找回密码
 立即注册

QQ登录

只需一步,快速开始

查看: 12688|回复: 0

nginx配合modsecurity实现WAF功能

[复制链接]
发表于 2017-10-19 16:53:31 | 显示全部楼层 |阅读模式
modsecurity原本是Apache上的一款开源waf,可以有效的增强web安全性,目前已经支持nginx和IIS,配合nginx的灵活和高效,可以打造成生产级的WAF,是保护和审核web安全的利器。' g, W% i4 Q* v5 a  S9 N
3 _% @( J) j2 c8 M9 x
一.准备工作7 d4 J: Q' b5 F$ v

) c' b7 |+ b, K6 `# I. i0 _- r  y系统:centos 6.5 64位、 tengine 2.1.0, modsecurity 2.8.0' N0 B- {) a( P! {+ ]1 I9 |9 o

9 S1 J) W  q7 P0 S2 F0 ttengine : http://tengine.taobao.org/download/tengine-2.1.0.tar.gz
7 X4 T/ ?$ E) k' k; ~4 |
0 u0 B! D1 }3 s& w3 Ymodsecurity for Nginx: https://www.modsecurity.org/tarball/2.8.0/modsecurity-2.8.0.tar.gz- p. x3 j# E. ^4 [1 j

6 i) w6 k0 A$ T' y$ O6 P/ u& EOWASP规则集: https://github.com/SpiderLabs/owasp-modsecurity-crs; J" ]5 V  ]) B; Y; K7 g

4 K3 d; b4 ~7 _; [) A) E依赖关系:$ l) G+ U& I% Z9 D7 w0 T  q6 l  |
tengine(nginx)依赖: pcre 、zlib、 openssl, 这三个包centos 6.5 系统源里都有:" k4 ?$ [! a7 R3 |! s

/ J; ?+ [' U: h% [) oyum install zlib zlib-devel openssl openssl-devel  pcre pcre-devel
+ I, ^+ d7 o9 h" ~modsecurty依赖的包:pcre httpd-devel libxml2 apr
+ ]& A! f' z* v3 `- j: l* A& N
) r" Q5 ~: M8 [# Yyum install httpd-devel apr apr-util-devel apr-devel  pcre pcre-devel  libxml2 libxml2-devel
0 U1 ?" p. Z( e* p( _3 E" B0 v4 w9 O5 T: n二.启用standalone模块并编译
2 a( ?! D/ c3 F$ a0 N1 @+ [4 ~; P% S& k/ a8 _( _. T* Y4 X1 `9 ?  I
下载modsecurity for nginx 解压,进入解压后目录执行:
' w$ T+ X1 }/ p! b) d
# v; e. k2 F' A' }; a, H) h/ x& v./autogen.sh
/ x) c5 X' m6 l* W  t/ q./configure --enable-standalone-module --disable-mlogc
" R5 U9 @  Z$ b  h" Dmake
* H. S7 `- y/ _三.nginx添加modsecurity模块8 R4 J: v5 S* ?- P" z+ u

# x( G% [" k4 J# g6 r# A在编译standalone后,nginx编译时可以通过"--add-module"添加modsecurity模块:
' w& _- ^7 B, F* H7 z: ?' y$ P: A8 f2 C0 z8 f9 A: L# n
./configure --add-module=/root/modsecurity-2.8.0/nginx/modsecurity/  --prefix=/opt/tengine
) V5 K* X; W  g- u) ?make && make install
/ Q) ~/ Y3 N9 H2 e9 h$ R四.添加规则
& q  i3 o' L, ]# M9 C, i
  v( U3 K- u& m0 J" f! h4 k$ Qmodsecurity倾向于过滤和阻止web危险,之所以强大就在于规则,OWASP提供的规则是于社区志愿者维护的,被称为核心规则CRS(corerules),规则可靠强大,当然也可以自定义规则来满足各种需求。
! a; }% O; W3 r9 v
; f/ q0 N9 ]% k! a9 B: h" n1.下载OWASP规则:7 E) w: m5 B* D  O, Z) X' J- ~

