ModSecurity原本是Apache上的一款开源WAF模块,可以有效的增强Web安全性。目前已经支持Nginx和IIS,配合Nginx的灵活和高效可以打造成生产级的WAF,是保护和审核Web安全的利器。
* R. y0 @+ L& q: g4 \0 @2 x" t) u* Q/ h& t( s% p* H
! h3 ]+ \0 z! p. g
在这篇文章中,我们将学习配置ModSecurity与OWASP的核心规则集。
2 n! q/ s& D8 |3 D$ { s9 o5 i; {$ M1 w6 s
6 n& H/ k2 h6 x1 s7 |: {* P9 G; T! c
什么是ModSecurity( v; b5 b: T7 P( g6 i+ U
ModSecurity是一个入侵侦测与防护引擎,它主要是用于Web应用程序,所以也被称为Web应用程序防火墙(WAF)。它可以作为Web服务器的模块或是单独的应用程序来运作。ModSecurity的功能是增强Web Application 的安全性和保护Web application以避免遭受来自已知与未知的攻击。) F1 Q$ r- w3 h+ V2 [
) d. |* H) B% Y' z3 O9 W8 w1 _7 p( b1 O- \0 R/ J/ ]
ModSecurity计划是从2002年开始,后来由Breach Security Inc.收购,但Breach Security Inc.允诺ModSecurity仍旧为Open Source,并开放源代码给大家使用。最新版的ModSecurity开始支持核心规则集(Core Rule Set),CRS可用于定义旨在保护Web应用免受0day及其它安全攻击的规则。% p( R% g# c6 U- H8 ?
, ~/ r' Z' ?1 M) g) w+ w2 g
/ p+ O9 S! B/ D" g" ~, e4 t
ModSecurity还包含了其他一些特性,如并行文本匹配、Geo IP解析和信用卡号检测等,同时还支持内容注入、自动化的规则更新和脚本等内容。此外,它还提供了一个面向Lua语言的新的API,为开发者提供一个脚本平台以实现用于保护Web应用的复杂逻辑。
1 M. w5 B" x( S/ ~8 H6 E- m- x' \4 I$ ~' W& C. X$ ~: G
- C: L% J& f: |. m; x
官网: https://www.modsecurity.org/
7 i$ b" B& k5 W2 o
" |- N4 }7 O$ M/ c* Y# U& A1 e$ a8 [3 W4 j% |
什么是OWASP CRS' c; `7 a. Y( b) @$ L
OWASP是一个安全社区,开发和维护着一套免费的应用程序保护规则,这就是所谓OWASP的ModSecurity的核心规则集(即CRS)。ModSecurity之所以强大就在于OWASP提供的规则,我们可以根据自己的需求选择不同的规则,也可以通过ModSecurity手工创建安全过滤器、定义攻击并实现主动的安全输入验证。
/ P2 Y \; Q, J; e" L6 w" j0 D3 P8 M$ @
0 {, ?; _) C8 _8 T6 ?0 r5 NModSecurity核心规则集(CRS)提供以下类别的保护来防止攻击。
, E, g2 i5 O+ L7 V
+ b4 z* F) K6 g1 i
4 R% S- E5 s! f2 A& F7 nHTTP Protection(HTTP防御)
& Y+ B$ E, d6 g+ c" B4 \2 SHTTP协议和本地定义使用的detectsviolations策略。4 ^/ F2 h7 @1 f& f1 E/ m9 ?+ ?- F/ R+ Z
, o- r* K. v; j. O& c* Q
4 f/ t7 R6 ^8 M4 A# j
Real-time Blacklist Lookups(实时黑名单查询)! y1 B8 T1 R* p& F8 V4 r5 Q
利用第三方IP名单。
7 Y1 _1 w" A' p; f8 P: O/ `# {: ]1 b0 {: s- z: c/ p. t3 m. j/ L
0 Q1 q7 m5 j4 q
HTTP Denial of Service Protections(HTTP的拒绝服务保护)' S N5 q' ?1 U! O4 R+ x. d1 @
防御HTTP的洪水攻击和HTTP Dos攻击。
8 d) C- s; Y ? O0 n6 c: X, N) ~ L c2 ~( U
/ t8 v6 {% A0 h6 B d0 L/ a' `
Common Web Attacks Protection(常见的Web攻击防护)- D* k+ b0 l! B1 e0 E! c/ R( K
检测常见的Web应用程序的安全攻击。. C- [! Y6 Q J' f' j
3 w W& m5 \: T( V2 H# F( `+ s1 {: o& i2 R( W8 h# A
Automation Detection(自动化检测)
% Q' A; T3 x9 F5 y检测机器人,爬虫,扫描仪和其他表面恶意活动。
; O6 Z. }% Z- ^' w% i! R; V; F' F1 _4 f, \% d
7 |; d4 N. k4 [Integration with AV Scanning for File Uploads(文件上传防病毒扫描)! h4 ^: I3 V( w7 ^# k4 L
