|
|
modsecurity原本是Apache上的一款开源waf,可以有效的增强web安全性,目前已经支持nginx和IIS,配合nginx的灵活和高效,可以打造成生产级的WAF,是保护和审核web安全的利器。+ o# |* C" F% B) t3 q) C) X
1 P# z6 H6 a2 s% _+ w
一.准备工作' V V1 ~# j, v* J: R2 ^
8 E7 F( Y' O, c! h) [- e系统:centos 6.5 64位、 tengine 2.1.0, modsecurity 2.8.0, ]# g( R. {, r. r
$ C# ] ^8 X% u; J9 t. Ctengine : http://tengine.taobao.org/download/tengine-2.1.0.tar.gz
4 n$ r7 O) @3 h d7 h& x: D* g4 S& l! |
modsecurity for Nginx: https://www.modsecurity.org/tarball/2.8.0/modsecurity-2.8.0.tar.gz Q- N6 d% X' U! X! a4 Q1 E
' S% _ \& ^. m; }$ C
OWASP规则集: https://github.com/SpiderLabs/owasp-modsecurity-crs# W; W- L3 ~* R
8 x1 D5 \0 [: w* V) X$ I依赖关系:
+ {4 s, B4 B4 f5 |- m+ w1 U8 Z# m$ ?! Qtengine(nginx)依赖: pcre 、zlib、 openssl, 这三个包centos 6.5 系统源里都有:$ c( V; T% P" ?9 _5 H* m: P
' p2 M/ i9 \& z9 A; v) @yum install zlib zlib-devel openssl openssl-devel pcre pcre-devel6 ` x4 g6 o0 D2 U X/ n
modsecurty依赖的包:pcre httpd-devel libxml2 apr! Q# a( K6 j" z; Q
% c& A; X' J2 ?yum install httpd-devel apr apr-util-devel apr-devel pcre pcre-devel libxml2 libxml2-devel
* F9 E. G" y) i& q5 _, @# L" K二.启用standalone模块并编译
# Q5 R% {' l. @% T8 F/ p6 J3 w* I5 W! a+ W; E, Q, b
下载modsecurity for nginx 解压,进入解压后目录执行:
% m& K ?5 X; j9 z' W: t8 l6 R& K) @1 a: m" D8 o
./autogen.sh
8 W; C0 F" b( ?3 r& B1 \./configure --enable-standalone-module --disable-mlogc7 D1 }, q8 k6 T& F+ H- |
make 5 J" i/ k6 y# s* Y8 _
三.nginx添加modsecurity模块) ~# K4 l" ]; {& n1 }
* X# |- L, _( Q. w
在编译standalone后,nginx编译时可以通过"--add-module"添加modsecurity模块:2 G/ @( w% o5 _4 i* Y7 L
# P9 }$ X- P) q9 f+ C3 i' ]3 g& X
./configure --add-module=/root/modsecurity-2.8.0/nginx/modsecurity/ --prefix=/opt/tengine' \) p. D) j0 s
make && make install {9 I3 S3 p5 z5 e. U" ]
四.添加规则1 S2 y/ t; @5 i: w
; o1 u4 x* v4 N: ^2 G/ b4 rmodsecurity倾向于过滤和阻止web危险,之所以强大就在于规则,OWASP提供的规则是于社区志愿者维护的,被称为核心规则CRS(corerules),规则可靠强大,当然也可以自定义规则来满足各种需求。
8 s5 v* _6 P- G- K8 V" ?: \9 h+ [ s- F! q- q
1.下载OWASP规则:
6 l$ o# {: }; C$ v& h7 B( x8 u$ B: w6 I8 L
git clone https://github.com/SpiderLabs/owasp-modsecurity-crs' M8 [( p- V3 S# {1 u2 m% r3 y
2 Y# N8 r- k7 }+ x+ I
mv owasp-modsecurity-crs /opt/tengine/conf/
) Q l3 U6 _& W
' t* r4 @, d: g; Kcd /opt/tengine/conf/owasp-modsecurity-crs && mv modsecurity_crs_10_setup.conf.example modsecurity_crs_10_setup.conf# B$ r8 T; v+ [
2.启用OWASP规则:/ S" {" o8 `7 A+ X' k
! T4 n% j0 k" _. I( t/ d% ^7 t/ u复制modsecurity源码目录下的modsecurity.conf-recommended和unicode.mapping到nginx的conf目录下,并将modsecurity.conf-recommended重新命名为modsecurity.conf。% H. a% z7 |( Q7 l) H7 y0 d
0 ~, m" v9 Q8 m- [4 P+ P7 z编辑modsecurity.conf 文件,将SecRuleEngine设置为 on
8 k8 K8 s" M1 v7 v9 `% c- ^0 o% D2 m+ Z
owasp-modsecurity-crs下有很多存放规则的文件夹,例如base_rules、experimental_rules、optional_rules、slr_rules,里面的规则按需要启用,需要启用的规则使用Include进来即可。
* h1 R% E& E# i3 v9 C# @1 c/ }! G9 j" \/ y% _( s( Z9 J. i
Include owasp-modsecurity-crs/modsecurity_crs_10_setup.conf7 _& c& q! ~+ P/ [1 o
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_sql_injection_attacks.conf4 A3 ?) G+ y# {; e* ]
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_xss_attacks.conf" n4 u0 P1 J9 B
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_40_generic_attacks.conf2 Q1 U& ^5 }) H1 ]8 K7 m% J3 R% Z$ w
Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_dos_protection.conf. w8 A- V- s1 t9 n( r
Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_brute_force.conf/ _& [" b4 v& @$ S+ f. U
Include owasp-modsecurity-crs/optional_rules/modsecurity_crs_16_session_hijacking.conf
0 P/ a6 D& W H, D7 U' u2 ]五.配置nginx
7 X1 D+ M } s7 u
. E; O6 X0 l7 F在需要启用modsecurity的主机的location下面加入下面两行即可:
+ l2 C( u; J; i" Q: B/ ~# g
% v8 K% a$ K. m' [. g6 hModSecurityEnabled on;
4 {* P$ {( k3 h0 z( }ModSecurityConfig modsecurity.conf;2 _& ^6 t* F3 m* G% O3 {$ ~9 x
下面是两个示例配置,php虚拟主机:
* P4 B( d) Z) p$ G1 l! A
+ K c7 r5 l/ v! a" V' i* fserver {6 R3 L/ q% Y; s8 ?9 a. H- }% q
listen 80;+ }/ R, ?4 G( V4 l
server_name 52os.net www.52os.net;: D$ F6 F' W4 k( T# ~2 e
. M! y4 H; Z' ]% S/ Y location ~ \.php$ {6 Q: ] `# g3 }4 U/ h1 d
ModSecurityEnabled on; + }$ w4 M5 t0 D$ [0 n" E
ModSecurityConfig modsecurity.conf;
9 q0 P B4 Y; a3 h- U7 C6 \" [/ h! u, G
root /web/wordpress;
& _* Z/ P f$ _* C r W index index.php index.html index.htm;
, M- S2 y) z9 X2 E. ?. \4 D , M, d; ]0 A* G$ L2 B$ Q! _
fastcgi_pass 127.0.0.1:9000;
/ x3 u/ A6 X0 k2 q6 V3 { fastcgi_index index.php; f3 z+ ^6 ~! e& i2 i' @. L
fastcgi_param SCRIPT_FILENAME $Document_root$fastcgi_script_name;
. m$ f1 L3 D9 @' g# D/ L include fastcgi_params;
4 W! S; A0 |4 V0 X `% F( h! U }% T( N) ]. b( E8 N+ E0 H! t
}! k: y% L6 ~6 R0 @' x
upstream负载均衡:
) t( U+ W \' W: \( g. ~, [' f
5 t9 `. U+ e1 C9 nupstream 52os.net {
8 }, o! S. k x server 192.168.1.100:8080;
2 z7 U$ L8 V9 t server 192.168.1.101:8080 backup;
3 U* [' h% K. E$ y}
- z. i6 Y' D: y! c, ~# s; J$ D+ K5 U' h7 [ c2 Q2 A9 P
server {
# g0 O, B4 ?2 Z* M* Qlisten 80; o' x* z' I/ l3 n
server_name 52os.net www.52os.net;
* E6 Z, ?; [/ i# l
3 Z f, [7 s/ h% Olocation / {2 T7 t$ f {6 Y
ModSecurityEnabled on; 4 _- Y# T2 j, q) X- S7 W
ModSecurityConfig modsecurity.conf; 3 R8 H) T3 [: D5 w0 P2 A: Q7 `2 {
# F1 s) I1 w& I. s( H( o proxy_pass http://online;
- x0 R- Y! T6 e6 {' }. G& z4 z proxy_redirect off;& T. ] h, ?+ S5 A9 U
proxy_set_header Host $host;
3 C1 _8 `" ]( b! A" ? proxy_set_header X-Real-IP $remote_addr;
9 j y- Z/ O7 H2 o proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;3 I) q6 e/ P) y/ E3 K3 `; [
}
* z% H$ R8 Z7 r5 M# e- L: ? a5 S}$ L: J" p5 r5 f6 S$ s
六.测试
1 c5 U# N" Z# a% p# X6 {/ D" X' z
我们启用了xss和sql注入的过滤,不正常的请求会直接返回403。以php环境为例,新建一个phpinfo.php内容为:; o3 m7 L0 H. l
' s6 t, m7 [! R2 S# _; A
<?php
2 c, x. J$ J0 E6 b phpinfo();
0 Q& Q8 P2 L2 B% t9 ^- A?>/ v& c( @, f, N- j1 X& v/ C/ v
在浏览器中访问:9 [, _1 y; `# C
3 e( ~0 B) I6 o, |1 {( @% O5 nhttp://www.52os.net/phpinfo.php?id=1 正常显示。
+ {& g U& m6 Zhttp://www.52os.net/phpinfo.php?id=1 and 1=1 返回403。" \& n7 t9 {7 C' i# p
http://www.52os.net/phpinfo.php?search=<scritp>alert('xss');</script> 返回403。1 F4 _- H9 j" S) h- o9 a' s" c6 v
说明sql注入和xss已经被过滤了
5 O- J# \; h+ i
& M% g* E( T w七、安装过程中排错
" A2 M; z0 U; K- `9 z
4 I6 \, s( p8 }8 t" O* c1.缺少APXS会报错3 Z) R+ A( r' l& U# p
: X, F" r; j; c; |) S: Hconfigure: looking for Apache module support via DSO through APXS5 X: b0 s5 J1 W$ n, C9 w5 Y
configure: error: couldn't find APXS
( O: A) G8 H) o1 S9 Japxs是一个为Apache HTTP服务器编译和安装扩展模块的工具,用于编译一个或多个源程序或目标代码文件为动态共享对象。
( m$ b. C/ z, \. B) P解决方法:: m$ T0 ~9 @* g0 g9 ~
/ w' D% }1 |, c! \6 \7 }3 Jyum install httpd-devel. X" _! S* c) R% b1 L
2.没有pcre/ S6 z. R- ?- T% `) _3 I
9 o& P! h9 m% _; d C, Iconfigure: *** pcre library not found.
