找回密码
 立即注册

QQ登录

只需一步,快速开始

查看: 12761|回复: 0

nginx配合modsecurity实现WAF功能

[复制链接]
发表于 2017-10-19 16:53:31 | 显示全部楼层 |阅读模式
modsecurity原本是Apache上的一款开源waf,可以有效的增强web安全性,目前已经支持nginx和IIS,配合nginx的灵活和高效,可以打造成生产级的WAF,是保护和审核web安全的利器。6 g/ l0 i9 f; x, `* J1 ?

6 j; E# D; q8 r) S; a* C一.准备工作8 t3 I$ S. _/ j

7 Q. t/ l3 N2 ^7 ?, e系统:centos 6.5 64位、 tengine 2.1.0, modsecurity 2.8.05 q2 P) H+ M% E5 v2 R5 M

/ M& \3 M, P- j, R  Gtengine : http://tengine.taobao.org/download/tengine-2.1.0.tar.gz+ H" }" p+ _0 ~6 s. z$ ^/ H7 ~6 X
$ x( F* J6 j  |* G' C
modsecurity for Nginx: https://www.modsecurity.org/tarball/2.8.0/modsecurity-2.8.0.tar.gz
! X/ g$ c! p- ~" v1 W" |, ?6 U/ ?& a6 h0 @4 o4 b% d3 ^
OWASP规则集: https://github.com/SpiderLabs/owasp-modsecurity-crs9 U3 {( k$ Q  \0 T7 j+ {; k( j  F5 H2 ?
' d4 G7 ^3 x0 v+ G' `
依赖关系:
0 p7 P5 r1 |$ y; M' dtengine(nginx)依赖: pcre 、zlib、 openssl, 这三个包centos 6.5 系统源里都有:: m, f& [+ O0 m' j
$ Q8 G8 f" E* A7 [
yum install zlib zlib-devel openssl openssl-devel  pcre pcre-devel
# g: Y( i, ~# _$ n  c! Rmodsecurty依赖的包:pcre httpd-devel libxml2 apr
- t! U5 J4 D- S  Z
3 m  g0 R$ T0 a: `4 Y. X9 d- d, Eyum install httpd-devel apr apr-util-devel apr-devel  pcre pcre-devel  libxml2 libxml2-devel4 {/ x* {3 v6 z0 y! M6 p
二.启用standalone模块并编译
6 Y  a/ t$ k, R7 _1 {/ R) `! |% h: H# f! L
下载modsecurity for nginx 解压,进入解压后目录执行:/ K1 ]7 X3 W1 r. @) |! M+ J

2 q+ m* ?4 ]' X) q' n/ v5 S./autogen.sh
( G9 W, e! a! H2 Z1 p./configure --enable-standalone-module --disable-mlogc& C  r) x* z& t- t* x6 ]; u
make # U  w/ A) K: G: X  ?" U) ~: v
三.nginx添加modsecurity模块
6 y6 K2 r+ g# k  \. `
5 I( f/ j. j7 h* d4 c% I/ l9 A9 R在编译standalone后,nginx编译时可以通过"--add-module"添加modsecurity模块:; S! I1 h4 Y# c" \

5 `$ L' R! R' [0 Y' ]1 b- S7 F./configure --add-module=/root/modsecurity-2.8.0/nginx/modsecurity/  --prefix=/opt/tengine4 D+ n& s/ @1 t$ ~! m
make && make install# f5 B! B, w; S& ]; u
四.添加规则
7 f" s3 A! s4 V' \( [8 p
5 G, n* ~! f7 c$ ~! m. c1 I1 K+ Cmodsecurity倾向于过滤和阻止web危险,之所以强大就在于规则,OWASP提供的规则是于社区志愿者维护的,被称为核心规则CRS(corerules),规则可靠强大,当然也可以自定义规则来满足各种需求。* x2 x( V3 G% B+ W

