找回密码
 立即注册

QQ登录

只需一步,快速开始

查看: 12679|回复: 0

nginx配合modsecurity实现WAF功能

[复制链接]
发表于 2017-10-19 16:53:31 | 显示全部楼层 |阅读模式
modsecurity原本是Apache上的一款开源waf,可以有效的增强web安全性,目前已经支持nginx和IIS,配合nginx的灵活和高效,可以打造成生产级的WAF,是保护和审核web安全的利器。/ l0 o0 s) z" k& I5 X2 @" r
0 S1 ?) q) @# q& O* E3 L' r
一.准备工作
  w* L% D$ j8 j6 N6 Y  a, N, q1 n" l! _% G5 Q$ e( C$ J1 ^1 S
系统:centos 6.5 64位、 tengine 2.1.0, modsecurity 2.8.08 z; j+ P5 _0 |1 R4 d

9 B* T$ r8 w& |7 L1 @tengine : http://tengine.taobao.org/download/tengine-2.1.0.tar.gz
. Q7 T: v  a0 Z0 w3 \8 z8 b5 |; i+ k9 M3 t
modsecurity for Nginx: https://www.modsecurity.org/tarball/2.8.0/modsecurity-2.8.0.tar.gz
! V1 Z8 h0 Y! }, ?# [$ @; s9 U% E- @% V: o/ @- o* t
OWASP规则集: https://github.com/SpiderLabs/owasp-modsecurity-crs
& V0 |) }& d* ?; X, `- u/ |: e, L/ b  T: H
依赖关系:. U$ w5 G9 l0 |2 D; j2 G) i
tengine(nginx)依赖: pcre 、zlib、 openssl, 这三个包centos 6.5 系统源里都有:
1 b1 {/ G  d# J; O( v5 w. _  H* \7 u8 s* p
yum install zlib zlib-devel openssl openssl-devel  pcre pcre-devel7 s' k  ?& D1 X
modsecurty依赖的包:pcre httpd-devel libxml2 apr) ~! J5 B9 m' A  n6 F: s
& z1 W6 G4 S- L
yum install httpd-devel apr apr-util-devel apr-devel  pcre pcre-devel  libxml2 libxml2-devel
1 ~/ |# U; g7 T  E/ y二.启用standalone模块并编译
# W7 ~1 U0 q0 X  J1 K* P, {2 |
/ u. {( k3 a. a% M下载modsecurity for nginx 解压,进入解压后目录执行:6 V; a9 \+ }3 R  M! O0 D
1 d9 @' ~. v' Z* F  b9 c
./autogen.sh
) u0 A5 v2 K0 V./configure --enable-standalone-module --disable-mlogc
8 L4 M; S8 ?- K0 qmake
9 U9 |1 {' i) F) B三.nginx添加modsecurity模块# G$ m2 x  L& c
0 u' |  b' V% v+ q' [7 T
在编译standalone后,nginx编译时可以通过"--add-module"添加modsecurity模块:6 c) y) |" J9 P" _

, P" o: T- }  L5 \& M# x./configure --add-module=/root/modsecurity-2.8.0/nginx/modsecurity/  --prefix=/opt/tengine4 Q& J4 Y* T5 K+ C2 ^
make && make install6 t* F5 R2 u" l- Z
四.添加规则/ R1 r8 l' r0 R% h. P" e& Q  G8 }) G

8 h2 I$ `7 s9 s* s5 Bmodsecurity倾向于过滤和阻止web危险,之所以强大就在于规则,OWASP提供的规则是于社区志愿者维护的,被称为核心规则CRS(corerules),规则可靠强大,当然也可以自定义规则来满足各种需求。" ^: a8 [( g  E  P  `" c- U