检测通过Web应用程序上传的恶意文件。7 M4 }: `* N0 t) T6 O/ Q9 S
; ~3 M2 d9 g/ q3 R$ F" z; \* f0 N/ _5 ]6 X. v/ p" {+ J
Tracking Sensitive Data(跟踪敏感数据)/ @) _, ]6 a; ]1 o1 U" }
信用卡通道的使用,并阻止泄漏。
$ T$ J0 L! }$ o' D% _+ ^4 ~9 B6 d8 F: d; T! X
" V. Y4 H4 ~0 [3 m
Trojan Protection(木马防护)
8 O# ]! V9 M6 a. J) a检测访问木马。0 x, _4 h9 {+ e! F
. p; G! e3 e( a2 [" y& V
" L. |8 H2 M( z, H# pIdentification of Application Defects(应用程序缺陷的鉴定)
( ~; ^. _! E0 r" k v$ H1 z8 h检测应用程序的错误配置警报。
" Q% ]/ J& n8 ?( L2 O4 r2 [) s- t$ l! V6 {9 a* |8 D# L
% Q7 o+ c- W4 p* X& U
Error Detection and Hiding(错误检测和隐藏)! x: A, N* s$ A6 x. R0 Z+ q" @
检测伪装服务器发送错误消息。
- q0 E9 U& S& [/ R2 m4 j
6 [2 M+ r! X4 q( y1 O' l' w
0 c$ N' d! x$ u8 a- `) N$ r; E安装ModSecurity
) h4 d* O! b1 H) f$ v/ x软件基础环境准备
' q; N/ \6 f' H2 i5 a( m下载对应软件包
' L' O1 F2 l8 t4 }! o$ cd /root
8 C; b# R: u5 {+ L- w2 m$ wget 'http://nginx.org/download/nginx-1.9.2.tar.gz'1 U9 L5 M5 D" b, s2 _- h' K' u- L5 V
$ wget -O modsecurity-2.9.1.tar.gz https://github.com/SpiderLabs/ModSecurity/releases/download/v2.9.1/modsecurity-2.9.1.tar.gz
4 c2 `! g7 N9 C P. k安装Nginx和ModSecurity依赖包
9 B# _6 g. j" g& P+ W8 x5 B2 vCentos/RHEL+ j) ^- u) n$ \5 {. I" e$ Z
: b+ l( m/ E8 t5 ~
8 [9 u! d9 q/ V2 w/ `* o {
$ yum install httpd-devel apr apr-util-devel apr-devel pcre pcre-devel libxml2 libxml2-devel zlib zlib-devel openssl openssl-devel
, W, n4 h/ } U/ k4 s7 c% TUbuntu/Debian4 P) t" h3 x$ n1 r3 h G1 ?/ c
% H$ W; c% Q, ~- H/ r" N
4 \7 t' }9 N* O& c8 B$ M& [; I
$ apt-get install libreadline-dev libncurses5-dev libssl-dev perl make build-essential git libpcre3 libpcre3-dev libtool autoconf apache2-dev libxml2 libxml2-dev libcurl4-openssl-dev g++ flex bison curl doxygen libyajl-dev libgeoip-dev dh-autoreconf libpcre++-dev. d) k% `. k* T. h+ Z9 F
编译安装ModSecurity
6 N# K ~2 U, F; HNginx加载ModSecurity模块有两种方式:一种是编译为Nginx静态模块,一种是通过ModSecurity-Nginx Connector加载动态模块。+ {& v. C* ]8 n8 v7 p3 ~
' j/ ] Q! z2 E: j- R9 s2 e# t( S7 l
方法一:编译为Nginx静态模块3 Z3 {9 G, v& A, ~, t
; e4 u, P) u1 U+ E
& n, V9 e+ I% \( h4 ~7 {编译为独立模块(modsecurity-2.9.1)
: P: h- \3 ?" m7 {, u" I$ tar xzvf modsecurity-2.9.1.tar.gz
# {7 D% h3 l n' n4 Z7 ?$ cd modsecurity-2.9.1/
6 _5 r7 H g9 K% `& H! |8 n$ V* ~* I$ ./autogen.sh
, {9 k( w2 D* D& @$ I8 e7 I- N: ]$ ./configure --enable-standalone-module --disable-mlogc% H e" {; x) v* c7 l2 u/ A. @
