|
|
modsecurity原本是Apache上的一款开源waf,可以有效的增强web安全性,目前已经支持nginx和IIS,配合nginx的灵活和高效,可以打造成生产级的WAF,是保护和审核web安全的利器。' g, W% i4 Q* v5 a S9 N
3 _% @( J) j2 c8 M9 x
一.准备工作7 d4 J: Q' b5 F$ v
) c' b7 |+ b, K6 `# I. i0 _- r y系统:centos 6.5 64位、 tengine 2.1.0, modsecurity 2.8.0' N0 B- {) a( P! {+ ]1 I9 |9 o
9 S1 J) W q7 P0 S2 F0 ttengine : http://tengine.taobao.org/download/tengine-2.1.0.tar.gz
7 X4 T/ ?$ E) k' k; ~4 |
0 u0 B! D1 }3 s& w3 Ymodsecurity for Nginx: https://www.modsecurity.org/tarball/2.8.0/modsecurity-2.8.0.tar.gz- p. x3 j# E. ^4 [1 j
6 i) w6 k0 A$ T' y$ O6 P/ u& EOWASP规则集: https://github.com/SpiderLabs/owasp-modsecurity-crs; J" ]5 V ]) B; Y; K7 g
4 K3 d; b4 ~7 _; [) A) E依赖关系:$ l) G+ U& I% Z9 D7 w0 T q6 l |
tengine(nginx)依赖: pcre 、zlib、 openssl, 这三个包centos 6.5 系统源里都有:" k4 ?$ [! a7 R3 |! s
/ J; ?+ [' U: h% [) oyum install zlib zlib-devel openssl openssl-devel pcre pcre-devel
+ I, ^+ d7 o9 h" ~modsecurty依赖的包:pcre httpd-devel libxml2 apr
+ ]& A! f' z* v3 `- j: l* A& N
) r" Q5 ~: M8 [# Yyum install httpd-devel apr apr-util-devel apr-devel pcre pcre-devel libxml2 libxml2-devel
0 U1 ?" p. Z( e* p( _3 E" B0 v4 w9 O5 T: n二.启用standalone模块并编译
2 a( ?! D/ c3 F$ a0 N1 @+ [4 ~; P% S& k/ a8 _( _. T* Y4 X1 `9 ? I
下载modsecurity for nginx 解压,进入解压后目录执行:
' w$ T+ X1 }/ p! b) d
# v; e. k2 F' A' }; a, H) h/ x& v./autogen.sh
/ x) c5 X' m6 l* W t/ q./configure --enable-standalone-module --disable-mlogc
" R5 U9 @ Z$ b h" Dmake
* H. S7 `- y/ _三.nginx添加modsecurity模块8 R4 J: v5 S* ?- P" z+ u
# x( G% [" k4 J# g6 r# A在编译standalone后,nginx编译时可以通过"--add-module"添加modsecurity模块:
' w& _- ^7 B, F* H7 z: ?' y$ P: A8 f2 C0 z8 f9 A: L# n
./configure --add-module=/root/modsecurity-2.8.0/nginx/modsecurity/ --prefix=/opt/tengine
) V5 K* X; W g- u) ?make && make install
/ Q) ~/ Y3 N9 H2 e9 h$ R四.添加规则
& q i3 o' L, ]# M9 C, i
v( U3 K- u& m0 J" f! h4 k$ Qmodsecurity倾向于过滤和阻止web危险,之所以强大就在于规则,OWASP提供的规则是于社区志愿者维护的,被称为核心规则CRS(corerules),规则可靠强大,当然也可以自定义规则来满足各种需求。
! a; }% O; W3 r9 v
; f/ q0 N9 ]% k! a9 B: h" n1.下载OWASP规则:7 E) w: m5 B* D O, Z) X' J- ~
: p' J$ M- |( R- {git clone https://github.com/SpiderLabs/owasp-modsecurity-crs
! J" V8 Z8 [) K
* X, x7 r" U. p* C4 Tmv owasp-modsecurity-crs /opt/tengine/conf/( f# a7 V# u: h8 r# R. M* N' X
8 _- ]5 o7 ~( h, ^* A- C# ?* [" c3 F2 bcd /opt/tengine/conf/owasp-modsecurity-crs && mv modsecurity_crs_10_setup.conf.example modsecurity_crs_10_setup.conf
