|
|
modsecurity原本是Apache上的一款开源waf,可以有效的增强web安全性,目前已经支持nginx和IIS,配合nginx的灵活和高效,可以打造成生产级的WAF,是保护和审核web安全的利器。
6 [' m# r# ^- d* q# q0 x1 m7 v) ^( ?+ h' J
一.准备工作
3 u1 ?9 y0 {1 {$ `, h- H* f
6 A7 t; e9 X; j' ~系统:centos 6.5 64位、 tengine 2.1.0, modsecurity 2.8.0
) @- r) B L/ A* E! j+ U3 O- M+ c
tengine : http://tengine.taobao.org/download/tengine-2.1.0.tar.gz) n. D+ A3 M9 |0 o
1 g v6 W; C/ U- a; |+ O
modsecurity for Nginx: https://www.modsecurity.org/tarball/2.8.0/modsecurity-2.8.0.tar.gz
$ s: ^4 C6 g9 `* l) W
$ f$ F$ C; V; o, gOWASP规则集: https://github.com/SpiderLabs/owasp-modsecurity-crs
# R( p" B0 o( S/ N6 e5 ~& `$ U9 L g4 k3 @/ n7 [
依赖关系:
$ Y; n- J6 s7 ntengine(nginx)依赖: pcre 、zlib、 openssl, 这三个包centos 6.5 系统源里都有:
9 p+ w& A- Y/ R# Z# `' x, {7 o% Q$ t8 j- ^: _- L# Q }
yum install zlib zlib-devel openssl openssl-devel pcre pcre-devel V" v( I0 b4 `# z' e2 k
modsecurty依赖的包:pcre httpd-devel libxml2 apr, T' b3 |$ B# `/ F) H
8 }/ K6 A' k: p, Y+ M" T% Ayum install httpd-devel apr apr-util-devel apr-devel pcre pcre-devel libxml2 libxml2-devel
2 p3 y3 T* }4 f4 b. ]( y2 i5 E二.启用standalone模块并编译
1 r) S, |+ ]9 `% g/ J
$ W2 D0 j a; c ^8 a1 }下载modsecurity for nginx 解压,进入解压后目录执行:
( W+ K6 U- j4 p9 z e5 Y! E1 k! G% m% o( V
./autogen.sh
. M4 T; R. Q' m* W3 a./configure --enable-standalone-module --disable-mlogc
& N5 n, m) P( j5 a4 P) Jmake $ A$ i1 i: T( F
三.nginx添加modsecurity模块
" [4 c) k+ j+ C w0 r+ V; V/ G4 o* O4 F* l
在编译standalone后,nginx编译时可以通过"--add-module"添加modsecurity模块:$ T3 [1 j( C$ Q' _: b) o) j3 o) A
$ v8 i! g* T7 A5 J7 _; y' ?$ I* L
./configure --add-module=/root/modsecurity-2.8.0/nginx/modsecurity/ --prefix=/opt/tengine) j0 y9 e* O3 ~- w( e4 H
make && make install* P3 n# s. ]! U0 V4 X/ W4 O" ^
四.添加规则9 B1 e7 H3 ]6 m% R! u4 [
0 C) H8 o( @; @4 C, v' Omodsecurity倾向于过滤和阻止web危险,之所以强大就在于规则,OWASP提供的规则是于社区志愿者维护的,被称为核心规则CRS(corerules),规则可靠强大,当然也可以自定义规则来满足各种需求。
& S3 ~, c1 R1 l" A
) [ `+ x! O1 P( u& L5 j1 y1 H/ l7 g1.下载OWASP规则:
8 Y& f8 L# F0 r0 a" [- F7 Z. U6 r o; o
git clone https://github.com/SpiderLabs/owasp-modsecurity-crs; L8 ]: P5 f: J
, p4 O2 f9 G, F7 J6 O
mv owasp-modsecurity-crs /opt/tengine/conf/; w) F1 c, |- w, H
, V# k% K; s" U- o, B* h7 d% Fcd /opt/tengine/conf/owasp-modsecurity-crs && mv modsecurity_crs_10_setup.conf.example modsecurity_crs_10_setup.conf
* w5 Z& z' \6 [- H2.启用OWASP规则:; \4 c. Y Z) X4 t. R9 h4 q& ]( w0 P
! V4 C0 h4 J, A复制modsecurity源码目录下的modsecurity.conf-recommended和unicode.mapping到nginx的conf目录下,并将modsecurity.conf-recommended重新命名为modsecurity.conf。
9 y' Z" I1 |. q( p3 U7 z! S( b
/ }( {* W0 \# \9 d' h* g编辑modsecurity.conf 文件,将SecRuleEngine设置为 on
1 M) h+ s4 l+ j8 {
) [5 D2 T" S* _4 T8 ]owasp-modsecurity-crs下有很多存放规则的文件夹,例如base_rules、experimental_rules、optional_rules、slr_rules,里面的规则按需要启用,需要启用的规则使用Include进来即可。1 V1 p p5 m1 u, |5 I" w# r: ~