! x1 ]* _5 x. F% }1.下载OWASP规则:
) x; ~' I! I5 U  [( x! ?8 ^
. q# U' d% I3 A8 N3 ?: ]git clone https://github.com/SpiderLabs/owasp-modsecurity-crs
. ^5 Z' n, {" `! b6 C6 _8 p7 Y, e
1 d/ z9 b* ?3 Wmv owasp-modsecurity-crs /opt/tengine/conf/
" L) s$ Y/ u: o8 T& C( i2 G/ {# ^5 P  d* ~
7 p; A2 [! Z+ ]- ~$ ]cd /opt/tengine/conf/owasp-modsecurity-crs && mv modsecurity_crs_10_setup.conf.example modsecurity_crs_10_setup.conf& O) b! V7 p2 l0 a9 |& k; u
2.启用OWASP规则:
6 t5 U1 K1 X& O6 B  ^7 Y
% A& o, F& y1 z8 N! M: l, i9 `复制modsecurity源码目录下的modsecurity.conf-recommended和unicode.mapping到nginx的conf目录下,并将modsecurity.conf-recommended重新命名为modsecurity.conf。
( u) U+ D2 E: D  ?9 A8 r/ @6 \% i
- @/ ~' a4 Q: i8 W2 m编辑modsecurity.conf 文件,将SecRuleEngine设置为 on9 l4 Z4 n( A0 n" }$ d
0 b( q- G! S) @) h# K" y
owasp-modsecurity-crs下有很多存放规则的文件夹,例如base_rules、experimental_rules、optional_rules、slr_rules,里面的规则按需要启用,需要启用的规则使用Include进来即可。
: A  g8 T# e: g" |7 L% e% I) W# r
Include owasp-modsecurity-crs/modsecurity_crs_10_setup.conf
: D7 Q6 I, U" X. `, T1 C; UInclude owasp-modsecurity-crs/base_rules/modsecurity_crs_41_sql_injection_attacks.conf
8 o* L, _$ A2 X2 x" p' OInclude owasp-modsecurity-crs/base_rules/modsecurity_crs_41_xss_attacks.conf
" U: n( A: ~5 _- V! ]: {5 r6 Q  EInclude owasp-modsecurity-crs/base_rules/modsecurity_crs_40_generic_attacks.conf
( e: S4 R9 s  o" U% P2 P9 YInclude owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_dos_protection.conf
+ M% C/ h* X$ M/ {1 `$ R' ?3 s  g" DInclude owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_brute_force.conf
) M& c0 A8 y' @2 eInclude owasp-modsecurity-crs/optional_rules/modsecurity_crs_16_session_hijacking.conf, e! l; y; K4 H' S
五.配置nginx4 Y! z+ _) \& x) E& Y& ~* W
  h. Z7 T2 F! }4 `% g* j9 m8 ^
在需要启用modsecurity的主机的location下面加入下面两行即可:
5 |' L  v+ ]% u! p, S, o2 v
2 [$ P! e2 ^2 W; n4 N8 L' wModSecurityEnabled on;  & \! k: U9 K4 R, ^1 S( \
ModSecurityConfig modsecurity.conf;
7 f7 C; |! `1 [. ?下面是两个示例配置,php虚拟主机:; ?5 w% \4 J1 r3 n2 [: c& g  l, I

- E" T' Q) k: J9 @, Userver {
& I: n* `2 _# g( s9 \) a      listen      80;$ G1 g) a2 `3 ]3 v3 ]1 w# b
      server_name 52os.net www.52os.net;
2 Q' s( c4 {: M. s5 w6 y9 d     
* `" D& j- t' y6 u1 }7 t5 I* X      location ~ \.php$ {, S# S+ R- N4 k% |9 [4 N' V. g9 \
      ModSecurityEnabled on;  
3 c/ L( C% O/ }      ModSecurityConfig modsecurity.conf;& w6 s/ u( V, ?- a. p# P3 `

$ P- z- c  G7 n. ^# c% k. {      root /web/wordpress;
- @9 y+ [# C1 J      index index.php index.html index.htm;3 [! s6 X: {: v3 x) q4 Q
  ) a, f" ?: h; c/ w/ a
      fastcgi_pass   127.0.0.1:9000;" `1 u+ U5 I6 Q# b# W
      fastcgi_index  index.php;
" b  P. |9 C$ \, m5 C5 }: F/ v$ ]      fastcgi_param  SCRIPT_FILENAME  $Document_root$fastcgi_script_name;  ~) L' @2 j/ s: \% j  @
      include        fastcgi_params;
. W/ H4 f0 C- l, W9 ^: s      }
6 \! w" w. n. m) F3 G* t  }: L( v, k2 h7 |5 g% o
upstream负载均衡:  P8 x4 ~9 T3 N) V! u; d' Q

