X8 C. [1 a一.准备工作
$ \% A  Y. l8 |- |9 Q7 U( o6 [! ?% w& Z% N4 Z2 L0 s' m
系统:centos 6.5 64位、 tengine 2.1.0, modsecurity 2.8.05 i" z# \* e7 H3 C# ]% m/ j; n: }

! v* [/ Z( Q" R8 e1 \" S3 K( e) ]tengine : http://tengine.taobao.org/download/tengine-2.1.0.tar.gz/ K+ r/ n* H3 V

& S$ A+ Z1 U" [) Vmodsecurity for Nginx: https://www.modsecurity.org/tarball/2.8.0/modsecurity-2.8.0.tar.gz
7 y# G1 c# u; N( l4 W
" s: y9 B8 M  }+ @OWASP规则集: https://github.com/SpiderLabs/owasp-modsecurity-crs
: S6 Z# F; b# n  I. B- M
+ L* o6 n  R: T; @依赖关系:* G' s: j! }6 y4 v# V3 a0 u
tengine(nginx)依赖: pcre 、zlib、 openssl, 这三个包centos 6.5 系统源里都有:
6 Q5 I- x5 |; p1 |3 c9 l
& o  c6 \$ S9 ^$ W% H$ H1 \' Qyum install zlib zlib-devel openssl openssl-devel  pcre pcre-devel# l; E: w  I. v& S+ q
modsecurty依赖的包:pcre httpd-devel libxml2 apr  b; Q3 {/ a! i' g

3 T; S0 \# y& s' E, O/ a$ E. Yyum install httpd-devel apr apr-util-devel apr-devel  pcre pcre-devel  libxml2 libxml2-devel
1 a" ^1 x2 V# ~  h二.启用standalone模块并编译6 R  w# s* O9 |8 B
7 _$ l' H" S$ b4 o
下载modsecurity for nginx 解压,进入解压后目录执行:
# O, s) _% Y( x" v* b! V/ g* S$ w+ \9 |8 ]
./autogen.sh- F5 m! l8 G0 d" B8 s
./configure --enable-standalone-module --disable-mlogc
3 R$ L) x  u* u! d) o: rmake
7 e5 y3 f$ G8 f6 G& m4 z2 g2 a! A* W( m三.nginx添加modsecurity模块
" F3 o3 V( p- x( R2 L( B$ i- a
5 }3 f; H8 n6 J" r5 U在编译standalone后,nginx编译时可以通过"--add-module"添加modsecurity模块:
9 s9 B, M3 C- W3 O! @; ]
0 t2 ^( A$ Q0 x5 x./configure --add-module=/root/modsecurity-2.8.0/nginx/modsecurity/  --prefix=/opt/tengine
/ p5 F7 A% ^  d* Q; s! b5 C, l3 zmake && make install% @$ m0 Y; t' g2 \) r
四.添加规则1 u- c' |7 S) }9 x! M  r4 @5 {

9 [6 Z; N3 N, k( B) O7 Imodsecurity倾向于过滤和阻止web危险,之所以强大就在于规则,OWASP提供的规则是于社区志愿者维护的,被称为核心规则CRS(corerules),规则可靠强大,当然也可以自定义规则来满足各种需求。
) z* W1 P8 x9 e& R+ S8 ?
2 w; X- |) c% V/ N6 I1.下载OWASP规则:* m( [7 S4 A0 ]7 z
4 a$ e: [+ ?8 j5 M7 q( s0 R
git clone https://github.com/SpiderLabs/owasp-modsecurity-crs
1 w! B- n0 ~: n
2 M* l9 @+ T& x  Imv owasp-modsecurity-crs /opt/tengine/conf/1 e+ b5 ~" N4 A0 e; ?& o' v
/ h+ N' g& c. _  s7 ]$ c) D! V
cd /opt/tengine/conf/owasp-modsecurity-crs && mv modsecurity_crs_10_setup.conf.example modsecurity_crs_10_setup.conf
& s. a% ^# q9 G6 ]" s2.启用OWASP规则:
! l( @" V& L# S# C# g
2 t  R- c% t/ J4 z复制modsecurity源码目录下的modsecurity.conf-recommended和unicode.mapping到nginx的conf目录下,并将modsecurity.conf-recommended重新命名为modsecurity.conf。
$ g/ {7 i# f- i) A4 N7 _
9 b# F) r- ^. H编辑modsecurity.conf 文件,将SecRuleEngine设置为 on- K% }+ f/ E" F  N- d+ }