$ make1 s4 M& u5 s1 a; D
编译安装Nginx并添加ModSecurity模块
, n8 F, X; x1 J9 V$ tar xzvf nginx-1.9.2.tar.gz
. U5 x/ [$ E3 @7 ?2 i+ G5 T$ cd nginx-1.9.2
% p5 n+ c2 a, A( H: W- n# @$ W4 Q$ ./configure --add-module=/root/modsecurity-2.9.1/nginx/modsecurity/. P" Z0 P) K! e) K5 }% O8 B
$ make && make install3 u4 ^& b& K+ A2 J$ w l1 W
方法二:编译通过ModSecurity-Nginx Connector加载的动态模块; [0 b" y. {. Z. p
9 i. a+ c' e3 \6 y9 |+ x
* H' o- |1 L! D4 W" b9 _% r编译LibModSecurity(modsecurity-3.0)& R" z, [5 E# G) x/ A6 }
$ cd /root* {3 {5 S2 r6 \& _3 ~: l! u
$ git clone https://github.com/SpiderLabs/ModSecurity0 V2 ^3 d8 W& p
$ cd ModSecurity, d4 u0 a# a U$ `
$ git checkout -b v3/master origin/v3/master
$ S& T, V3 D4 j! o, m$ sh build.sh
- y# V6 c1 s+ G5 Y- ~4 Q' ~0 k* \$ git submodule init
, j7 q% s) _9 h& @5 n5 f7 p$ git submodule update
: W" w! {5 v7 q. k$ ./configure
& e8 X% l7 H. b$ |& ]" E1 g$ make( ~; x4 q8 q/ t: Z* |2 M& v
$ make install# n4 H4 V# s$ p$ M" l- { O" K
LibModSecurity会安装在 /usr/local/modsecurity/lib 目录下。' e2 g C3 L9 t u
9 E5 P4 @5 X/ \4 N7 l5 T9 W( o
2 D& o c% e+ t" y
$ ls /usr/local/modsecurity/lib
: n3 X: X/ y) p8 C1 ilibmodsecurity.a libmodsecurity.la libmodsecurity.so libmodsecurity.so.3 libmodsecurity.so.3.0.0% _) t1 l. m3 d7 s2 `8 V
编译安装Nginx并添加ModSecurity-Nginx Connector模块
; Q& h, ~5 T: B5 ?/ W% }使用ModSecurity-Nginx模块来连接LibModSecurity! Y, }2 _4 ^) M) A! _4 c: j9 \
1 z ?' n& X# F4 m# N8 P% o
& V7 p# X; I% p% ]
$ cd /root
+ o- P$ u6 n( [3 X4 E, A C- } G$ git clone https://github.com/SpiderLabs/ModSecurity-nginx.git modsecurity-nginx3 r4 i- @3 {) f4 A
$ tar xzvf nginx-1.9.2.tar.gz$ B5 ]& x" l; a% O7 U
$ cd nginx-1.9.2) E8 x2 k# ^/ U7 M
$ ./configure --add-module=/root/modsecurity-nginx
/ V" B+ J* p/ E7 \. m4 {: A$ make% W" L3 O: X/ F4 B: `; |
$ make && make install9 j, {1 t. M" ?+ r
添加OWASP规则
( U& n7 ]5 {; y3 G( P) W! vModSecurity倾向于过滤和阻止Web危险,之所以强大就在于规则。OWASP提供的规则是社区志愿者维护的被称为核心规则CRS,规则可靠强大,当然也可以自定义规则来满足各种需求。
{7 X' Y. c; y& X- b. `& t6 U+ z2 t. p: W1 n* j7 f
5 S( j! H6 } Y" z) g下载OWASP规则并生成配置文件0 j" O8 s7 B. Y' P& d! x
$ git clone https://github.com/SpiderLabs/owasp-modsecurity-crs.git" E$ _& T2 v0 z6 I: _
$ cp -rf owasp-modsecurity-crs /usr/local/nginx/conf/
! O& p: X2 |4 N$ cd /usr/local/nginx/conf/owasp-modsecurity-crs
* P; ?* J* H5 B+ }$ cp crs-setup.conf.example crs-setup.conf
* G( Y0 ~5 f D8 \# F配置OWASP规则