0 S& ?$ O' \( Z1 V* A* Xupstream 52os.net {
" a. o% Q( N6 M; B. `    server 192.168.1.100:8080;
" u- U. ?- Y# T- D8 v8 w    server 192.168.1.101:8080 backup;
) X( ~) y; _% T  A. y, S& K9 t}
. J+ a2 i+ m* `* r5 Z6 |9 f, y$ O, a  L0 a
server {
3 [! \/ p3 I; q& y+ u6 Qlisten 80;
  O; x( ~( |# z  gserver_name 52os.net www.52os.net;$ o7 Y4 O8 E5 A( ~) o6 z9 }& z

$ v7 l' F+ m3 Y0 f+ rlocation / {' q5 f8 N1 a5 c' N* L' |1 P$ ^
    ModSecurityEnabled on;  
! D/ ^, A; g+ z# g0 V* A  C1 x    ModSecurityConfig modsecurity.conf;  
: ?0 D+ v& h; w9 [) j" b$ ^
3 n. A# r1 ?7 i& M1 |7 {  c        proxy_pass http://online;: V( x. K( C3 M/ o' t* V% s
        proxy_redirect         off;# i' o3 E1 ^$ [% p2 T. r. u
        proxy_set_header Host $host;
1 n1 c2 d, I  ~% ]8 ?. E( |1 Y  B; G        proxy_set_header X-Real-IP $remote_addr;
& e4 Q/ i2 R* h, a  K# d        proxy_set_header  X-Forwarded-For $proxy_add_x_forwarded_for;
; |  ?, \# [3 l' h5 x    }/ b9 j; b) U" }2 o2 ]
}% x4 l+ z: Z8 Z) t+ X. v8 G
六.测试
7 k8 R' b+ n+ g
# R. t  h% y, f5 R& o) k( `3 f我们启用了xss和sql注入的过滤,不正常的请求会直接返回403。以php环境为例,新建一个phpinfo.php内容为:- P& S) ?1 G& r3 Z
6 s1 C* [, i- u, F5 u' G& V) a* a
<?php) d4 ~0 K" E: k  k1 @& s
    phpinfo();    # ?& @) g0 h. e5 O4 W
?>
, a4 Y7 a  {5 A, F1 k4 g. D( M( c& ?在浏览器中访问:
/ G8 M) k+ p3 S% o/ N. Y4 v' J0 g9 f9 O& b
http://www.52os.net/phpinfo.php?id=1 正常显示。: H2 Z1 d7 A/ A9 a& a* J: D
http://www.52os.net/phpinfo.php?id=1 and 1=1  返回403。
, |. W  |0 y0 n. Nhttp://www.52os.net/phpinfo.php?search=<scritp>alert('xss');</script>  返回403。
4 O; [+ E3 k8 o2 H7 w/ \0 K5 |说明sql注入和xss已经被过滤了3 C% }& T+ [  ]/ D9 S

  e: g* r% O& z七、安装过程中排错: A) P' R0 b4 u- n7 h

6 Q" C& m  ?+ Y: f6 M% `5 h. N1.缺少APXS会报错% g, ^7 s3 B/ \$ S  n& ]
& G+ e6 K6 l' J# i. Q7 j9 M% v$ u/ ^
configure: looking for Apache module support via DSO through APXS
1 I7 B: [0 P5 K: n) pconfigure: error: couldn't find APXS
' y& L9 {# @, [% m! P4 t4 ^% F; ]apxs是一个为Apache HTTP服务器编译和安装扩展模块的工具,用于编译一个或多个源程序或目标代码文件为动态共享对象。
5 f/ T4 s! z7 @! N% G5 v解决方法:! k: B  W( s/ A
& D8 w2 H2 \' }, ~, Q, c5 p* M
yum install httpd-devel
3 R% F- C) W6 t  ^* ^' q2.没有pcre, w* r1 e0 C. h5 u8 h
, s9 ]0 ^1 r- C$ w- m- S- f3 ~1 \
configure: *** pcre library not found.
) i6 V  g) p) B4 \$ z; ~configure: error: pcre library is required( B4 P7 v. f* }! h/ ~; N
解决方法:
; c- l) f( G, T$ D3 [3 y6 i
7 C( m1 F0 [# p8 |: W+ Hyum install pcre pcre-devel4 R0 V: z- t* _% k& M5 R
3.没有libxml2& \/ \$ Y( T0 W: T+ v

