找回密码
 立即注册

QQ登录

只需一步,快速开始

查看: 12774|回复: 0

nginx配合modsecurity实现WAF功能

[复制链接]
发表于 2017-10-19 16:53:31 | 显示全部楼层 |阅读模式
modsecurity原本是Apache上的一款开源waf,可以有效的增强web安全性,目前已经支持nginx和IIS,配合nginx的灵活和高效,可以打造成生产级的WAF,是保护和审核web安全的利器。
& M) }8 E; {4 I4 ]3 e- z  t4 |& ], V% E  r6 S2 \
一.准备工作
& z5 A9 g1 V7 f. [; U7 \6 y8 P3 ]  {" x0 m: c9 O( |" e
系统:centos 6.5 64位、 tengine 2.1.0, modsecurity 2.8.0
; [, O4 z* l9 ?# r5 o1 R7 `# I) Y, e; |/ q7 I( i! B, o
tengine : http://tengine.taobao.org/download/tengine-2.1.0.tar.gz
7 R$ i+ M0 }& x5 F+ ?* x
7 e% E& \4 l" L/ m( N1 Wmodsecurity for Nginx: https://www.modsecurity.org/tarball/2.8.0/modsecurity-2.8.0.tar.gz- N  {) f) [' S9 T) w

0 x2 L; l+ ~$ V+ n7 R$ KOWASP规则集: https://github.com/SpiderLabs/owasp-modsecurity-crs5 S3 j0 t3 Y1 p2 [% A9 u
6 `/ z' Q. f1 V; q. {
依赖关系:; p/ d2 x; v* j) l: Q+ i) @7 g
tengine(nginx)依赖: pcre 、zlib、 openssl, 这三个包centos 6.5 系统源里都有:" T5 [5 y0 }! l3 o; c3 v
+ w7 W! n$ n, ^: |9 i/ |4 c2 f
yum install zlib zlib-devel openssl openssl-devel  pcre pcre-devel
2 J4 y; m2 ?, N: f- O6 y, ~5 ~modsecurty依赖的包:pcre httpd-devel libxml2 apr
8 o$ S; l1 s2 o3 G7 R7 i# N, [
' o8 `9 g3 r5 a  s8 \0 F; t, ~( r* Cyum install httpd-devel apr apr-util-devel apr-devel  pcre pcre-devel  libxml2 libxml2-devel
/ H; I1 r! J1 I, |7 b4 P二.启用standalone模块并编译( j. H0 H" f4 O, Z
  R0 s0 c3 l/ @8 x. j9 V- t
下载modsecurity for nginx 解压,进入解压后目录执行:7 R, |3 P' H! J

6 W" d0 q1 T7 g' o" T: g' M9 z./autogen.sh
. W& Q7 p7 T) o7 \% v./configure --enable-standalone-module --disable-mlogc/ N5 ?& m' F/ d% J  o9 N# [
make 6 f3 a7 S. `4 E' _1 J1 D  K
三.nginx添加modsecurity模块
, V' N; |. K& Q9 O3 r6 U4 q* n% C8 u, T* n' o: _+ T
在编译standalone后,nginx编译时可以通过"--add-module"添加modsecurity模块:) Z, g, y" t& `1 K" v

, k, {5 u% Y; L- X./configure --add-module=/root/modsecurity-2.8.0/nginx/modsecurity/  --prefix=/opt/tengine# ~; e8 K5 Y: q2 X# B7 u
make && make install
$ R- ?, n1 a3 N/ o( _5 n4 |4 `四.添加规则
$ t! n$ e" G: a( H
; }- `' e) b2 x( s- Amodsecurity倾向于过滤和阻止web危险,之所以强大就在于规则,OWASP提供的规则是于社区志愿者维护的,被称为核心规则CRS(corerules),规则可靠强大,当然也可以自定义规则来满足各种需求。& s# L! d4 V' b! K0 \% W

1 X! C* X4 j) O" a1.下载OWASP规则:3 s6 z9 p5 P% f1 y2 S0 n
7 F( d" V4 B( A/ H( T2 [' t6 N
git clone https://github.com/SpiderLabs/owasp-modsecurity-crs/ A# J' I( k$ t) E/ j/ k
7 j+ I% ]2 o: j, G5 J, r" }; l
mv owasp-modsecurity-crs /opt/tengine/conf/* h# I% Q; n$ ]8 p5 Y

