|
|
modsecurity原本是Apache上的一款开源waf,可以有效的增强web安全性,目前已经支持nginx和IIS,配合nginx的灵活和高效,可以打造成生产级的WAF,是保护和审核web安全的利器。
4 e) M, b9 b0 Y: \ Z) V4 R5 q# i, ^
一.准备工作
n5 u6 j) J& V. \3 \2 @' e! q/ ?+ i0 \
系统:centos 6.5 64位、 tengine 2.1.0, modsecurity 2.8.0; B* m2 I2 ]9 T/ g( a. b! v
6 h: q' Y' D) I( K9 f2 G
tengine : http://tengine.taobao.org/download/tengine-2.1.0.tar.gz0 i2 y0 s2 }4 |: y2 @& q- f
/ J s) s/ M: D7 hmodsecurity for Nginx: https://www.modsecurity.org/tarball/2.8.0/modsecurity-2.8.0.tar.gz' G7 _9 g4 E5 f# ^6 a4 H5 f9 o- R, r
S' ~3 B0 M3 {( R9 |- x
OWASP规则集: https://github.com/SpiderLabs/owasp-modsecurity-crs4 ^9 G2 \9 X7 r) u. A( D/ X% g
6 r1 {0 i% A; C
依赖关系:
8 o$ g/ ~3 b2 o1 Q8 ^tengine(nginx)依赖: pcre 、zlib、 openssl, 这三个包centos 6.5 系统源里都有:
/ a: \* b# ?* B7 z: o7 m: j# D/ | ^/ X
yum install zlib zlib-devel openssl openssl-devel pcre pcre-devel
9 h, y# H7 N2 i( O( y$ i0 Fmodsecurty依赖的包:pcre httpd-devel libxml2 apr
! L0 m m O+ Y% h$ x
, [' F: I2 H8 O) L6 o6 g" \yum install httpd-devel apr apr-util-devel apr-devel pcre pcre-devel libxml2 libxml2-devel3 r/ D% ~3 x$ L1 A0 G
二.启用standalone模块并编译
N' D/ b1 k" x! J2 f, f% B4 o' e. ]8 g& |3 y0 ?
下载modsecurity for nginx 解压,进入解压后目录执行:" J8 h' O. _ t* s/ s) y C
/ ~! H- q8 Q- |) @# _./autogen.sh& u' I8 h* Y3 O( S
./configure --enable-standalone-module --disable-mlogc9 S# w4 T5 ] J; I% o: L: W2 Q5 N2 Q7 j
make $ G2 Q3 ], A& s1 s8 C
三.nginx添加modsecurity模块7 h5 m2 ]2 F* X0 E
# f. n" H2 i0 O6 R8 ]: H
在编译standalone后,nginx编译时可以通过"--add-module"添加modsecurity模块:- }6 ?3 I" S" _3 W: S
2 ]( j+ S& a$ l& m `
./configure --add-module=/root/modsecurity-2.8.0/nginx/modsecurity/ --prefix=/opt/tengine
4 S0 F: `2 g- Q# N' }0 N) z& A0 Xmake && make install
/ k1 k# a0 b% U8 y* g! h1 r: Q" X四.添加规则6 P7 E* ~8 u) H9 q _3 l9 E( {9 U
0 m( j& E, M6 p, ?modsecurity倾向于过滤和阻止web危险,之所以强大就在于规则,OWASP提供的规则是于社区志愿者维护的,被称为核心规则CRS(corerules),规则可靠强大,当然也可以自定义规则来满足各种需求。( a+ b8 n( d* a4 ~! I1 c/ f
) }6 I m+ O2 n" \% a0 w( o- j1.下载OWASP规则:/ Z' D. q' z+ w+ S6 h$ ]
. ~ R0 @4 K3 R8 l# ]* w