8 J# O4 j( }& T6 p# P |6 Y2 L编辑crs-setup.conf文件2 T0 m- w. A5 @
* s, ^, ^! _6 T/ |+ h8 S3 T* s4 t1 b6 \( H. d, l
$ sed -ie 's/SecDefaultAction "phase:1,log,auditlog,pass"/#SecDefaultAction "phase:1,log,auditlog,pass"/g' crs-setup.conf( a& M f9 K' C
$ sed -ie 's/SecDefaultAction "phase:2,log,auditlog,pass"/#SecDefaultAction "phase:2,log,auditlog,pass"/g' crs-setup.conf! x5 Z& t2 T1 K& P
$ sed -ie 's/#.*SecDefaultAction "phase:1,log,auditlog,deny,status:403"/SecDefaultAction "phase:1,log,auditlog,deny,status:403"/g' crs-setup.conf& o3 W0 P% ~) p: B
$ sed -ie 's/# SecDefaultAction "phase:2,log,auditlog,deny,status:403"/SecDefaultAction "phase:2,log,auditlog,deny,status:403"/g' crs-setup.conf2 {- Q. c; j) C( q& c
默认ModSecurity不会阻挡恶意连接,只会记录在Log里。修改SecDefaultAction选项,默认开启阻挡。
" W4 `4 O5 z6 q8 B- R- S- }
+ A( V- m1 D8 l& {
; J9 _3 L) o5 }! b# s* o6 P/ P启用ModSecurity模块和CRS规则0 Y' X( }/ G6 Q! f3 K3 { e2 b
复制ModSecurity源码目录下的modsecurity.conf-recommended和unicode.mapping到Nginx的conf目录下,并将modsecurity.conf-recommended重新命名为modsecurity.conf。; C/ i; C8 ?2 c
9 I! U! R' P0 D5 V' Y7 I
: |8 L* }: @ b- f) ~) Z6 K' x& c
modsecurity.conf-recommended是ModSecurity工作的主配置文件。默认情况下,它带有.recommended扩展名。要初始化ModSecurity,我们就要重命名此文件。
) I! K2 L5 Y4 N# F5 e
, ~- X* ]0 z2 P' |" b1 {% B: Z$ K5 T; R- _
$ cd /root/modsecurity-2.9.1/- j0 L2 P) o' }( d) ~: o
$ cp modsecurity.conf-recommended /usr/local/nginx/conf/modsecurity.conf
- W' q J$ R' K0 s# Y* Q0 g$ cp unicode.mapping /usr/local/nginx/conf/5 f/ w6 P) Y9 g$ r) H8 R/ M
将SecRuleEngine设置为On,默认值为DetectOnly即为观察模式,建议大家在安装时先默认使用这个模式,规则测试完成后在设置为On,避免出现对网站、服务器某些不可知的影响。
7 G, \ }! _: X9 j
* B/ B, W. S& o! L* C3 k4 J! u! V- h, ~3 c% Z- S# u+ y
$ vim /usr/local/nginx/conf/modsecurity.conf" T% H6 K+ c0 H2 ?2 v. [6 ?4 S
SecRuleEngine On
* V* G* A1 b: G$ YModSecurity中几个常用配置说明:. y( M4 z8 b- Z4 s2 [1 G
3 x/ d G; e. O( O9 p, B* e
, V0 k$ ]3 O0 @! E4 T% K G1.SecRuleEngine:是否接受来自ModSecurity-CRS目录下的所有规则的安全规则引擎。因此,我们可以根据需求设置不同的规则。要设置不同的规则有以下几种。SecRuleEngine On:将在服务器上激活ModSecurity防火墙,它会检测并阻止该服务器上的任何恶意攻击。SecRuleEngine Detection Only:如果设置这个规则它只会检测到所有的攻击,并根据攻击产生错误,但它不会在服务器上阻止任何东西。SecRuleEngine Off:这将在服务器上上停用ModSecurity的防火墙。% |. k! q+ b' z: T. L
; R8 Q& d1 V8 R7 q {& p' X. t, j' u1 u5 R& n
2.SecRequestBodyAccess:它会告诉ModSecurity是否会检查请求,它起着非常重要的作用。它只有两个参数ON或OFF。
4 f" o) `3 L, K5 c# c8 w3 M( I H" L( T! Q; v