+ [! u' ]2 ]* g6 H6 P$ j  Y" X% wcd /opt/tengine/conf/owasp-modsecurity-crs && mv modsecurity_crs_10_setup.conf.example modsecurity_crs_10_setup.conf
4 X9 G3 R4 s. O. ~& y% q  h5 k/ S& p2.启用OWASP规则:
) i+ N+ a8 q) d% O! t" @& A& n9 V: y& t. L
复制modsecurity源码目录下的modsecurity.conf-recommended和unicode.mapping到nginx的conf目录下,并将modsecurity.conf-recommended重新命名为modsecurity.conf。) m2 p9 B1 I! ?  t9 p4 ~5 e
# E3 K5 F; v# ^( T+ j& O
编辑modsecurity.conf 文件,将SecRuleEngine设置为 on: X' K1 U4 d0 ?* B0 h# M. t) M

8 U# r  d2 ?+ A& X+ ?  \  Bowasp-modsecurity-crs下有很多存放规则的文件夹,例如base_rules、experimental_rules、optional_rules、slr_rules,里面的规则按需要启用,需要启用的规则使用Include进来即可。
5 H* L& i: v* \- Y/ }9 A
8 p5 e8 M3 s0 Z7 KInclude owasp-modsecurity-crs/modsecurity_crs_10_setup.conf% j+ _" U; K3 F) J+ N
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_sql_injection_attacks.conf
/ S4 d4 X. v7 [" H; q3 x6 I. M& YInclude owasp-modsecurity-crs/base_rules/modsecurity_crs_41_xss_attacks.conf5 U, |& F2 `# _" N$ Y# G4 ~) C
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_40_generic_attacks.conf5 L6 \* A( f  \
Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_dos_protection.conf7 n, a9 C- t. K8 d2 f
Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_brute_force.conf2 U# O) u6 Y' n. ~
Include owasp-modsecurity-crs/optional_rules/modsecurity_crs_16_session_hijacking.conf
: n" w, J& L3 `五.配置nginx
1 o7 U  @4 p7 z5 z# q. H$ `. z' Y
, S9 I" g* v* ?8 X$ C" n在需要启用modsecurity的主机的location下面加入下面两行即可:9 ^6 u; V7 S3 @) Y

4 v! e- k2 h( D& {! k; A$ VModSecurityEnabled on;  
4 X: D. e9 s3 E9 l5 s: u9 |1 AModSecurityConfig modsecurity.conf;
% ~9 Y. B  }7 v. d" d# A+ `- J1 w下面是两个示例配置,php虚拟主机:
5 _; U: R8 [/ `, E% V
$ J5 |2 U! Z& `# H) Eserver {1 w  |1 h. N1 j
      listen      80;
; C& [! x6 h% q2 r7 @2 j5 w      server_name 52os.net www.52os.net;
+ ~4 R* w6 H1 J) W" B4 y, J     
  B7 L# O; u- I9 k8 n* Z. T7 Z      location ~ \.php$ {
! A+ }$ F- w5 f8 O      ModSecurityEnabled on;  # V" b5 h8 H  \1 T+ d& h2 o
      ModSecurityConfig modsecurity.conf;
1 f* s3 \2 d* `3 f3 T2 n. |. [% c9 K$ C0 c/ a4 Z2 D0 m
      root /web/wordpress;
  q0 h- C$ F' U9 S# N1 G8 `/ Z7 a      index index.php index.html index.htm;
- V, i* w6 Z0 `. Z  
6 s5 m5 Q. {* T; ^9 r" O0 k5 Y: x      fastcgi_pass   127.0.0.1:9000;
6 p+ }3 g) M3 [, c      fastcgi_index  index.php;
! Z0 @5 T1 a! ]+ G4 P5 `      fastcgi_param  SCRIPT_FILENAME  $Document_root$fastcgi_script_name;
; U9 @+ h% ?* d# R      include        fastcgi_params;
2 W: J& r2 |5 y' ?: m4 d; A1 \" d# [      }# |" L6 [& ^- R) C3 Z; x' x. N; A  o
  }
+ Z' ]* T8 N5 q7 a" ~3 M( e5 Mupstream负载均衡:9 y; ^. X" O- J1 w9 y' o1 D