; }. M" D2 P+ z; W- P3 @
5 o/ p  D% Z, M4 O9 gconfigure: *** xml library not found.1 g6 N* B- y* W5 W4 B9 H7 l
configure: error: libxml2 is required. A1 g* Q- h: C$ y; ?4 }9 m$ Y. q
解决方法:
. }) l6 {/ @  |8 W- a( B' L  \% o; M$ r" n1 z- f
yum install  libxml2 libxml2-devel6 z2 i+ v* E0 C9 M- o  D0 Q
4.执行 /opt/tengine/sbin/nginx -m 时有警告
0 c1 w5 r& N% x3 K' p
! [* l2 A' Y! f* R1 W" |Tengine version: Tengine/2.1.0 (nginx/1.6.2): ]; ~- t$ y% {
nginx: [warn] ModSecurity: Loaded APR do not match with compiled!
) O/ C3 n7 F0 B5 X6 \( ~4 Y原因:modsecurity编译时和加载时的apr版本不一致造成的,并且会有以下error.log
3 M1 i5 G, U% b% A) J% o/ w/ W  T2 y) ^# G* w  G6 y$ M
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity for nginx (STABLE)/2.8.0 () configured.' O& f5 {7 [3 D  l
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: APR compiled version="1.5.0"; loaded     version="1.3.9"
6 I  H7 Z1 x, i" d- u2015/01/26 02:04:18 [warn] 29036#0: ModSecurity: Loaded APR do not match with compiled!
) M$ b& {; s& d9 V( H, B9 V9 d3 W2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: PCRE compiled version="7.8 "; loaded version="7.8 2008-09-05"
* h3 d; E, M9 F# @/ n2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: LIBXML compiled version="2.7.6"
' O$ f7 d& W* {) W$ G' a8 ?2015/01/26 02:04:18 [notice] 29036#0: Status engine is currently disabled, enable it by set SecStatusEngine to On.
! M3 e! j: s& B6 F; o5 v9 }: h+ D7 z解决方法,移除低版本的APR (1.3.9)0 X0 o0 x6 X: R
$ \- Q  `) \( C7 R% V# R" O# T
yum remove apr/ ~- [( X& i( V6 ^' O2 c, Y% }% j
5.Error.log中有: Audit log: Failed to lock global mutex1 Y1 \. I$ W8 H; T0 E& B$ C9 l
/ w' n8 h1 Z  ^. ~1 }
2015/01/26 04:15:42 [error] 61610#0: [client 10.11.15.161] ModSecurity: Audit log: Failed to lock     / L. ~$ l' e3 _; d. |
global mutex: Permission denied [hostname ""] [uri "/i.php"] [unique_id "AcAcAcAcAcAcAcA4DcA7AcAc"]' v0 P, v4 d$ j/ s/ m
解决方法:
7 w1 K' P8 S6 L3 ~编辑modsecurity.conf,注释掉默认的SecAuditLogType和SecAuditLog,添加以下内容:0 P, l1 x9 P& Z
; H& o1 q9 h0 o8 R$ G
SecAuditLogDirMode 0777$ C( R# t" l& K4 [* G
SecAuditLogFileMode 0550* n1 H# M3 P4 _$ {
SecAuditLogStorageDir /var/log/modsecurity
5 L; l$ ^9 A0 T  TSecAuditLogType Concurrent
% z/ C3 d5 v* `* W% N7 ~* j参考文章:
5 x. C0 Q% l! U2 v6 h- r$ {https://github.com/SpiderLabs/ModSecurity/wiki/Reference-Manual#Installation_for_NGINX
7 J0 y. l& h- J: \& x$ Mhttp://drops.wooyun.org/tips/2614
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

QQ|Archiver|手机版|小黑屋|第一站论坛 ( 蜀ICP备06004864号-6 )

GMT+8, 2026-10-8 17:11 , Processed in 0.058774 second(s), 19 queries .

Powered by Discuz! X3.5

© 2001-2026 Discuz! Team.

快速回复 返回顶部 返回列表