( g* j* y6 ]! o$ j% ^* kInclude owasp-modsecurity-crs/modsecurity_crs_10_setup.conf
6 N1 L8 q( b5 z. F3 V0 H; wInclude owasp-modsecurity-crs/base_rules/modsecurity_crs_41_sql_injection_attacks.conf$ Q7 Z* A4 P$ D
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_xss_attacks.conf
+ _% Z7 M7 V/ m& c# s" IInclude owasp-modsecurity-crs/base_rules/modsecurity_crs_40_generic_attacks.conf
3 F$ [, c' n5 }8 zInclude owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_dos_protection.conf
& ^2 ?3 s9 J- `# kInclude owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_brute_force.conf
" Y& t* r" f# A7 mInclude owasp-modsecurity-crs/optional_rules/modsecurity_crs_16_session_hijacking.conf- y' e0 ?, V5 @
五.配置nginx1 i: `2 A4 o% l5 b: Z
5 r7 {# y; W- H: y) b在需要启用modsecurity的主机的location下面加入下面两行即可:5 R7 i2 {% B1 K b; M
) C9 }3 ?& p o j5 w% h
ModSecurityEnabled on; : @) y, o. v; q1 }
ModSecurityConfig modsecurity.conf;
9 ?& K1 l% m" s9 l; b g下面是两个示例配置,php虚拟主机:
% j1 P8 l& @1 T7 L8 M3 w0 J0 W5 m, t4 V
server {
/ \* i8 y- D! F y' M; r listen 80;* [& `* c) G- O& C2 V
server_name 52os.net www.52os.net;
/ v. l5 C! S) d' s' T6 Y * G+ V) r+ X/ u2 b
location ~ \.php$ {
! d7 u2 B/ `/ j, ]2 s, A. j2 Z ModSecurityEnabled on; / ]% e% h- w/ }6 _* u2 x" Y4 |
ModSecurityConfig modsecurity.conf;
% M: V. S" ^8 `; @* N6 @+ Y+ Z& R- c0 d
root /web/wordpress;0 f, S6 J! r* F
index index.php index.html index.htm;
0 l- Y" B7 N1 n: Z! _8 V' F * a' o+ K! `. z& X( {% Y2 F1 P/ X
fastcgi_pass 127.0.0.1:9000;
; L7 c/ J M6 R fastcgi_index index.php;4 t# r; [1 |! e: {
fastcgi_param SCRIPT_FILENAME $Document_root$fastcgi_script_name;
, R. L+ e1 G- p w0 b include fastcgi_params;
5 z0 u( ~7 r6 c }& ~0 B/ k4 B' X; F* L
}" G0 b* }0 l5 @+ M8 T4 ~
upstream负载均衡:
. e9 H0 _ g" F* |3 p
! R; W, h1 o$ }( uupstream 52os.net {) n/ g" T. H( j- p5 p
server 192.168.1.100:8080;8 E0 [' q7 V- j+ e" q
server 192.168.1.101:8080 backup;. p- M' |) I" t* H3 c) ]5 C
}) J8 }) B7 q( F/ U- r( {9 F% m2 g
4 f# N: `9 r4 s+ [
server {
0 h2 R% R# l1 `+ ]8 H! ^* klisten 80;
' W2 B- z- S2 b: ~& u- l4 jserver_name 52os.net www.52os.net;1 @& Y0 X( J x: q
2 ]: c) ]6 S/ a% Glocation / {4 m' _: \/ q5 {" B. F- K
ModSecurityEnabled on; u! |2 ?0 H1 O, G
ModSecurityConfig modsecurity.conf;
$ {! e% @, j* b; [4 [' W8 U4 }! t2 v: X7 f
proxy_pass http://online;
3 w9 h9 Y, c: L1 G proxy_redirect off;. f% K5 v" D3 q- ~) `: U
proxy_set_header Host $host;
0 i& ~( ?7 O3 O f' |+ _2 O1 W proxy_set_header X-Real-IP $remote_addr;# w8 _1 J2 @0 r1 o; k; ~5 v7 ]5 I2 c7 U
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;8 f+ N4 U% _! ]4 i
}
3 @2 c- t; f0 |! X+ e}8 x, V0 B' T, y4 T3 f8 ?