7 g. R0 \+ k" iowasp-modsecurity-crs下有很多存放规则的文件夹,例如base_rules、experimental_rules、optional_rules、slr_rules,里面的规则按需要启用,需要启用的规则使用Include进来即可。
( m7 ^5 r" S0 j! F, _$ \& t
" [1 [: P( P! aInclude owasp-modsecurity-crs/modsecurity_crs_10_setup.conf
; J) ^& `" `4 R- r# bInclude owasp-modsecurity-crs/base_rules/modsecurity_crs_41_sql_injection_attacks.conf
/ w. ^  |; M# F9 [Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_xss_attacks.conf9 S3 L8 k" \* M8 ~* N/ s
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_40_generic_attacks.conf
: B1 M' N1 l. L  k0 n4 }Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_dos_protection.conf
' i0 C: M  ~" ~& P, W8 g4 E; GInclude owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_brute_force.conf/ c! Q( e8 C6 w9 o
Include owasp-modsecurity-crs/optional_rules/modsecurity_crs_16_session_hijacking.conf% B: N0 X- T1 `6 \9 v0 y+ }
五.配置nginx, ]$ p3 Q: u" ]7 g9 }$ ?- _

5 s/ C. o- W4 S- S1 v$ r7 [. W% t7 @在需要启用modsecurity的主机的location下面加入下面两行即可:
% N8 N& J" e# q7 R, ~& r9 Q
# H5 C( v6 I' R$ \* w' M9 N7 QModSecurityEnabled on;  * ^$ D5 n& i1 i# ~) c+ A& J
ModSecurityConfig modsecurity.conf;
4 S2 u$ t4 {( ?; Z- G" D* O下面是两个示例配置,php虚拟主机:' y! _4 ]1 t  f( n- m' \5 K
! e, i. z5 q' M- s" W
server {2 V* P! x& l4 |6 s; v( T! \) \
      listen      80;
1 h+ O$ P1 y% v+ z: Q1 O      server_name 52os.net www.52os.net;
: n, }1 d  T0 p$ _( E1 N- r     
: q! U  a# ]" L+ J' X8 p; ^* K, B      location ~ \.php$ {
" M9 H8 `4 _, W0 r      ModSecurityEnabled on;  ) F+ T- E: ]* I! ]
      ModSecurityConfig modsecurity.conf;% _* c6 {. p  W; c& @: X

; F# X5 G/ L6 ~- \3 ~. S( M: K      root /web/wordpress;4 }; w$ C- i% ]% v1 ~5 a
      index index.php index.html index.htm;
+ u6 }- S3 O- h- M& j  ! ?4 E8 V4 i  R/ W2 Y! e% _
      fastcgi_pass   127.0.0.1:9000;! G. N  k* z* j* u
      fastcgi_index  index.php;
. X/ ]0 K7 p$ }5 M) P      fastcgi_param  SCRIPT_FILENAME  $Document_root$fastcgi_script_name;8 O& V) D  Q) R, A
      include        fastcgi_params;
* t# a- K7 H: H, i# u% E7 ~      }
5 N3 K9 K( y" y/ [4 x' f. j' V, a  }
: \* j" E" F) j5 R* uupstream负载均衡:& d- q% u, P9 b( b- Y

