找回密码
 立即注册

QQ登录

只需一步,快速开始

查看: 12678|回复: 0

nginx配合modsecurity实现WAF功能

[复制链接]
发表于 2017-10-19 16:53:31 | 显示全部楼层 |阅读模式
modsecurity原本是Apache上的一款开源waf,可以有效的增强web安全性,目前已经支持nginx和IIS,配合nginx的灵活和高效,可以打造成生产级的WAF,是保护和审核web安全的利器。
$ W, e8 E) e% D% y; J' {- [' N. H/ C7 \' l
一.准备工作- v* h+ D' v$ D6 g5 t
) h& ?' Y9 I* o6 m6 {& W. D
系统:centos 6.5 64位、 tengine 2.1.0, modsecurity 2.8.0
9 t& B0 J. q) Z" X2 }& S2 S0 m' f! L  b6 d: ~2 T
tengine : http://tengine.taobao.org/download/tengine-2.1.0.tar.gz
8 M2 t9 V; n  X1 ^0 Q; E( M- t9 ~/ d
. ]& s2 o1 r5 h& J; Nmodsecurity for Nginx: https://www.modsecurity.org/tarball/2.8.0/modsecurity-2.8.0.tar.gz  T7 Q5 @9 H; |, [* `: v, U  g
3 G  C- M( g$ r4 _" j8 ?
OWASP规则集: https://github.com/SpiderLabs/owasp-modsecurity-crs# }# U4 A9 }# c# `* E
& q+ p  z5 S: W2 A; z
依赖关系:9 m7 |6 E/ l5 ]" P3 ~& N# [& ^
tengine(nginx)依赖: pcre 、zlib、 openssl, 这三个包centos 6.5 系统源里都有:+ l* i0 h% k8 t. k# X8 i# }

2 ], r  D  Y& b0 X! `yum install zlib zlib-devel openssl openssl-devel  pcre pcre-devel# [- Z( _* Q- d$ J9 M7 t$ S
modsecurty依赖的包:pcre httpd-devel libxml2 apr1 ]- n$ j2 g1 M$ J) T

! h% L  ^9 b3 g6 H$ V# ]- T" byum install httpd-devel apr apr-util-devel apr-devel  pcre pcre-devel  libxml2 libxml2-devel
7 C) P8 t2 O/ b, @: C% V6 z" E二.启用standalone模块并编译0 r- ~7 @7 g/ Z/ c# d) I

' u3 X  _& Q0 A  l下载modsecurity for nginx 解压,进入解压后目录执行:
4 [3 x$ V% G# n) e
3 k& v) T0 y5 i& {1 G: a./autogen.sh
" W( k8 x& W# A/ m/ F  Q./configure --enable-standalone-module --disable-mlogc
- Q! {( v9 H$ l7 J: G6 ~2 I2 C1 \: emake $ n1 [+ c) p( X$ a! W( G7 s; I
三.nginx添加modsecurity模块
& N. J- P( ~5 v9 Q* X5 E! w0 L
! k: |" s* w. [' x! _在编译standalone后,nginx编译时可以通过"--add-module"添加modsecurity模块:  M' @/ a* F- ?4 ?' M0 O
' Y* k! Z% I" _( ?+ B7 _& u( B
./configure --add-module=/root/modsecurity-2.8.0/nginx/modsecurity/  --prefix=/opt/tengine1 Z; r3 r. p. r4 L+ ?/ Y
make && make install5 m7 ~0 Y. L2 M- ?' p: K
四.添加规则6 Z+ n" i7 g& I0 d8 W( D% B