六.测试
& F6 }5 Z0 _, k, l
6 V/ Q: T1 `4 k3 T( x, |) _我们启用了xss和sql注入的过滤,不正常的请求会直接返回403。以php环境为例,新建一个phpinfo.php内容为:
. ^4 F2 w6 h4 [( C1 J- a' B
( f0 i( X! [2 |% U: Z- M' Y<?php# e$ @- ?& P" C1 ^# b
phpinfo();
0 k# E- {7 ~: M: p, W) g' d?>
5 e6 G- u, z' [在浏览器中访问:
' E& j' Y$ z( _& M
6 p; m( ^; p; j* y5 f( yhttp://www.52os.net/phpinfo.php?id=1 正常显示。) w; c* J, t% M4 j) ?" M
http://www.52os.net/phpinfo.php?id=1 and 1=1 返回403。
; `" p/ |2 u& r2 b- B9 @% Lhttp://www.52os.net/phpinfo.php?search=<scritp>alert('xss');</script> 返回403。
" q) R4 p# l, S2 y说明sql注入和xss已经被过滤了
0 v, |8 l. Y3 N1 I3 F/ V+ ]2 X. l) [+ X% a# Z
七、安装过程中排错
1 y, O; \: t* K- |$ V3 K$ R* u, i( d# L/ Q( t0 ~; A: c+ {
1.缺少APXS会报错5 x8 N6 H) `9 P' Z1 H- e) I- h* T4 v
2 P. Y/ u9 e l* N; j) _
configure: looking for Apache module support via DSO through APXS
- c! a# i1 V( `7 z @configure: error: couldn't find APXS2 V0 U/ {# F5 @+ l. k4 I) U
apxs是一个为Apache HTTP服务器编译和安装扩展模块的工具,用于编译一个或多个源程序或目标代码文件为动态共享对象。; g; p! k& v6 U, l1 u- |
解决方法:
: j, Y3 n- h- G) \
$ \2 [ H _4 B: T6 @ hyum install httpd-devel9 n% s- |* j4 [: B1 }
2.没有pcre2 i1 t- \# q' z, Q! D
8 v. j/ k* D- ?configure: *** pcre library not found.2 B. w4 I" q) I+ {
configure: error: pcre library is required! P) v: j l( o/ B, J
解决方法:
/ R2 R) E$ G J! a
" k# ? T4 R- `6 }9 V4 Ayum install pcre pcre-devel( u, k, Z+ F# X+ D/ {
3.没有libxml2. G, l% S/ w0 i6 @! {# X
7 i$ C% l7 h# w& w
3 z0 u- L9 B% K% N$ G! qconfigure: *** xml library not found.
9 u' e( M5 @& Tconfigure: error: libxml2 is required5 {, |# U) e1 `: E2 h6 j* e( p) b
解决方法:
; Y* |" c5 d6 ~8 ^) l# z9 w) S4 @, T; ~; u) M% H4 G
yum install libxml2 libxml2-devel
3 e& F. ?& q/ T/ g- R4.执行 /opt/tengine/sbin/nginx -m 时有警告# u2 E2 x V7 ~9 L
6 Z& `2 l7 K, bTengine version: Tengine/2.1.0 (nginx/1.6.2)
3 g! ?; P# @0 A+ Z; Fnginx: [warn] ModSecurity: Loaded APR do not match with compiled!% Y1 Z: C, U0 O }+ m. c
原因:modsecurity编译时和加载时的apr版本不一致造成的,并且会有以下error.log. U7 T/ D7 b$ _
; y& t% h& B" R- g
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity for nginx (STABLE)/2.8.0 () configured.
# m9 c# m& p. a# e/ Y, g4 Z; [/ ?& G7 S2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: APR compiled version="1.5.0"; loaded version="1.3.9"( k$ ]8 \' p5 x7 F+ v
2015/01/26 02:04:18 [warn] 29036#0: ModSecurity: Loaded APR do not match with compiled!/ J: b$ M. x z. P" ]
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: PCRE compiled version="7.8 "; loaded version="7.8 2008-09-05"; W. N& B: x5 ^# b" B; c
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: LIBXML compiled version="2.7.6"
3 Q2 T6 ], D. E* l$ Q+ T0 `2015/01/26 02:04:18 [notice] 29036#0: Status engine is currently disabled, enable it by set SecStatusEngine to On.
1 V- }1 K, [* P' v% C解决方法,移除低版本的APR (1.3.9)$ i' q& z- Z: X9 K1 v' @- c
* G$ [4 G o2 z7 t' }1 yyum remove apr
5 a* S( G9 G/ Y. _+ L/ N' S6 F5.Error.log中有: Audit log: Failed to lock global mutex/ \! [+ S/ V9 ~- ]% Q/ ^
. R9 i, r" b( N4 e
2015/01/26 04:15:42 [error] 61610#0: [client 10.11.15.161] ModSecurity: Audit log: Failed to lock 2 y- ]# A- E1 }; H" n. c
global mutex: Permission denied [hostname ""] [uri "/i.php"] [unique_id "AcAcAcAcAcAcAcA4DcA7AcAc"]
6 K# N+ E. J! }0 h8 R- b解决方法:% [/ V* i/ K5 Z4 F, }8 m" M" q; [
编辑modsecurity.conf,注释掉默认的SecAuditLogType和SecAuditLog,添加以下内容:
. B5 c& O) C6 T4 x/ h0 X7 L; x; I' x3 W
SecAuditLogDirMode 07775 f) U& t4 Z2 |% E
SecAuditLogFileMode 0550; ~$ T4 C6 V* w' G* U/ P
SecAuditLogStorageDir /var/log/modsecurity8 l: {) Z9 L5 Z! ^' ~
SecAuditLogType Concurrent$ U4 q, i. q2 x8 f
参考文章:9 `! g6 S4 G: b( H/ s( r& m Y
https://github.com/SpiderLabs/ModSecurity/wiki/Reference-Manual#Installation_for_NGINX# `% \6 k4 N5 y# r& A" ^
http://drops.wooyun.org/tips/2614 |
|