: p' J$ M- |( R- {git clone https://github.com/SpiderLabs/owasp-modsecurity-crs
! J" V8 Z8 [) K
* X, x7 r" U. p* C4 Tmv owasp-modsecurity-crs /opt/tengine/conf/( f# a7 V# u: h8 r# R. M* N' X

8 _- ]5 o7 ~( h, ^* A- C# ?* [" c3 F2 bcd /opt/tengine/conf/owasp-modsecurity-crs && mv modsecurity_crs_10_setup.conf.example modsecurity_crs_10_setup.conf
# D1 T* i3 P& p7 P: p, J2 W" D2.启用OWASP规则:
! M" ^, M% A$ P+ z" F+ a8 q& Z
( v8 ^, N5 i% x' @( ^复制modsecurity源码目录下的modsecurity.conf-recommended和unicode.mapping到nginx的conf目录下,并将modsecurity.conf-recommended重新命名为modsecurity.conf。
1 K/ o" ]( B. g1 @. ?" h
. N0 \( j( s, a, Y, @' P$ U& H& t2 j编辑modsecurity.conf 文件,将SecRuleEngine设置为 on
1 P7 R- u  c" J
* Z6 [: p6 v! Q& U! _4 xowasp-modsecurity-crs下有很多存放规则的文件夹,例如base_rules、experimental_rules、optional_rules、slr_rules,里面的规则按需要启用,需要启用的规则使用Include进来即可。9 Z( Y  y# |1 \  s' r& |" r: o( Y& a

& `5 b: p, N4 Y: e( w4 vInclude owasp-modsecurity-crs/modsecurity_crs_10_setup.conf4 G$ o9 h; X" `0 L8 c- D7 S& d
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_sql_injection_attacks.conf9 A& z, M! R3 U- h
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_xss_attacks.conf
' g( y5 ~: D5 [& c* e- dInclude owasp-modsecurity-crs/base_rules/modsecurity_crs_40_generic_attacks.conf6 w0 ]- _0 i- {
Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_dos_protection.conf4 b' y: x6 y3 g$ O
Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_brute_force.conf
8 e. |# h, t' j/ L( KInclude owasp-modsecurity-crs/optional_rules/modsecurity_crs_16_session_hijacking.conf5 o" ]1 U0 y1 H& H5 X
五.配置nginx9 @: @5 N! y3 N1 c% _* j
4 I' e6 K' S! J+ w5 a" l% j
在需要启用modsecurity的主机的location下面加入下面两行即可:9 }7 G/ k0 `! l* \

0 O* J8 E7 c: V6 k/ h* pModSecurityEnabled on;  6 L2 Y6 F/ c( ]# z2 n/ H
ModSecurityConfig modsecurity.conf;) a8 `0 ~  U4 t( O+ k) H0 l
下面是两个示例配置,php虚拟主机:4 g+ x: K7 r9 i& T7 ~- S$ ]) U
0 T; [: C% v5 O' W; D' s
server {& L& `: [9 q% G. {2 c
      listen      80;2 k- B9 R, l; m
      server_name 52os.net www.52os.net;# v- v& ~3 Q2 U- j& v
     ) E7 [: G  i- o' P' F* c+ U
      location ~ \.php$ {# k& K  b; x, @) ^1 j! S/ N
      ModSecurityEnabled on;  , S  w6 w$ d$ Q' t
      ModSecurityConfig modsecurity.conf;! q9 w6 D" E5 R# O4 e
$ a* l/ \4 @8 n, L  o: L
      root /web/wordpress;
2 R8 x, ?/ o. w$ R' }; f' @/ p5 t4 g      index index.php index.html index.htm;
% i+ c8 y) ^2 Z9 I! l6 l  + K- N' L" ?% H
      fastcgi_pass   127.0.0.1:9000;
# M' U% f' T, i      fastcgi_index  index.php;9 K! ^. U7 P0 \4 C9 r' A  j
      fastcgi_param  SCRIPT_FILENAME  $Document_root$fastcgi_script_name;
2 i! ?3 N0 \+ i' I" u5 q- P9 x      include        fastcgi_params;
2 ^2 q2 ]# S7 O$ {) N4 a2 Y- T. Q! T      }* V, T- A7 w( [/ n: ^& L- s
  }
9 K, @8 y, N. m* ]upstream负载均衡:) u0 s" U+ R* z) o1 d, g/ a