& O2 A: M. r+ y" D! A# k1.下载OWASP规则:
8 p$ U' @0 i" K
8 C4 h& z. A$ v. ?! d+ Ogit clone https://github.com/SpiderLabs/owasp-modsecurity-crs
5 F; z/ O3 _9 x1 h! p
# d/ g+ j" X* F6 ^8 P% y* F0 ]3 ^mv owasp-modsecurity-crs /opt/tengine/conf/
. b! R/ [  k! j* P! ^9 r; r
! a( S* {! c/ v& d( r2 R, U" Mcd /opt/tengine/conf/owasp-modsecurity-crs && mv modsecurity_crs_10_setup.conf.example modsecurity_crs_10_setup.conf1 x7 W. h3 t; E9 }; ~3 `; z1 w
2.启用OWASP规则:
  g' I# C: R3 R/ Q7 U
5 f. S7 N; O, z复制modsecurity源码目录下的modsecurity.conf-recommended和unicode.mapping到nginx的conf目录下,并将modsecurity.conf-recommended重新命名为modsecurity.conf。
+ t$ f, e7 N* l7 G# [: G% L& [7 O, J! _" K, e
编辑modsecurity.conf 文件,将SecRuleEngine设置为 on
0 I. n1 l( f) b2 [. w' s/ P! f- G2 _
owasp-modsecurity-crs下有很多存放规则的文件夹,例如base_rules、experimental_rules、optional_rules、slr_rules,里面的规则按需要启用,需要启用的规则使用Include进来即可。4 C  u! ~% \% H$ `* L9 F$ F4 q- X# x
9 W4 M) x0 D% q" A
Include owasp-modsecurity-crs/modsecurity_crs_10_setup.conf
" ~# M- N9 B6 d6 M( _) @2 |7 t$ Q3 m7 @Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_sql_injection_attacks.conf
# [+ u$ n: _) ?/ _/ c- f' L3 AInclude owasp-modsecurity-crs/base_rules/modsecurity_crs_41_xss_attacks.conf
( n4 v& d! E- C* f1 j0 J1 B/ ^% aInclude owasp-modsecurity-crs/base_rules/modsecurity_crs_40_generic_attacks.conf  d- O7 j- i" U0 I: B3 K3 ?- H
Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_dos_protection.conf. e6 Z; w: a0 o) B7 p
Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_brute_force.conf
( W/ ^% o6 R% i1 S$ U% P" rInclude owasp-modsecurity-crs/optional_rules/modsecurity_crs_16_session_hijacking.conf
0 t9 ^" \" Q( n) S1 D/ a; f五.配置nginx3 T( }- ^: ?9 Z" k

8 d3 y$ f# F1 W在需要启用modsecurity的主机的location下面加入下面两行即可:
0 s" V% }' a; C& [7 q# V& u4 g$ X1 p
ModSecurityEnabled on;  : y2 J& a1 z& m# f: Z6 p
ModSecurityConfig modsecurity.conf;. P- _# {. j0 w; @2 D
下面是两个示例配置,php虚拟主机:$ U) T( S1 h- b: L& E' Z
0 s1 R9 N8 s& P5 L9 J
server {- c* t5 L$ r% g& \2 ]
      listen      80;, z- Z. `$ i1 H/ Y& g1 f; C
      server_name 52os.net www.52os.net;
5 j& Q; W0 L( |5 t/ q2 \     
# J4 p+ O0 E, O8 b      location ~ \.php$ {0 J7 a0 m/ t- V- k
      ModSecurityEnabled on;  
- G+ Y5 n# R% D: j* {      ModSecurityConfig modsecurity.conf;
1 H, e  c! ~$ F2 B0 K+ l- T, l3 I4 r6 E* ^: Q8 O
      root /web/wordpress;+ r+ l4 x7 {5 b- t1 B! h1 {# S
      index index.php index.html index.htm;
7 _1 j" @, R0 J4 a  
9 P- l* }& ?% T      fastcgi_pass   127.0.0.1:9000;
& g* [: H5 W: _; R5 b! V  w      fastcgi_index  index.php;5 m' D4 p4 s) l) C
      fastcgi_param  SCRIPT_FILENAME  $Document_root$fastcgi_script_name;2 c% U/ Z9 a) S. v, `6 i2 S
      include        fastcgi_params;- h) I9 T1 w2 x1 b( P! H4 G
      }5 r( g2 I  L6 t8 G
  }
5 b+ R, m; b# \" C( ^upstream负载均衡:( f' R, K' J5 D' J0 _