, G9 j) Y3 Y; `+ Q4 uupstream 52os.net {+ d7 L( q4 A4 C% T0 O' P
    server 192.168.1.100:8080;
. L& D3 {/ B3 }9 Z    server 192.168.1.101:8080 backup;7 a6 Q6 u/ g) `5 F( B' f
}
) c; H% c% e0 K! Q; `0 W9 n+ x9 e
server {" L  E! X8 i1 [4 }; z: ~2 e
listen 80;5 a* b! X/ |; `  Q! @; R/ C5 q: w' w
server_name 52os.net www.52os.net;7 s1 t6 S, J1 D4 _+ k+ ^

' N; ]3 b  t+ P2 Dlocation / {
8 n5 a% f+ G8 c, w    ModSecurityEnabled on;  
! g- [) A- P7 i& U3 J: N) P5 n' T    ModSecurityConfig modsecurity.conf;  + P2 m$ K& D; @0 h9 Z2 j

) v$ [7 N, S7 F        proxy_pass http://online;9 A1 L# j) [& I2 F/ h6 I
        proxy_redirect         off;
$ k6 j8 \" e, X! @        proxy_set_header Host $host;9 \5 S9 k& h, \1 \' |) W; D1 b7 y
        proxy_set_header X-Real-IP $remote_addr;5 h; c1 x: h0 |( j
        proxy_set_header  X-Forwarded-For $proxy_add_x_forwarded_for;
% q4 j. a" v8 d  p' g    }
  s& R- [! r( j; F+ F}$ Z: x! ?' o- a# U+ n% u
六.测试
: i& |: A$ {2 h( n% K* t' B( M. d; }  `0 G% G
我们启用了xss和sql注入的过滤,不正常的请求会直接返回403。以php环境为例,新建一个phpinfo.php内容为:
4 ?1 F' L+ I3 U) d. |2 C2 Y0 c2 n; Z1 j7 t
<?php6 n7 Q' h5 N3 J$ c6 [6 v* d
    phpinfo();   
3 d# C1 x! Y$ O?>1 L: `% U) B5 T" x
在浏览器中访问:
5 k4 Q% p$ A4 F4 y* K
# [8 G* u& U7 d: x; q% @8 R9 ]http://www.52os.net/phpinfo.php?id=1 正常显示。
7 i9 b3 x  k% Q! r( R' S' Shttp://www.52os.net/phpinfo.php?id=1 and 1=1  返回403。
2 H" R) Z1 B2 S% Bhttp://www.52os.net/phpinfo.php?search=<scritp>alert('xss');</script>  返回403。
- @) G9 |  |- h$ i& a3 A% f说明sql注入和xss已经被过滤了
7 A( @+ T6 C# G
. k4 c( S4 k  w! R2 I& z6 w七、安装过程中排错
: k6 Z+ L: R5 F' v, N/ j3 z$ Y- v' Z1 C! k. g" A" k+ U+ ?
1.缺少APXS会报错& [- N0 \9 |# W- x/ d8 ~$ ~

' G: B2 l0 p2 ?& bconfigure: looking for Apache module support via DSO through APXS  Q$ x! _9 Q5 D" I
configure: error: couldn't find APXS" m. i: q/ Z# ]* I9 ]$ ?8 k- X/ l
apxs是一个为Apache HTTP服务器编译和安装扩展模块的工具,用于编译一个或多个源程序或目标代码文件为动态共享对象。
' h, G5 t" P, Y; F) A解决方法:* W/ N6 z; _4 B4 v9 k$ f! o
3 r5 n5 K) y6 [& b6 \1 h( }& L
yum install httpd-devel" a; F; ]! l: Q( N: t) X
2.没有pcre( F; a1 G- m0 |" r1 U

7 Q% ?) `. E" i% N4 bconfigure: *** pcre library not found./ ]/ t  Y8 D8 E6 A! S/ g8 a* b% V
configure: error: pcre library is required3 p- f6 y6 j3 ^3 K
解决方法:. T% K) \. |4 O' c, J9 X* U0 r  Y6 w/ j