git clone https://github.com/SpiderLabs/owasp-modsecurity-crs5 w G5 B# F( O# r+ B4 L
% L, T1 U* p& m# _' ~
mv owasp-modsecurity-crs /opt/tengine/conf/8 o! L/ L, \" ^7 ^
! m* M5 d; U: O' [
cd /opt/tengine/conf/owasp-modsecurity-crs && mv modsecurity_crs_10_setup.conf.example modsecurity_crs_10_setup.conf
, p3 x- u$ R8 k5 R2.启用OWASP规则:
. g4 [% }1 C: h8 n, [! a& c; w
$ i: ^( k9 l5 T7 U7 A复制modsecurity源码目录下的modsecurity.conf-recommended和unicode.mapping到nginx的conf目录下,并将modsecurity.conf-recommended重新命名为modsecurity.conf。1 M* K) [- Y; Z8 V; q9 R- }- r
, ?: K( C+ w& p编辑modsecurity.conf 文件,将SecRuleEngine设置为 on8 F) \ x- [% ]- t+ `
) k0 g0 ^; D3 w: t. wowasp-modsecurity-crs下有很多存放规则的文件夹,例如base_rules、experimental_rules、optional_rules、slr_rules,里面的规则按需要启用,需要启用的规则使用Include进来即可。
+ ]5 U$ U2 W8 ~, [0 z- _* u4 c4 d& e7 p' ^8 _9 l" p# v$ C: H0 V. h4 K
Include owasp-modsecurity-crs/modsecurity_crs_10_setup.conf
x+ c, m5 O$ M! Y& p' i) ~Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_sql_injection_attacks.conf
' t y& J L. z0 PInclude owasp-modsecurity-crs/base_rules/modsecurity_crs_41_xss_attacks.conf
3 t% o- @1 s: RInclude owasp-modsecurity-crs/base_rules/modsecurity_crs_40_generic_attacks.conf
* J) [" v4 q. OInclude owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_dos_protection.conf
, ~. t; A5 X! Q9 T% h0 j3 \Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_brute_force.conf
" X, A& B1 O/ }' PInclude owasp-modsecurity-crs/optional_rules/modsecurity_crs_16_session_hijacking.conf
, y, T+ C, ]: M) O9 a5 [/ U五.配置nginx
. U( S" { C0 H
. I2 l9 G# g9 c7 M( ^在需要启用modsecurity的主机的location下面加入下面两行即可:
+ q. o" Q6 E$ `( P( m7 E6 Y! }6 Z2 P8 F- }- ^& Q% z
ModSecurityEnabled on;
1 e o9 i0 [9 I9 N# FModSecurityConfig modsecurity.conf;
+ ]. I4 K% u# T% `下面是两个示例配置,php虚拟主机:
* i" {8 b( e; _7 g4 X2 y2 m7 y2 H5 I
server {
, G4 \2 e" y. [: W4 _2 g listen 80;
+ O( k+ s8 d, Y/ E' P- ?+ x server_name 52os.net www.52os.net;
; i/ \0 o, \ H, Q s6 o g' z
% o) ]/ W' W3 U; m location ~ \.php$ {* T1 H+ F5 m# O+ C; a4 S( k! ?