# ?! x, ~( X8 Tupstream 52os.net {
, _' p5 I+ x- e    server 192.168.1.100:8080;0 f, I6 F7 H5 O# l$ h) V. _
    server 192.168.1.101:8080 backup;+ ]6 z- a! j+ M$ \5 q
}; o! i' J8 e3 ~6 w5 `& o* `

8 b0 \0 m8 r/ F" G4 u4 L* B% sserver {" Z7 q6 H# X$ f. D1 i% J
listen 80;
0 ^( e( r% b* B. q# qserver_name 52os.net www.52os.net;
9 t7 |  a4 m' l; I$ R: U! b+ u  T* z* w" |7 i
location / {1 n% m  k2 a" V$ O
    ModSecurityEnabled on;  
+ l0 E/ K" f5 s/ k$ W    ModSecurityConfig modsecurity.conf;  : X3 Y& f2 f3 o/ h* k+ M

6 q* D* W& \3 }. K4 L        proxy_pass http://online;
2 g! R9 a2 T9 s        proxy_redirect         off;
4 c: ^# ]: {% N9 ^7 H        proxy_set_header Host $host;3 q6 E5 q) |4 N) j4 U" q
        proxy_set_header X-Real-IP $remote_addr;
3 l3 \" Z* x9 b        proxy_set_header  X-Forwarded-For $proxy_add_x_forwarded_for;
! P7 G* B( o8 M0 b    }2 I: x5 n! ^3 B
}
1 c6 t0 m. V$ V% _9 ~7 m六.测试$ M9 Z* X1 K& v( ]1 L& B7 t

' S( m1 B* e! m. J' W. i我们启用了xss和sql注入的过滤,不正常的请求会直接返回403。以php环境为例,新建一个phpinfo.php内容为:
/ O! m% k9 O  J
' j  r0 X7 D- \6 N  {+ O<?php  L- A( H3 U6 G6 K" n* m9 I
    phpinfo();    ! y: i5 U2 v" }4 w* @
?>
0 `: N2 P9 @# ~) y# _5 r7 G在浏览器中访问:% W! A. W! @: ^

6 }% i, F) Z& y# Y; W7 ghttp://www.52os.net/phpinfo.php?id=1 正常显示。
+ U' a9 @' v$ Xhttp://www.52os.net/phpinfo.php?id=1 and 1=1  返回403。$ G$ P6 S- k/ z: `; n
http://www.52os.net/phpinfo.php?search=<scritp>alert('xss');</script>  返回403。
  h( \3 s# _3 i: h6 y4 b说明sql注入和xss已经被过滤了
7 j  x6 e( g- S, H( l& u5 Y# @; _4 f0 L" J& e. o) e  F! ^
七、安装过程中排错7 d7 T, D# u5 v+ y
, e6 x5 H& y5 N0 f  u
1.缺少APXS会报错3 u% S5 u1 w* g; y/ R  h: y+ P* Z