# X' n) p% N- ^6 Emodsecurity倾向于过滤和阻止web危险,之所以强大就在于规则,OWASP提供的规则是于社区志愿者维护的,被称为核心规则CRS(corerules),规则可靠强大,当然也可以自定义规则来满足各种需求。
9 H" Z/ q4 N* H7 @* W! g
# U% R& K4 L( z9 T" \1 j7 p1.下载OWASP规则:. O% ~( e$ x% a, e9 W. B7 w
" a3 u& d1 M. ]% O
git clone https://github.com/SpiderLabs/owasp-modsecurity-crs
! w- n) N* M" Z( x3 l$ L+ M" u8 x8 R$ o
: m: y+ i. ?' R  Qmv owasp-modsecurity-crs /opt/tengine/conf/
+ J5 U6 i3 B/ Y. Q+ `
$ \* }  c9 [9 x7 icd /opt/tengine/conf/owasp-modsecurity-crs && mv modsecurity_crs_10_setup.conf.example modsecurity_crs_10_setup.conf
6 t! W( Q. ]0 ~5 [; C' K% f2.启用OWASP规则:
6 z$ N8 s" Z8 D9 v( J* Q, j" G' w% a, {" S' l5 L
复制modsecurity源码目录下的modsecurity.conf-recommended和unicode.mapping到nginx的conf目录下,并将modsecurity.conf-recommended重新命名为modsecurity.conf。
' @: ]( H) |2 Q# G! c# M  b; r# h1 ?$ E( C  L4 L
编辑modsecurity.conf 文件,将SecRuleEngine设置为 on3 A6 M1 B; U# x( x! W% ]

! F6 Z4 T+ [) _owasp-modsecurity-crs下有很多存放规则的文件夹,例如base_rules、experimental_rules、optional_rules、slr_rules,里面的规则按需要启用,需要启用的规则使用Include进来即可。
1 S' V/ a! M1 m5 h7 [- B- J
- H  s# E0 ~* z; {' D# jInclude owasp-modsecurity-crs/modsecurity_crs_10_setup.conf
# X, d% K+ I3 sInclude owasp-modsecurity-crs/base_rules/modsecurity_crs_41_sql_injection_attacks.conf( z4 D- }- T% w; A
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_xss_attacks.conf5 b) g4 U. t+ e/ P. k; C( F
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_40_generic_attacks.conf
+ |9 M: Y; d3 Z) d7 {' p" z3 WInclude owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_dos_protection.conf
# x. P# a( ^' l- a3 t. g5 Q" }6 r- eInclude owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_brute_force.conf
7 m" ], X8 I! q5 qInclude owasp-modsecurity-crs/optional_rules/modsecurity_crs_16_session_hijacking.conf
6 d0 c: s- i) J五.配置nginx
, d+ C6 q0 ?1 j$ k* k1 v2 V0 r& g# C# W* s1 {  @
在需要启用modsecurity的主机的location下面加入下面两行即可:
: @- E0 m- \7 v# x1 {
& V7 L/ N: L. `. d( oModSecurityEnabled on;  
2 \- N( v! I1 y, r$ g, g+ KModSecurityConfig modsecurity.conf;
( B$ b* S7 r, d" c  }1 z5 [下面是两个示例配置,php虚拟主机:0 j; l% ?, l- Y( d/ s
! Z3 h" G" Z) _7 ?, S8 G4 p
server {
- w. I3 P7 a  _4 B+ m4 c      listen      80;$ ?( i, h" c5 l8 t# P5 z
      server_name 52os.net www.52os.net;2 J, s0 S& j3 ~2 M( h* \
     
$ E+ E7 {( h5 J$ v6 y# S      location ~ \.php$ {
! V9 D3 l! \0 i; X      ModSecurityEnabled on;  $ @, E1 o; e" t- y8 Y8 z
      ModSecurityConfig modsecurity.conf;! J+ i2 s. u7 Q
, U( o7 h3 o7 I
      root /web/wordpress;- V4 N: W' s4 ]7 \. `" S& }
      index index.php index.html index.htm;
& @! {9 H0 j0 P/ j1 t2 U  l0 D6 \  5 {3 m. q( K$ d' i0 Z
      fastcgi_pass   127.0.0.1:9000;
/ Y6 L+ F" S8 F3 @; y/ Y      fastcgi_index  index.php;) A1 S. v, A  X. c4 D
      fastcgi_param  SCRIPT_FILENAME  $Document_root$fastcgi_script_name;
# y! k. m6 a' B! B3 S# j; G      include        fastcgi_params;6 M9 ]8 `8 \: W( x
      }
6 \: w8 B$ a! N$ ?# V( E4 f  }
$ z# \9 E5 g  G8 z" F5 B/ l. D* y+ {upstream负载均衡:" ~3 O' `; P5 a: p