' ^- w& K1 [8 P  I; [upstream 52os.net {4 z, h! N$ r/ q1 u7 E+ t
    server 192.168.1.100:8080;. z% Y2 F7 K, e. P0 d1 Q
    server 192.168.1.101:8080 backup;4 T, y% z. d3 G, M4 f2 p
}: i* d3 N( @$ G. r

% t9 p1 _, ~! {: `8 X; jserver {0 g$ c- }0 z  a. e
listen 80;
- x7 k$ A- W: U0 B! eserver_name 52os.net www.52os.net;
! c/ A3 W; V4 c, F- Q  z
# ?' Z& R1 i' ]! K+ nlocation / {7 P1 U9 Z$ S- u( I2 U2 ^
    ModSecurityEnabled on;  8 S' `- v. i- O  w5 L
    ModSecurityConfig modsecurity.conf;  
' H1 w( Q0 Y" e; j! Z9 ~- r$ Q2 {2 q
        proxy_pass http://online;4 O9 T: J$ D9 s' ~8 h, d
        proxy_redirect         off;0 |% A, m. y/ v' B' B9 o2 T
        proxy_set_header Host $host;( N& b% b. S1 H$ j: k
        proxy_set_header X-Real-IP $remote_addr;/ V8 ?) k, h' ]* z! `
        proxy_set_header  X-Forwarded-For $proxy_add_x_forwarded_for;  F2 [  v+ T$ a0 f) t4 i
    }' C" y2 G7 f# P5 z" d; t7 X
}
! V+ f% J# J6 v$ M6 W5 B' f4 {六.测试
3 j3 ]$ C. D' Q3 W4 w$ t
3 h7 Z5 ?5 U+ N! d我们启用了xss和sql注入的过滤,不正常的请求会直接返回403。以php环境为例,新建一个phpinfo.php内容为:
5 z7 ~( Q$ E/ O' Q7 k0 i% u5 b6 n  k% x
<?php
& s( o, V" e6 M' [: d7 X    phpinfo();   
8 F$ c  l+ b1 O, E, Q8 r8 E?>
$ i7 e4 D; o* J" `% x在浏览器中访问:: _. _- q: _7 E% u9 T, z4 M
2 J: v) Z( A! r' ~
http://www.52os.net/phpinfo.php?id=1 正常显示。8 N( v  A  p3 C8 u; c& ~
http://www.52os.net/phpinfo.php?id=1 and 1=1  返回403。
5 }- x& V' \( g. h4 ]http://www.52os.net/phpinfo.php?search=<scritp>alert('xss');</script>  返回403。
6 J, p0 ]7 o6 z说明sql注入和xss已经被过滤了) Y( _0 s0 z. l$ }/ z2 k0 Q! `

, u. y8 }& }# m七、安装过程中排错! d! b- P( |; ?& B. N' s$ a0 _
, `8 _- W5 Q  p& [# H1 \+ J: B
1.缺少APXS会报错) y* z3 T' C8 `, F- j4 J
  Q: @+ N  d+ m' j, X7 B$ e1 z* n
configure: looking for Apache module support via DSO through APXS
. D7 P/ o; _, e+ Tconfigure: error: couldn't find APXS4 u( f7 J! u% u( z  \: ?
apxs是一个为Apache HTTP服务器编译和安装扩展模块的工具,用于编译一个或多个源程序或目标代码文件为动态共享对象。
/ g3 t8 q; U( j; g) Z' H, s' N6 q解决方法:$ v. @. @4 R* U  J% ^