# D1 T* i3 P& p7 P: p, J2 W" D2.启用OWASP规则:
! M" ^, M% A$ P+ z" F+ a8 q& Z
( v8 ^, N5 i% x' @( ^复制modsecurity源码目录下的modsecurity.conf-recommended和unicode.mapping到nginx的conf目录下,并将modsecurity.conf-recommended重新命名为modsecurity.conf。
1 K/ o" ]( B. g1 @. ?" h
. N0 \( j( s, a, Y, @' P$ U& H& t2 j编辑modsecurity.conf 文件,将SecRuleEngine设置为 on
1 P7 R- u c" J
* Z6 [: p6 v! Q& U! _4 xowasp-modsecurity-crs下有很多存放规则的文件夹,例如base_rules、experimental_rules、optional_rules、slr_rules,里面的规则按需要启用,需要启用的规则使用Include进来即可。9 Z( Y y# |1 \ s' r& |" r: o( Y& a
& `5 b: p, N4 Y: e( w4 vInclude owasp-modsecurity-crs/modsecurity_crs_10_setup.conf4 G$ o9 h; X" `0 L8 c- D7 S& d
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_sql_injection_attacks.conf9 A& z, M! R3 U- h
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_xss_attacks.conf
' g( y5 ~: D5 [& c* e- dInclude owasp-modsecurity-crs/base_rules/modsecurity_crs_40_generic_attacks.conf6 w0 ]- _0 i- {
Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_dos_protection.conf4 b' y: x6 y3 g$ O
Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_brute_force.conf
8 e. |# h, t' j/ L( KInclude owasp-modsecurity-crs/optional_rules/modsecurity_crs_16_session_hijacking.conf5 o" ]1 U0 y1 H& H5 X
五.配置nginx9 @: @5 N! y3 N1 c% _* j
4 I' e6 K' S! J+ w5 a" l% j
在需要启用modsecurity的主机的location下面加入下面两行即可:9 }7 G/ k0 `! l* \
0 O* J8 E7 c: V6 k/ h* pModSecurityEnabled on; 6 L2 Y6 F/ c( ]# z2 n/ H
ModSecurityConfig modsecurity.conf;) a8 `0 ~ U4 t( O+ k) H0 l
下面是两个示例配置,php虚拟主机:4 g+ x: K7 r9 i& T7 ~- S$ ]) U
0 T; [: C% v5 O' W; D' s
server {& L& `: [9 q% G. {2 c
listen 80;2 k- B9 R, l; m
server_name 52os.net www.52os.net;# v- v& ~3 Q2 U- j& v
) E7 [: G i- o' P' F* c+ U
location ~ \.php$ {# k& K b; x, @) ^1 j! S/ N
ModSecurityEnabled on; , S w6 w$ d$ Q' t
ModSecurityConfig modsecurity.conf;! q9 w6 D" E5 R# O4 e
$ a* l/ \4 @8 n, L o: L
root /web/wordpress;
2 R8 x, ?/ o. w$ R' }; f' @/ p5 t4 g index index.php index.html index.htm;
% i+ c8 y) ^2 Z9 I! l6 l + K- N' L" ?% H
fastcgi_pass 127.0.0.1:9000;
# M' U% f' T, i fastcgi_index index.php;9 K! ^. U7 P0 \4 C9 r' A j
fastcgi_param SCRIPT_FILENAME $Document_root$fastcgi_script_name;
2 i! ?3 N0 \+ i' I" u5 q- P9 x include fastcgi_params;
2 ^2 q2 ]# S7 O$ {) N4 a2 Y- T. Q! T }* V, T- A7 w( [/ n: ^& L- s
}