ModSecurityEnabled on;
7 l U3 n! g0 n" N4 P ModSecurityConfig modsecurity.conf;
# F3 ] w. @! _& k" j
9 ?$ I0 i% r( f4 ?, b P root /web/wordpress;
$ u- k# A: M/ |4 `7 @* A index index.php index.html index.htm;
) O/ y. r1 {9 l" Z2 O" X Z# o
8 @" ~& S3 j# ~) i$ U fastcgi_pass 127.0.0.1:9000;
& u( H) n- N; e+ M fastcgi_index index.php;9 v5 O4 K6 d" n5 w6 u1 \
fastcgi_param SCRIPT_FILENAME $Document_root$fastcgi_script_name;' m! S: }7 d5 B% s' l; C z; u2 Y
include fastcgi_params;
. ?. ~, D0 X7 S& O4 T& J9 f }9 p: k! I- t' j- r/ e+ J
}
4 q/ q. U7 m2 H: N+ Fupstream负载均衡:" O/ ]1 s* \; c0 g" K
; Q2 u/ Q5 X# y* X8 Y4 f! l4 _/ z
upstream 52os.net {
L8 J6 _. e6 r% T- \# I server 192.168.1.100:8080;5 {8 F$ F2 q, k
server 192.168.1.101:8080 backup;
7 [5 H$ B! }7 Y H& _3 U+ t8 `) S}
4 F3 r% i& T5 |! ^3 y' f/ h7 E" g8 G$ K
server {/ k7 V, A9 Z! P& l0 Y) K* J
listen 80;
5 F! A/ U: S# S4 o- D3 Tserver_name 52os.net www.52os.net;
) s3 W5 F( `1 C
4 z7 F+ _8 R# xlocation / {
4 ~3 P: s) D. j5 p T ModSecurityEnabled on;
! P! B9 E" g4 Z3 b" R ModSecurityConfig modsecurity.conf;
+ f4 C H M$ L, C
+ I5 M" l7 L0 l7 \! I! E proxy_pass http://online;
2 e' E; i, A( N! ] proxy_redirect off;* a9 }, K9 j. ^
proxy_set_header Host $host;
3 x( {1 q/ N7 H proxy_set_header X-Real-IP $remote_addr;- J) D3 V1 ]! H1 D3 q: C" S, B
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;; C3 \, s- Z) v/ {1 J1 p0 }' i5 Z
}
7 K. }+ m" S* L( W}- Y7 Q6 S, `2 G. a" l
六.测试. y2 A: z3 r% |4 I
6 }, Q% I4 L+ X1 z. A& H
我们启用了xss和sql注入的过滤,不正常的请求会直接返回403。以php环境为例,新建一个phpinfo.php内容为:: S0 P* y. I" k* C
+ ^ ?3 S$ l; L" ~7 ?' n) Z9 k. m
<?php% _. g. d8 `5 m- M- S. N7 e
phpinfo(); # n2 o8 C! ^: d: W1 P
?>
6 d9 {( C4 N% }- n' s在浏览器中访问:; i8 y7 ~& g# e" n
/ s# c3 ~2 c) d. M& \+ Bhttp://www.52os.net/phpinfo.php?id=1 正常显示。3 C6 d) ^8 T' ]0 h/ M
http://www.52os.net/phpinfo.php?id=1 and 1=1 返回403。: Y4 d" l% z/ ^8 X# ^2 G' _
http://www.52os.net/phpinfo.php?search=<scritp>alert('xss');</script> 返回403。
; ?9 q* q- Q2 ~5 F! X说明sql注入和xss已经被过滤了# f) R/ G3 {8 B/ r
z+ \+ I6 ]" C y. k5 \% K七、安装过程中排错, y8 }, @! G# T% V
( E# I3 k+ k& q0 V! a1 C1.缺少APXS会报错
! M9 z. A; }# D5 p7 `
F$ P5 M+ ~# l# n* s- A4 y Sconfigure: looking for Apache module support via DSO through APXS
: [" a- q: m+ D/ R4 z: d: F6 K0 f/ Wconfigure: error: couldn't find APXS B; j1 ]/ V+ a2 u, ?' {# H
apxs是一个为Apache HTTP服务器编译和安装扩展模块的工具,用于编译一个或多个源程序或目标代码文件为动态共享对象。' R$ Q; o* A2 C/ g# d; |
解决方法:
: C, [( `- U B( }
0 U2 G, I/ W- l fyum install httpd-devel
" }# }; B0 `( F& K, d2.没有pcre
3 R' F5 R4 y/ w3 C
! H/ s( U& Q" G2 y$ hconfigure: *** pcre library not found.