& ^! G5 a6 _# I5 m# k" wupstream 52os.net {
: s* f) ~2 q0 E5 I    server 192.168.1.100:8080;
( R3 B1 V1 n& L" o8 t9 R    server 192.168.1.101:8080 backup;/ o, _0 X2 w5 y
}
. ~3 _" G+ C# u9 I5 v
( X- h2 r7 X; h5 W1 H0 bserver {
0 K- R8 o: f$ b+ W  L, {! [7 x8 Plisten 80;
& W% u* ?, g1 \( a$ I& aserver_name 52os.net www.52os.net;) ~. u& Q  \. h4 i/ q2 V8 n
( {1 E: p7 @4 d/ W/ k% Q$ j: M
location / {3 z' `6 i9 T. o+ b/ ?+ J
    ModSecurityEnabled on;  
: K( h) @# h- M" ?' D    ModSecurityConfig modsecurity.conf;  
  A! i) h* j, a, A( \2 K! \; {) E% x- Z( Y( A# ~* \. S0 K7 H. X
        proxy_pass http://online;& E+ N  E/ |, T& e: `; f7 V6 y
        proxy_redirect         off;
" K3 ?8 a9 x7 r- U% l        proxy_set_header Host $host;
: G4 |) j- `4 J/ D        proxy_set_header X-Real-IP $remote_addr;. v2 p4 o' k% }0 U- ]
        proxy_set_header  X-Forwarded-For $proxy_add_x_forwarded_for;
1 G) g4 ~! y- w0 M* c    }
3 [5 i2 S5 j3 h8 Q7 t  i" q9 l}
' C  `' Z( k. Z' A* e$ k2 @' L六.测试, c' K3 g# x5 P: g- R

; M7 A- m1 F" v& ~6 F- p# E我们启用了xss和sql注入的过滤,不正常的请求会直接返回403。以php环境为例,新建一个phpinfo.php内容为:* |& P; d' r! A" [4 q/ R4 W$ G
7 Q2 n7 Y; {# {: ^
<?php
/ h4 v8 l; c8 [% B    phpinfo();    " Y0 e: U$ T9 Y) l2 r& A
?>5 a. \' r1 `5 g1 a/ q. N  r
在浏览器中访问:
0 M  `, f, w/ y4 f2 U# w6 c) M
) i: M& q: o) W9 U$ u0 ~# I+ Y) whttp://www.52os.net/phpinfo.php?id=1 正常显示。. o5 Q  `$ }. }
http://www.52os.net/phpinfo.php?id=1 and 1=1  返回403。; p9 _2 q) e( v1 g
http://www.52os.net/phpinfo.php?search=<scritp>alert('xss');</script>  返回403。
. ~4 W& A) O6 p: m! L$ a/ F) {* Z说明sql注入和xss已经被过滤了2 P. _) q" X% ~. P% `8 j
4 f) R; Q# s5 M) e3 k
七、安装过程中排错
% g% t+ k5 k) a- d5 `0 ?9 R8 d. k3 R8 s9 i3 i* E% U4 Q
1.缺少APXS会报错/ R/ z, f/ r' ~

( W: k( K! ?1 j" O4 ^6 z: G# A, ^2 gconfigure: looking for Apache module support via DSO through APXS
& ~& ]- C' T8 @1 I+ ?9 S" }0 Nconfigure: error: couldn't find APXS
4 i8 [5 k2 Z/ ^8 ^2 W6 m- Rapxs是一个为Apache HTTP服务器编译和安装扩展模块的工具,用于编译一个或多个源程序或目标代码文件为动态共享对象。. G$ i2 W6 t. r- ?3 ]; a0 x0 ~
解决方法:5 X7 |  F) n4 g, p( O
! h+ Z9 n3 q+ b' ]" }! U9 Y+ b
yum install httpd-devel6 C7 N8 I& y$ H# v
2.没有pcre2 n/ H- B( O! ^* d# }5 i1 x; L' g8 n" }

+ I; Q6 q9 U; }configure: *** pcre library not found.
9 |7 W' Z; @% S4 {6 Fconfigure: error: pcre library is required1 l* O# P5 M0 Z$ r. W  o; n, P- `
解决方法:/ ~8 B2 ]. n; |: @* l' S0 [
8 H& B# E- B% `4 L
yum install pcre pcre-devel
5 ^, x. J7 a# s" n7 x- E3.没有libxml24 U% _6 v' p7 e2 V