9 K, @8 y, N. m* ]upstream负载均衡:) u0 s" U+ R* z) o1 d, g/ a
# ?! x, ~( X8 Tupstream 52os.net {
, _' p5 I+ x- e server 192.168.1.100:8080;0 f, I6 F7 H5 O# l$ h) V. _
server 192.168.1.101:8080 backup;+ ]6 z- a! j+ M$ \5 q
}; o! i' J8 e3 ~6 w5 `& o* `
8 b0 \0 m8 r/ F" G4 u4 L* B% sserver {" Z7 q6 H# X$ f. D1 i% J
listen 80;
0 ^( e( r% b* B. q# qserver_name 52os.net www.52os.net;
9 t7 | a4 m' l; I$ R: U! b+ u T* z* w" |7 i
location / {1 n% m k2 a" V$ O
ModSecurityEnabled on;
+ l0 E/ K" f5 s/ k$ W ModSecurityConfig modsecurity.conf; : X3 Y& f2 f3 o/ h* k+ M
6 q* D* W& \3 }. K4 L proxy_pass http://online;
2 g! R9 a2 T9 s proxy_redirect off;
4 c: ^# ]: {% N9 ^7 H proxy_set_header Host $host;3 q6 E5 q) |4 N) j4 U" q
proxy_set_header X-Real-IP $remote_addr;
3 l3 \" Z* x9 b proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
! P7 G* B( o8 M0 b }2 I: x5 n! ^3 B
}
1 c6 t0 m. V$ V% _9 ~7 m六.测试$ M9 Z* X1 K& v( ]1 L& B7 t
' S( m1 B* e! m. J' W. i我们启用了xss和sql注入的过滤,不正常的请求会直接返回403。以php环境为例,新建一个phpinfo.php内容为:
/ O! m% k9 O J
' j r0 X7 D- \6 N {+ O<?php L- A( H3 U6 G6 K" n* m9 I
phpinfo(); ! y: i5 U2 v" }4 w* @
?>
0 `: N2 P9 @# ~) y# _5 r7 G在浏览器中访问:% W! A. W! @: ^
6 }% i, F) Z& y# Y; W7 ghttp://www.52os.net/phpinfo.php?id=1 正常显示。
+ U' a9 @' v$ Xhttp://www.52os.net/phpinfo.php?id=1 and 1=1 返回403。$ G$ P6 S- k/ z: `; n
http://www.52os.net/phpinfo.php?search=<scritp>alert('xss');</script> 返回403。
h( \3 s# _3 i: h6 y4 b说明sql注入和xss已经被过滤了
7 j x6 e( g- S, H( l& u5 Y# @; _4 f0 L" J& e. o) e F! ^
七、安装过程中排错7 d7 T, D# u5 v+ y
, e6 x5 H& y5 N0 f u
1.缺少APXS会报错3 u% S5 u1 w* g; y/ R h: y+ P* Z
% g) r5 Q2 J8 A: K: _configure: looking for Apache module support via DSO through APXS& F7 u3 o8 T J% @, ~+ O1 ]
configure: error: couldn't find APXS. B2 N+ s$ Z3 B3 Z6 w9 D
apxs是一个为Apache HTTP服务器编译和安装扩展模块的工具,用于编译一个或多个源程序或目标代码文件为动态共享对象。7 z( E0 w" k0 d* t1 y* T3 r
解决方法:7 H# [# X3 N5 I8 t/ a
4 F; K- R+ D; T# s
yum install httpd-devel$ z' A$ l! R# ~( ?/ |. H
2.没有pcre
* {- [/ U. I) o: ^) P* ?( t$ S* o- P$ k6 ^$ T+ e* _! ^
configure: *** pcre library not found." |$ f9 H. x6 {" ]! W8 L0 N/ V8 Y
configure: error: pcre library is required
' d5 a% W8 C& N解决方法:
R/ }8 U, K4 C0 s
( i( Q1 P/ i; U- @ myum install pcre pcre-devel
$ Q0 j' ^# l' P3.没有libxml2" W1 K# I$ [/ J3 z
* |/ ~( i2 P: Y( W6 ~& \1 h' s* Q$ d
) \" P, H/ n. y' `6 c
configure: *** xml library not found.