  ]" d! \" y5 m5 _$ x2 }/ dyum install pcre pcre-devel
& ^# M5 R8 h7 A3 o3.没有libxml2
1 }! o# W8 @4 u( S
* G& U- C- `- H  p& n* Q3 N: g: w2 ?$ j2 g. Z- ^  H! u: f4 G
configure: *** xml library not found.$ t$ n$ v- w2 P# x2 U
configure: error: libxml2 is required. H: @2 s  w- z3 k
解决方法:
: q0 {( }  a6 W( y4 s% [! z
  ~+ n% P  Q4 J8 y2 K1 a7 gyum install  libxml2 libxml2-devel3 Q6 K* A/ S& I$ u' F
4.执行 /opt/tengine/sbin/nginx -m 时有警告# N7 N" m  C) t' H9 d
8 p: c6 K- h; k- S: S! m+ ]
Tengine version: Tengine/2.1.0 (nginx/1.6.2)
" r- v9 [- F5 R' J* U+ qnginx: [warn] ModSecurity: Loaded APR do not match with compiled!& t8 M3 @3 M1 s
原因:modsecurity编译时和加载时的apr版本不一致造成的,并且会有以下error.log
2 Q) N# X# i! o* L# k* b- ^9 T
% O6 Z' c& |  a! Q2015/01/26 02:04:18 [notice] 29036#0: ModSecurity for nginx (STABLE)/2.8.0 () configured.
" ]8 o3 W5 a: R* ^* m& W$ z2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: APR compiled version="1.5.0"; loaded     version="1.3.9"
/ X6 x- D& O6 D' A$ a& C+ z2015/01/26 02:04:18 [warn] 29036#0: ModSecurity: Loaded APR do not match with compiled!
' s- P# d$ x$ Q# u5 ~8 `2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: PCRE compiled version="7.8 "; loaded version="7.8 2008-09-05"
% N' A) a/ I( O3 k+ y2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: LIBXML compiled version="2.7.6"$ T! s# b# k7 b; I: P3 @- v# v. t
2015/01/26 02:04:18 [notice] 29036#0: Status engine is currently disabled, enable it by set SecStatusEngine to On.& S5 A4 P% F! I1 C
解决方法,移除低版本的APR (1.3.9)
, R! O+ R: N& |" i0 P/ o6 e
1 Q) [# R; W6 }5 ?$ C" p' }6 Ryum remove apr/ u6 M/ ?: J+ Y* k- e6 \4 m! o( T
5.Error.log中有: Audit log: Failed to lock global mutex. H& P; {: m5 h* _7 i! ?. w

7 @& b( n5 S4 M1 |& [. R2015/01/26 04:15:42 [error] 61610#0: [client 10.11.15.161] ModSecurity: Audit log: Failed to lock     
/ Y) R. Y" a- m/ D# [& w& A% [  Bglobal mutex: Permission denied [hostname ""] [uri "/i.php"] [unique_id "AcAcAcAcAcAcAcA4DcA7AcAc"]4 o# |+ h4 j2 t, B$ b4 }7 [
解决方法:
  ]( ~$ r# L1 ^/ C2 d. X4 G编辑modsecurity.conf,注释掉默认的SecAuditLogType和SecAuditLog,添加以下内容:
- s* J2 [7 R* q0 j* a! C; s2 K/ C4 f) G# _- H& g: n4 U) K5 K/ ]
SecAuditLogDirMode 0777$ `0 C6 o% O6 K; y
SecAuditLogFileMode 05506 \0 d& }! X3 R% m
SecAuditLogStorageDir /var/log/modsecurity
/ Y  X" K$ S1 [; b+ n3 cSecAuditLogType Concurrent/ P% }8 E# U; m' u# @
参考文章:
5 A" k. l: K. ohttps://github.com/SpiderLabs/ModSecurity/wiki/Reference-Manual#Installation_for_NGINX! m6 R1 U) r* o# @* N" O
http://drops.wooyun.org/tips/2614
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

QQ|Archiver|手机版|小黑屋|第一站论坛 ( 蜀ICP备06004864号-6 )

GMT+8, 2026-10-10 14:48 , Processed in 0.069806 second(s), 19 queries .

Powered by Discuz! X3.5

© 2001-2026 Discuz! Team.

快速回复 返回顶部 返回列表