8 w4 r5 f. ~- T" fconfigure: error: pcre library is required
- e' G7 F* E s/ @: y解决方法:
! x- l8 c4 Q( Y+ E9 K" |3 u& [2 S- d& x! u" g. [
yum install pcre pcre-devel
$ \, Y9 U% c1 `( b9 R3.没有libxml25 D5 S6 n5 J0 d" y* D
6 K. [! r& o% C4 {+ ^, V
$ Q+ M4 y0 A$ c" d8 hconfigure: *** xml library not found.
5 O$ ?8 m4 }( S$ Yconfigure: error: libxml2 is required
/ ?- i a& _. U# a+ \. p1 q8 I% D0 m/ n解决方法:
" x+ e: z6 u& H- s/ Q4 d. }* y9 w2 f. X1 b
yum install libxml2 libxml2-devel; ^7 M+ M, I8 h- F) z; E6 t7 v
4.执行 /opt/tengine/sbin/nginx -m 时有警告1 J4 K# f1 x7 O5 H* g
9 ?. D) o5 S2 m1 _! ATengine version: Tengine/2.1.0 (nginx/1.6.2)( S. S4 a! u" p- i
nginx: [warn] ModSecurity: Loaded APR do not match with compiled!
( s# w1 D; N; I( \# T5 P$ u原因:modsecurity编译时和加载时的apr版本不一致造成的,并且会有以下error.log
) w# `7 J- K$ U8 x7 _
. q) G$ l. M" n2015/01/26 02:04:18 [notice] 29036#0: ModSecurity for nginx (STABLE)/2.8.0 () configured., W ?1 ]/ }% z( [4 m' d
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: APR compiled version="1.5.0"; loaded version="1.3.9"
& F4 ]. Y7 I V7 @2015/01/26 02:04:18 [warn] 29036#0: ModSecurity: Loaded APR do not match with compiled!
; f, ~8 v2 C: K: t' m2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: PCRE compiled version="7.8 "; loaded version="7.8 2008-09-05"
# F* ^/ f$ x' ~: }# E- e6 P: `2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: LIBXML compiled version="2.7.6"# z1 l) @; n/ j3 ]8 g3 |
2015/01/26 02:04:18 [notice] 29036#0: Status engine is currently disabled, enable it by set SecStatusEngine to On.
2 X2 A' M8 E, D ^' U$ o: Y解决方法,移除低版本的APR (1.3.9)6 {! B9 w" s9 J* q$ d8 U$ ?/ c( O
2 c9 ?9 @& w2 w, U* Eyum remove apr' V$ ]- P# f5 z: i H h+ K- m G
5.Error.log中有: Audit log: Failed to lock global mutex
6 Z, `- b! X! _8 k7 C4 r
2 f: p& W0 n+ `& Y2015/01/26 04:15:42 [error] 61610#0: [client 10.11.15.161] ModSecurity: Audit log: Failed to lock * O& X$ t9 `* p
global mutex: Permission denied [hostname ""] [uri "/i.php"] [unique_id "AcAcAcAcAcAcAcA4DcA7AcAc"]
7 E7 W b- c* }5 M; g解决方法:
( c/ y% a( x4 S# n- @编辑modsecurity.conf,注释掉默认的SecAuditLogType和SecAuditLog,添加以下内容:
1 V) V$ R/ s- X7 A# O# T6 C8 V; q n. w# O% w
SecAuditLogDirMode 0777
" v# z( N. f' w& \- W% k1 |$ S; b WSecAuditLogFileMode 05505 C5 C1 h1 {6 k+ S) T& Q+ ]6 W
SecAuditLogStorageDir /var/log/modsecurity* o7 [8 x) P( ?
SecAuditLogType Concurrent0 ]. i6 P7 |- Q8 @5 c
参考文章:: S# ]! U3 K2 E8 ]2 E- i
https://github.com/SpiderLabs/ModSecurity/wiki/Reference-Manual#Installation_for_NGINX$ t" O$ ~7 D; b
http://drops.wooyun.org/tips/2614 |
|