1 }) s3 y5 ?, ^6 Q3.SecResponseBodyAccess:如果此参数设置为ON,然后ModeSecurity可以分析服务器响应,并做适当处理。它也有只有两个参数ON和Off,我们可以根据求要进行设置。. B( B& d, f Z# s: m" t- z3 Z5 v6 N: ?6 Y
# z$ E2 o b& v- X$ v* ?6 n3 }! m9 O9 T+ C
4.SecDataDir:定义ModSecurity的工作目录,该目录将作为ModSecurity的临时目录使用。& c1 Y$ B$ T. f8 O4 s& I8 E; X
% c& Y4 N+ R" W9 {/ ~8 Q1 q9 q- B1 X- y( O, H5 H) z! I, x
在 owasp-modsecurity-crs/rules 下有很多定义好的规则,将需要启用的规则用Include指令添加进来就可以了。; [) J3 A! {) [( D! u9 I+ I' O9 I$ p
! {, `1 [+ Z% E8 J }% c! ?$ N) `, c0 T7 W9 X9 j5 @( [/ p
3.x版本CRS
( v t7 b- D- M6 M1 p' I$ cd /usr/local/nginx/conf/owasp-modsecurity-crs( d& L7 I4 s1 n* k% r0 N- {5 g: {
# 生成例外排除请求的配置文件
* Q2 v* H3 I" p$ cp rules/REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf.example rules/REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf, p: @5 o& @, |5 G |5 K: C8 ]" g
$ cp rules/RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf.example rules/RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf3 i/ v; J# W, K8 n+ _/ S+ u* S* h( j
$ cp rules/*.data /usr/local/nginx/conf
. L- k. O* E V$ T5 [为了保持modsecurity.conf简洁,这里新建一个modsec_includes.conf文件,内容为需要启用的规则。
0 D) u6 I9 v/ p' v/ ?8 A9 y+ N6 J5 A; I' [
# Y- w* u/ t8 e% M
$ vim /usr/local/nginx/conf/modsec_includes.conf6 I8 B) W* V0 K m0 E) m8 @
6 T% t+ r# o2 ^" c$ s- A2 p0 B[Bash shell] 纯文本查看 复制代码 include modsecurity.conf
include owasp-modsecurity-crs/crs-setup.conf
include owasp-modsecurity-crs/rules/REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf
include owasp-modsecurity-crs/rules/REQUEST-901-INITIALIZATION.conf
Include owasp-modsecurity-crs/rules/REQUEST-903.9002-WORDPRESS-EXCLUSION-RULES.conf
include owasp-modsecurity-crs/rules/REQUEST-905-COMMON-EXCEPTIONS.conf
include owasp-modsecurity-crs/rules/REQUEST-910-IP-REPUTATION.conf
include owasp-modsecurity-crs/rules/REQUEST-911-METHOD-ENFORCEMENT.conf
include owasp-modsecurity-crs/rules/REQUEST-912-DOS-PROTECTION.conf
include owasp-modsecurity-crs/rules/REQUEST-913-SCANNER-DETECTION.conf
include owasp-modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf
include owasp-modsecurity-crs/rules/REQUEST-921-PROTOCOL-ATTACK.conf
include owasp-modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf
include owasp-modsecurity-crs/rules/REQUEST-931-APPLICATION-ATTACK-RFI.conf
include owasp-modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf
include owasp-modsecurity-crs/rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf
include owasp-modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf
include owasp-modsecurity-crs/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf
include owasp-modsecurity-crs/rules/REQUEST-943-APPLICATION-ATTACK-SESSION-FIXATION.conf
include owasp-modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf
include owasp-modsecurity-crs/rules/RESPONSE-950-DATA-LEAKAGES.conf
include owasp-modsecurity-crs/rules/RESPONSE-951-DATA-LEAKAGES-SQL.conf
include owasp-modsecurity-crs/rules/RESPONSE-952-DATA-LEAKAGES-JAVA.conf
include owasp-modsecurity-crs/rules/RESPONSE-953-DATA-LEAKAGES-PHP.conf
include owasp-modsecurity-crs/rules/RESPONSE-954-DATA-LEAKAGES-IIS.conf
include owasp-modsecurity-crs/rules/RESPONSE-959-BLOCKING-EVALUATION.conf
include owasp-modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf
include owasp-modsecurity-crs/rules/RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf % L) n# e/ O3 M: u) X
7 f; U1 [9 F$ J7 U \5 B注:考虑到可能对主机性能上的损耗,可以根据实际需求加入对应的漏洞的防护规则即可。* V: T% @1 I; n1 X" Q; U1 `2 g& o
% v% W' n5 U4 l8 h; h) g4 s5 n/ r- T5 q" y5 z
配置Nginx支持Modsecurity
( }0 b3 c4 Y/ K' J0 k' R启用Modsecurity
( D8 A8 _$ F5 s0 r! g: U0 H使用静态模块加载的配置方法/ ?9 Q' P4 P; q' [3 s% E" a4 I
在需要启用Modsecurity的主机的location下面加入下面两行即可:- z o. M0 |( Y/ Z0 O" r+ x" [* O4 A
- H$ X. G9 ~# _. p0 |% ~& Q M. b# u; C8 s( c4 i$ N- A5 `: H
ModSecurityEnabled on;
8 X% I) ]2 H. k4 v7 G- tModSecurityConfig modsec_includes.conf;4 a; x$ o( A5 ]+ x3 @
修改Nginx配置文件,在需要启用Modsecurity的location开启Modsecurity。
+ t+ M; t: o/ I2 _0 W3 b' A8 i
& y, _; l" R2 R2 q# @4 y- a; Q. H) m
# k( ~9 u# N4 M$ vim /usr/local/nginx/conf/nginx.conf. {, {+ |3 x6 S
& v! r) \6 S& C; f
! m) C5 V% g, r) ]/ `0 Userver {+ j% b/ ]" `8 H" z) {/ @
listen 80;7 j# `5 f# w9 l4 k! J
server_name example.com;
3 U5 k; M$ E" \$ j
' Z- m R0 C- M; B& U+ L
% V6 x" X" Y# j3 S location / {/ a# Y$ O5 D$ S' J1 g* d. R! o
ModSecurityEnabled on;+ e) S, |: m1 O0 ]9 x& O. [
ModSecurityConfig modsec_includes.conf;
( [! r- _, A: g( N' L% ?6 { root html;
* P9 S/ B6 @% i6 S. j/ K0 w% _ index index.html index.htm;8 {6 w4 L1 n( y! P. O/ Z: ^9 ~5 r* l
}* A5 c0 S9 r+ }0 e0 c
}; s! F" C% ]* z2 Z! n, o. a* o
使用动态模块加载的配置方法% H3 B" L$ j, J z% E. J1 H
在需要启用Modsecurity的主机的location下面加入下面两行即可:( j7 v, K/ z3 y, \% L