( F. b' Z2 c& t9 Q1 k" h+ cconfigure: error: libxml2 is required
4 u* d& L- Y$ h解决方法: X4 b1 }$ Z; g( y
1 P+ v9 D7 I5 D2 [5 k$ D% ? Q
yum install libxml2 libxml2-devel. }8 P& z" Y/ w6 ~
4.执行 /opt/tengine/sbin/nginx -m 时有警告
4 x) a: H+ h; M3 e+ |* A; K1 G" V" v, x( f, l1 Q
Tengine version: Tengine/2.1.0 (nginx/1.6.2)7 c+ u j; v) z, ^' t, J, j
nginx: [warn] ModSecurity: Loaded APR do not match with compiled!
7 d( y7 K+ Q+ |3 \. x原因:modsecurity编译时和加载时的apr版本不一致造成的,并且会有以下error.log
) U) A# F, d% L' _, F( x
* W+ m+ G3 x7 V; h- h) }2015/01/26 02:04:18 [notice] 29036#0: ModSecurity for nginx (STABLE)/2.8.0 () configured.
8 Q$ A- m' |* M2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: APR compiled version="1.5.0"; loaded version="1.3.9" z1 G# F2 h) a8 V
2015/01/26 02:04:18 [warn] 29036#0: ModSecurity: Loaded APR do not match with compiled!
4 r! N6 b' ~; n9 q& V2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: PCRE compiled version="7.8 "; loaded version="7.8 2008-09-05"
Z) [! c# R3 T9 B! S2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: LIBXML compiled version="2.7.6"
7 \5 n; o; ^2 O2015/01/26 02:04:18 [notice] 29036#0: Status engine is currently disabled, enable it by set SecStatusEngine to On.5 Z9 `3 f" t6 T' r2 g
解决方法,移除低版本的APR (1.3.9)
0 Z) d) M: Z/ G( o1 J) m
; U! g9 T, M/ Q9 J- W/ N6 uyum remove apr
9 ?5 g1 v3 U4 e: x+ `! T5.Error.log中有: Audit log: Failed to lock global mutex
2 T3 n: o% R$ H5 C4 _7 C& v* f. [/ n
) I2 R, _+ K' R: S9 I' x$ J2015/01/26 04:15:42 [error] 61610#0: [client 10.11.15.161] ModSecurity: Audit log: Failed to lock
2 Z8 H7 v8 x( f* n; Rglobal mutex: Permission denied [hostname ""] [uri "/i.php"] [unique_id "AcAcAcAcAcAcAcA4DcA7AcAc"]+ R& J5 y" \! {9 {. e
解决方法:6 U: ]5 Z( w2 j7 N/ A. r
编辑modsecurity.conf,注释掉默认的SecAuditLogType和SecAuditLog,添加以下内容:* V' f$ s" W) W, R. l/ D
" f5 |$ n$ {. w' l7 `1 W
SecAuditLogDirMode 0777- y* T, A; p- f
SecAuditLogFileMode 0550
/ Z2 b) P2 q, |# Z; v0 y3 d9 RSecAuditLogStorageDir /var/log/modsecurity
& A. X7 r. t( uSecAuditLogType Concurrent7 [' W4 s A/ P+ v# f
参考文章:; g! I+ y' h: d& ~( ?5 R- K
https://github.com/SpiderLabs/ModSecurity/wiki/Reference-Manual#Installation_for_NGINX( [6 S0 ]2 M' S L- Z- y
http://drops.wooyun.org/tips/2614 |
|