% g) r5 Q2 J8 A: K: _configure: looking for Apache module support via DSO through APXS& F7 u3 o8 T  J% @, ~+ O1 ]
configure: error: couldn't find APXS. B2 N+ s$ Z3 B3 Z6 w9 D
apxs是一个为Apache HTTP服务器编译和安装扩展模块的工具,用于编译一个或多个源程序或目标代码文件为动态共享对象。7 z( E0 w" k0 d* t1 y* T3 r
解决方法:7 H# [# X3 N5 I8 t/ a
4 F; K- R+ D; T# s
yum install httpd-devel$ z' A$ l! R# ~( ?/ |. H
2.没有pcre
* {- [/ U. I) o: ^) P* ?( t$ S* o- P$ k6 ^$ T+ e* _! ^
configure: *** pcre library not found." |$ f9 H. x6 {" ]! W8 L0 N/ V8 Y
configure: error: pcre library is required
' d5 a% W8 C& N解决方法:
  R/ }8 U, K4 C0 s
( i( Q1 P/ i; U- @  myum install pcre pcre-devel
$ Q0 j' ^# l' P3.没有libxml2" W1 K# I$ [/ J3 z
* |/ ~( i2 P: Y( W6 ~& \1 h' s* Q$ d
) \" P, H/ n. y' `6 c
configure: *** xml library not found.
( F. b' Z2 c& t9 Q1 k" h+ cconfigure: error: libxml2 is required
4 u* d& L- Y$ h解决方法:  X4 b1 }$ Z; g( y
1 P+ v9 D7 I5 D2 [5 k$ D% ?  Q
yum install  libxml2 libxml2-devel. }8 P& z" Y/ w6 ~
4.执行 /opt/tengine/sbin/nginx -m 时有警告
4 x) a: H+ h; M3 e+ |* A; K1 G" V" v, x( f, l1 Q
Tengine version: Tengine/2.1.0 (nginx/1.6.2)7 c+ u  j; v) z, ^' t, J, j
nginx: [warn] ModSecurity: Loaded APR do not match with compiled!
7 d( y7 K+ Q+ |3 \. x原因:modsecurity编译时和加载时的apr版本不一致造成的,并且会有以下error.log
) U) A# F, d% L' _, F( x
* W+ m+ G3 x7 V; h- h) }2015/01/26 02:04:18 [notice] 29036#0: ModSecurity for nginx (STABLE)/2.8.0 () configured.
8 Q$ A- m' |* M2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: APR compiled version="1.5.0"; loaded     version="1.3.9"  z1 G# F2 h) a8 V
2015/01/26 02:04:18 [warn] 29036#0: ModSecurity: Loaded APR do not match with compiled!
4 r! N6 b' ~; n9 q& V2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: PCRE compiled version="7.8 "; loaded version="7.8 2008-09-05"
  Z) [! c# R3 T9 B! S2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: LIBXML compiled version="2.7.6"
7 \5 n; o; ^2 O2015/01/26 02:04:18 [notice] 29036#0: Status engine is currently disabled, enable it by set SecStatusEngine to On.5 Z9 `3 f" t6 T' r2 g
解决方法,移除低版本的APR (1.3.9)
0 Z) d) M: Z/ G( o1 J) m
; U! g9 T, M/ Q9 J- W/ N6 uyum remove apr
9 ?5 g1 v3 U4 e: x+ `! T5.Error.log中有: Audit log: Failed to lock global mutex
2 T3 n: o% R$ H5 C4 _7 C& v* f. [/ n
) I2 R, _+ K' R: S9 I' x$ J2015/01/26 04:15:42 [error] 61610#0: [client 10.11.15.161] ModSecurity: Audit log: Failed to lock     
2 Z8 H7 v8 x( f* n; Rglobal mutex: Permission denied [hostname ""] [uri "/i.php"] [unique_id "AcAcAcAcAcAcAcA4DcA7AcAc"]+ R& J5 y" \! {9 {. e
解决方法:6 U: ]5 Z( w2 j7 N/ A. r
编辑modsecurity.conf,注释掉默认的SecAuditLogType和SecAuditLog,添加以下内容:* V' f$ s" W) W, R. l/ D
" f5 |$ n$ {. w' l7 `1 W
SecAuditLogDirMode 0777- y* T, A; p- f
SecAuditLogFileMode 0550
/ Z2 b) P2 q, |# Z; v0 y3 d9 RSecAuditLogStorageDir /var/log/modsecurity
& A. X7 r. t( uSecAuditLogType Concurrent7 [' W4 s  A/ P+ v# f
参考文章:; g! I+ y' h: d& ~( ?5 R- K
https://github.com/SpiderLabs/ModSecurity/wiki/Reference-Manual#Installation_for_NGINX( [6 S0 ]2 M' S  L- Z- y
http://drops.wooyun.org/tips/2614
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

QQ|Archiver|手机版|小黑屋|第一站论坛 ( 蜀ICP备06004864号-6 )

GMT+8, 2026-9-29 20:40 , Processed in 0.043696 second(s), 19 queries .

Powered by Discuz! X3.5

© 2001-2026 Discuz! Team.

快速回复 返回顶部 返回列表