, x* M+ J# c/ i% B. f/ G8 @0 i8 Uupstream 52os.net {, H0 C% N  q) ?' Z6 j
    server 192.168.1.100:8080;
7 B5 t1 V4 G: p0 ~    server 192.168.1.101:8080 backup;
: n& m; R7 A. a  L/ t}
; {2 c1 U0 b- c9 x/ f. o& X! Z! z
8 E. h& ]1 b+ D9 u8 wserver {
% s' I, u* W, slisten 80;1 @$ c9 y$ `& C9 c$ b* w8 X& Z
server_name 52os.net www.52os.net;
; t: r8 _1 K# K6 U, g- x
0 `! S1 T" V- }. `) K' g" i, Jlocation / {. [- B) k5 h4 T* A
    ModSecurityEnabled on;  0 |5 Q- @6 f! P8 w$ Y& {! F
    ModSecurityConfig modsecurity.conf;  , ^8 u0 k0 S1 {! E

0 @6 ?+ _! |6 M" q. @: H  z% v        proxy_pass http://online;7 v' E; o  J1 v( s
        proxy_redirect         off;# p% R# l7 ~7 y+ i3 R# t
        proxy_set_header Host $host;
" Z5 g) P- v( J& H6 C; u, Q8 Q        proxy_set_header X-Real-IP $remote_addr;, f/ C9 d$ b# @3 n' H
        proxy_set_header  X-Forwarded-For $proxy_add_x_forwarded_for;
9 N; N- s  s9 a0 J    }; Q; [1 A! e* ~, K( ^* a  a+ C
}/ k( S% g3 j9 K% n& o. W  C
六.测试
" l0 q3 r; ~: E
( M) i8 ]6 t4 a: p7 \0 Q我们启用了xss和sql注入的过滤,不正常的请求会直接返回403。以php环境为例,新建一个phpinfo.php内容为:# j% b3 _' u" g, e

  i9 p5 K% l) s) Q* }7 d4 }<?php: G/ G6 l5 k# Z6 w8 M: y  H: A, d0 Q
    phpinfo();    8 d5 ?" U5 C6 g4 g2 s
?>
; W+ `4 o, I: U3 G/ p' Z5 f在浏览器中访问:
1 b5 ^( Z* u+ M1 R7 ^" R. H* R! N5 [
http://www.52os.net/phpinfo.php?id=1 正常显示。1 m( k0 L3 k1 m
http://www.52os.net/phpinfo.php?id=1 and 1=1  返回403。
, `# p% G& Z5 ~3 M4 Mhttp://www.52os.net/phpinfo.php?search=<scritp>alert('xss');</script>  返回403。0 B# ?2 A9 i! x5 j, V
说明sql注入和xss已经被过滤了9 q, l' k  o5 I/ y. q

: R0 Y% A9 s" k- N七、安装过程中排错$ f0 g6 [2 w. Z4 H

( y) b% |" N0 W! Y" \1.缺少APXS会报错. E# H# w9 `# ^2 y3 q( L* O0 D

) w! y/ v4 M$ ~" Pconfigure: looking for Apache module support via DSO through APXS
; z* E/ j: F! h% Wconfigure: error: couldn't find APXS
8 [& M) Y( V) F. bapxs是一个为Apache HTTP服务器编译和安装扩展模块的工具,用于编译一个或多个源程序或目标代码文件为动态共享对象。9 e  f% O' H! w0 {  Z' k
解决方法:% K& D, y- t' X

& @* d& D0 c. Q0 x! Nyum install httpd-devel1 f! U- @+ z* L( Z4 I  o- d
2.没有pcre
& |  p9 Q& p8 O2 b. J: }; |0 c' x- P- X5 `
configure: *** pcre library not found.9 v; u" [! `: M2 r6 X1 c
configure: error: pcre library is required
  _+ j5 B" C# P* }7 v% w. Y. h解决方法:
. E' X! y0 N) c8 U4 H# h5 v
2 Q: v; G: U% dyum install pcre pcre-devel0 G6 D/ a% |- w+ v2 r
3.没有libxml20 B) r3 R( B' |9 b' l! e- e9 M