3 U* f, T8 v0 u" \& L+ e( l$ b" W' `
configure: *** xml library not found.: R: q0 D8 Y7 z2 g5 [8 O  @
configure: error: libxml2 is required
) T, }, _% k8 g% E6 `% I解决方法:
( y7 o- M) t% }% N* c' e' b
, C# }( V5 w2 C, f$ kyum install  libxml2 libxml2-devel
& K3 ~. z5 I* v4.执行 /opt/tengine/sbin/nginx -m 时有警告
( ~0 s$ b0 u3 \* M  K% X; [6 r1 X" X4 s2 Y
Tengine version: Tengine/2.1.0 (nginx/1.6.2)/ q1 v" N  G7 q/ c8 ]
nginx: [warn] ModSecurity: Loaded APR do not match with compiled!7 U- Z# o+ m& Z2 s; b/ Y  R+ I
原因:modsecurity编译时和加载时的apr版本不一致造成的,并且会有以下error.log9 L- G2 Z% @" s0 u: ^

( z4 O2 _% g: a7 j8 g  u2015/01/26 02:04:18 [notice] 29036#0: ModSecurity for nginx (STABLE)/2.8.0 () configured.
, _: s. D4 [; l- J4 o4 ~2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: APR compiled version="1.5.0"; loaded     version="1.3.9"; ]# E. J: z; d) g  }
2015/01/26 02:04:18 [warn] 29036#0: ModSecurity: Loaded APR do not match with compiled!" K2 T+ Q/ S% _3 T
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: PCRE compiled version="7.8 "; loaded version="7.8 2008-09-05"
6 A3 K, I. x, Q; x: E' U2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: LIBXML compiled version="2.7.6"% }+ Z3 d; t9 B( m$ \2 H- Z
2015/01/26 02:04:18 [notice] 29036#0: Status engine is currently disabled, enable it by set SecStatusEngine to On.
5 |- v: K) y; l, i% B0 x( X解决方法,移除低版本的APR (1.3.9)
/ R3 P# D/ N1 e0 ?; Q+ B
  u1 T! F! n9 P& P2 byum remove apr+ H/ e1 p( M1 m8 u" }$ q
5.Error.log中有: Audit log: Failed to lock global mutex: `% K3 c4 X& D- M
. ?9 F* Z* S: d+ y
2015/01/26 04:15:42 [error] 61610#0: [client 10.11.15.161] ModSecurity: Audit log: Failed to lock     
3 L# e' ^0 ?3 d! Vglobal mutex: Permission denied [hostname ""] [uri "/i.php"] [unique_id "AcAcAcAcAcAcAcA4DcA7AcAc"]* Z% P" W3 G0 j( j% h1 U' A( v. _" C
解决方法:
* k  Q! H* @7 l7 O- G编辑modsecurity.conf,注释掉默认的SecAuditLogType和SecAuditLog,添加以下内容:
( }& w- T) b& C
4 v6 H" C8 w& {" f! F1 n1 RSecAuditLogDirMode 07770 b, t6 s1 L/ f  @7 ]0 ]' N
SecAuditLogFileMode 0550& t6 D# k: D/ }* ?) L
SecAuditLogStorageDir /var/log/modsecurity2 b& O( t$ @9 O0 M8 D
SecAuditLogType Concurrent- N2 m0 E7 x% @) V
参考文章:
4 _9 C- {* U) t( k1 V& n# x+ shttps://github.com/SpiderLabs/ModSecurity/wiki/Reference-Manual#Installation_for_NGINX, g2 ]4 R3 r1 g2 u% W+ k; s
http://drops.wooyun.org/tips/2614
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

QQ|Archiver|手机版|小黑屋|第一站论坛 ( 蜀ICP备06004864号-6 )

GMT+8, 2026-9-30 16:14 , Processed in 0.068119 second(s), 19 queries .

Powered by Discuz! X3.5

© 2001-2026 Discuz! Team.

快速回复 返回顶部 返回列表