: z& R  l$ A4 e1 W. ]8 gyum install httpd-devel. m! o% g8 v5 t. u: y  A# ?
2.没有pcre
4 ?7 G- a4 {5 M  b! ?8 u- ~& H% B) P7 T
0 R/ P, N. q$ ~- I" T) ]  Pconfigure: *** pcre library not found.
; Z! T" `" s) T, Z7 oconfigure: error: pcre library is required
  x7 X; |" B5 [7 Y6 q解决方法:* q8 Q: w+ y# m6 w' P
" m; a8 H5 l8 B7 j, D1 E. m* y
yum install pcre pcre-devel
' j4 t2 g/ F' p- q6 ~3.没有libxml2
1 t+ u/ z1 C' K  O$ k0 z: u. q* C8 @) o
) a( j0 _2 r0 ^8 A  l  W3 j% p8 w3 [$ v
configure: *** xml library not found.# Z+ c% h+ X3 ~* p7 p
configure: error: libxml2 is required
9 Y9 ]+ L2 ~: I2 |0 @- @/ {解决方法:
8 e4 o: m/ J5 ]4 K& f: G) {: p+ V4 c& H
yum install  libxml2 libxml2-devel9 A4 d% [1 n% y8 l) J
4.执行 /opt/tengine/sbin/nginx -m 时有警告
- N: X! L4 K  K$ B. O. R) v
0 t& d& D, T1 LTengine version: Tengine/2.1.0 (nginx/1.6.2)9 t! U; m, m$ L% E, L  O
nginx: [warn] ModSecurity: Loaded APR do not match with compiled!' \# f& _) R% G) |5 j3 N
原因:modsecurity编译时和加载时的apr版本不一致造成的,并且会有以下error.log
/ O, H& D9 n: g) R- E
/ c  r, B8 x$ Y$ ?2015/01/26 02:04:18 [notice] 29036#0: ModSecurity for nginx (STABLE)/2.8.0 () configured.4 e3 }, `6 z' [! O6 ~/ [! S4 g4 Z
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: APR compiled version="1.5.0"; loaded     version="1.3.9"+ B! e1 k) C! c$ h& d3 h' B( L  W
2015/01/26 02:04:18 [warn] 29036#0: ModSecurity: Loaded APR do not match with compiled!
2 K4 s% h$ U) i7 _/ d. K6 s2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: PCRE compiled version="7.8 "; loaded version="7.8 2008-09-05"
. n( q) M" C4 @3 g2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: LIBXML compiled version="2.7.6"
. T% b' C4 M2 K$ c! I5 g2015/01/26 02:04:18 [notice] 29036#0: Status engine is currently disabled, enable it by set SecStatusEngine to On.2 k9 _9 N1 r2 E% o
解决方法,移除低版本的APR (1.3.9)
3 R" j  a1 N) B5 l( t* `
- Q& Y5 P3 k! ?6 \' k) }: wyum remove apr" Y) k( Z8 c* q
5.Error.log中有: Audit log: Failed to lock global mutex
1 X/ u( [1 ^  z6 K) v# `' m( l* l) J: _' ^3 W) y
2015/01/26 04:15:42 [error] 61610#0: [client 10.11.15.161] ModSecurity: Audit log: Failed to lock     
' C& m+ D  n. j4 t. hglobal mutex: Permission denied [hostname ""] [uri "/i.php"] [unique_id "AcAcAcAcAcAcAcA4DcA7AcAc"]
& {) e. A& f2 D$ I解决方法:6 F! @- f3 Z% S$ T
编辑modsecurity.conf,注释掉默认的SecAuditLogType和SecAuditLog,添加以下内容:
. w9 L! i5 Q; {- Z4 ~
6 A5 l6 J7 d; aSecAuditLogDirMode 0777
3 J8 C$ X4 v% J9 `2 bSecAuditLogFileMode 0550
! I: u  h7 i1 N3 H) m3 hSecAuditLogStorageDir /var/log/modsecurity9 H) R& p0 n6 r1 Q3 ?' X' j
SecAuditLogType Concurrent/ m4 N% U4 |  @' G
参考文章:
' Q+ ]! e5 _# K9 `https://github.com/SpiderLabs/ModSecurity/wiki/Reference-Manual#Installation_for_NGINX
. n8 S5 \! r' v, V) f( q& fhttp://drops.wooyun.org/tips/2614
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

QQ|Archiver|手机版|小黑屋|第一站论坛 ( 蜀ICP备06004864号-6 )

GMT+8, 2026-9-29 07:24 , Processed in 0.066698 second(s), 20 queries .

Powered by Discuz! X3.5

© 2001-2026 Discuz! Team.

快速回复 返回顶部 返回列表