# q: f/ L) k  X. `6 {& C2 [8 [% N5 Z2 N
configure: *** xml library not found.) e  z% g$ k0 D
configure: error: libxml2 is required
# `6 T: K4 S% k2 W1 {$ t解决方法:
% e, i2 t& j: R. n8 y0 N' L# Y' p, V  a- S% |$ P9 Q
yum install  libxml2 libxml2-devel, D  f4 ?/ l* ^+ l! e* ]) ]
4.执行 /opt/tengine/sbin/nginx -m 时有警告
: y2 Z3 ^+ K( L8 }
) M5 }8 J+ W& Y9 l9 u9 A8 JTengine version: Tengine/2.1.0 (nginx/1.6.2)+ \  M" C9 p+ i5 D
nginx: [warn] ModSecurity: Loaded APR do not match with compiled!. ^* `& ?# C7 v; Z( ^0 U$ G
原因:modsecurity编译时和加载时的apr版本不一致造成的,并且会有以下error.log" ]% f( K4 R  @0 U/ R
" k& u8 B* C# {4 K# O" {7 S
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity for nginx (STABLE)/2.8.0 () configured.
( ~0 l( @; j! p% r# ^1 g. B% _1 `2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: APR compiled version="1.5.0"; loaded     version="1.3.9"' r  A' e; y- e. M8 P
2015/01/26 02:04:18 [warn] 29036#0: ModSecurity: Loaded APR do not match with compiled!
' G6 J) T. ^! R: ]2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: PCRE compiled version="7.8 "; loaded version="7.8 2008-09-05"+ ^( Z7 ?( a% `. {; X
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: LIBXML compiled version="2.7.6"7 o. ~, A1 H6 L  L& `# O
2015/01/26 02:04:18 [notice] 29036#0: Status engine is currently disabled, enable it by set SecStatusEngine to On.
* J8 S  e' x* O& F解决方法,移除低版本的APR (1.3.9)+ V3 n: h7 }* v; C: z& A$ m. M$ I
: Z" ]* q7 t. Y$ [6 K6 e" x- B  h
yum remove apr
; Q" _1 M2 q" R$ V! {5.Error.log中有: Audit log: Failed to lock global mutex1 \( q" @" p: [  L- v
3 ]: B# l  o" [7 Y
2015/01/26 04:15:42 [error] 61610#0: [client 10.11.15.161] ModSecurity: Audit log: Failed to lock     
8 u: I& z  s( ~, f0 `global mutex: Permission denied [hostname ""] [uri "/i.php"] [unique_id "AcAcAcAcAcAcAcA4DcA7AcAc"]
0 l# i2 f# {/ v2 D解决方法:/ E; d% C2 j- U+ q, t
编辑modsecurity.conf,注释掉默认的SecAuditLogType和SecAuditLog,添加以下内容:0 N% {# p2 l$ d: N, B9 W8 g

. D- M( v4 Q- Q) g  ^: ^SecAuditLogDirMode 0777* q- _) c9 U$ {$ u+ f
SecAuditLogFileMode 0550
" M) g8 [) ]( J$ OSecAuditLogStorageDir /var/log/modsecurity6 u# g- J1 n& L: z
SecAuditLogType Concurrent+ G1 `3 L9 `3 W, Y' S7 H
参考文章:8 {! R. Z5 _2 o# p5 V: u6 f4 X
https://github.com/SpiderLabs/ModSecurity/wiki/Reference-Manual#Installation_for_NGINX6 v* Y$ m2 [# w$ w6 [4 U' n5 [+ _
http://drops.wooyun.org/tips/2614
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

QQ|Archiver|手机版|小黑屋|第一站论坛 ( 蜀ICP备06004864号-6 )

GMT+8, 2026-9-29 06:26 , Processed in 0.056891 second(s), 19 queries .

Powered by Discuz! X3.5

© 2001-2026 Discuz! Team.

快速回复 返回顶部 返回列表