) Z6 R% ]( t/ `0 y/ M1 C& P% s8 b8 i3 cconfigure: error: pcre library is required
! w% l/ `; Z8 g解决方法:
7 N n9 T# u; V6 m- Z, D) I/ K$ Z/ L+ O% _. `! A$ t7 G8 k# A4 \
yum install pcre pcre-devel
; K' g+ ]6 ]3 C9 v4 o- V& f( z' y3.没有libxml2
5 _* T; H0 Y- @# G6 Z5 g9 A- N- \$ J' n# g( l( a1 s+ z
5 I1 v6 |" U( d L4 \* e4 H; _
configure: *** xml library not found.
- @$ o: s- A# zconfigure: error: libxml2 is required
- O0 x( Y2 e# S4 ~( X' m) k解决方法:( T* F# Q6 E9 [3 c+ O6 h
0 ]( B/ V5 K9 m: E f/ \yum install libxml2 libxml2-devel. Z9 W: C' S( G. |9 Z& l' ^
4.执行 /opt/tengine/sbin/nginx -m 时有警告# I& X5 W0 H% W% o/ E
3 G: u6 V7 O% M) E C) M2 hTengine version: Tengine/2.1.0 (nginx/1.6.2)
& Z' q+ E% u# Knginx: [warn] ModSecurity: Loaded APR do not match with compiled!; r6 \# Z& o) `1 K( S. Z* R7 B( g: @
原因:modsecurity编译时和加载时的apr版本不一致造成的,并且会有以下error.log9 t1 U* C+ I, d9 V" z
6 D* ?# L' W* C$ _% U; y2 r
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity for nginx (STABLE)/2.8.0 () configured.
8 [* c, \1 `* a( c( k7 B' m2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: APR compiled version="1.5.0"; loaded version="1.3.9", N; o: X7 S( }! ]" B( y
2015/01/26 02:04:18 [warn] 29036#0: ModSecurity: Loaded APR do not match with compiled!; i% D6 b5 j6 g% }0 q& K0 Z( y
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: PCRE compiled version="7.8 "; loaded version="7.8 2008-09-05"" A3 H! X8 H C Z" S, j" Q/ k
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: LIBXML compiled version="2.7.6"
8 S1 N5 R& y: U+ S+ V! g: |2015/01/26 02:04:18 [notice] 29036#0: Status engine is currently disabled, enable it by set SecStatusEngine to On.6 n+ ]' N" K* Q8 V, t D9 J+ n
解决方法,移除低版本的APR (1.3.9)0 M2 B; X2 b+ H k$ n9 V7 X2 a
, U+ _1 g6 |* s* C2 l% S2 e6 |yum remove apr( Y1 }# z5 u0 h, z6 `
5.Error.log中有: Audit log: Failed to lock global mutex
/ P4 Z6 o+ D1 S
' m# O9 _- d: I2015/01/26 04:15:42 [error] 61610#0: [client 10.11.15.161] ModSecurity: Audit log: Failed to lock
. X: a. Y. ?/ Yglobal mutex: Permission denied [hostname ""] [uri "/i.php"] [unique_id "AcAcAcAcAcAcAcA4DcA7AcAc"]7 V# \& h& T7 J c( j2 V
解决方法:* j9 w6 I( d5 v% W5 j
编辑modsecurity.conf,注释掉默认的SecAuditLogType和SecAuditLog,添加以下内容:
9 C* j7 `: {* p Q: a
# D* A: H) g2 {9 x j, PSecAuditLogDirMode 0777
1 \( L* k/ D' _* WSecAuditLogFileMode 0550- B+ z/ e5 y) e3 i9 q
SecAuditLogStorageDir /var/log/modsecurity, m$ v; O# j1 X& O4 x& D
SecAuditLogType Concurrent
% u, v; d7 ~# c Y参考文章:. d& l% t r! K; ^% {0 Z
https://github.com/SpiderLabs/ModSecurity/wiki/Reference-Manual#Installation_for_NGINX, I% x8 h+ ^4 ?0 f; L8 I
http://drops.wooyun.org/tips/2614 |
|