) O) Q+ G3 ?& P& ]& s' v- u* w( |; j! T$ U- \
modsecurity on;
; h. F- b; M5 E( p# J* Zmodsecurity_rules_file modsec_includes.conf;
+ i& p# [. }: E& B* z修改Nginx配置文件,在需要启用Modsecurity的location开启Modsecurity。/ _* W. F" g# T5 F# `0 t! h! P8 l
! D: B, f; i4 y$ h, O0 ]4 f/ X) H1 O. d
$ vim /usr/local/nginx/conf/nginx.conf4 j, C8 e( x% o! Z8 S) {2 n
+ z3 ]5 A# z; Y* Z3 x4 I* ^
1 K8 T( R9 B+ V* W7 Bserver {
. }8 Z; W; y5 q6 {- v listen 80;
/ S% B0 U0 U# t) ? server_name localhost mike.hi-linux.com;
; e7 j( e# s, q- p$ O: K4 e4 } access_log /var/log/nginx/yourdomain.log;" y# h) N- o' t2 j8 {5 E0 J
) Q' A4 U: x: ?7 X
5 _, n! ~3 Z* }
location / {0 ]3 y+ Q. e% Z+ R% K# F; v4 ^
# `# j, _) ~! n# I, ~8 s A- K5 v8 R3 ]8 M8 o$ l
modsecurity on;
* @: B9 L$ i1 _0 C modsecurity_rules_file modsec_includes.conf;
% E/ {4 _0 u' R0 E2 k3 m5 }' w+ Z root html;
0 Z& G4 J, ^' V8 O1 Q5 b index index.html index.htm;1 L# `* j) T( @" A4 a% u
}9 e0 Z7 y. Z: }
}
# n7 x7 |6 t9 w* O1 { `验证Nginx配置文件 U9 z$ t! P6 O1 `
$ /usr/local/nginx/sbin/nginx -t
$ O+ L. j3 @/ u: O8 t( Y3 @nginx: the configuration file /usr/local/nginx/conf/nginx.conf syntax is ok$ ~ I& }% h- X7 m
nginx: configuration file /usr/local/nginx/conf/nginx.conf test is successful" q& I+ Z. A: I8 u
启动Nginx
2 s* H# J* y2 B6 |, x$ /usr/local/nginx/sbin/nginx -c /usr/local/nginx/conf/nginx.conf$ T% i' |- X' ^5 f e
4 n& a x5 {) ]" V" R, o3 h
测试Modsecurity ModSecurity现在已经成功配置了OWASP的规则。现在我们将测试对一些最常见的Web应用攻击。来测试ModSecurity是否挡住了攻击。这里我们启用了XSS和SQL注入的过滤规则,下面的例子中不正常的请求会直接返回403。 在浏览器中访问默认首页,会看到Nginx默认的欢迎页: [/url] 这时我们在网址后面自己加上正常参数,例如: 。同样会看到Nginx默认的欢迎页: [url=http://img.colabug.com/2017/06/842f48f203c6c2cd30144f29b57af97a.png] 接下来,我们在前面正常参数的基础上再加上 ,整个请求变成: [/url] 就会看到Nginx返回403 Forbidden的信息了,说明Modsecurity成功拦截了此请求。再来看一个的例子,同样会被Modsecurity拦截。 [url=http://img.colabug.com/2017/06/246ce28e95310a32f791893d4f5c55ca.png] 查看Modsecurity日志 [url=http://img.colabug.com/2017/06/ae44dcb58b8a4a0ea761317e398b3101.png][/url] 所有命中规则的外部攻击均会存在modsec_audit.log,用户可以对这个文件中记录进行审计。Log文件位置在modsecurity.conf中SecAuditLog选项配置,Linux默认在 /var/log/modsec_audit.log 。 $ cat /usr/local/nginx/conf/modsecurity.confSecAuditLog /var/log/modsec_audit.logModsecurity主要是规则验证(验证已知漏洞),Nginx下还有另一个功能强大的WAF模块Naxsi。Naxsi最大特点是可以设置学习模式,抓取您的网站产生必要的白名单,以避免误报!Naxsi不依赖于预先定义的签名,Naxsi能够战胜更多复杂/未知/混淆的攻击模式。 5 w/ W" P+ I- q) j" R' F* B1 y! g
|