找回密码
 立即注册

QQ登录

只需一步,快速开始

查看: 12503|回复: 0

利用ModSecurity在Nginx上构建WAF

[复制链接]
发表于 2017-10-19 17:34:51 | 显示全部楼层 |阅读模式
ModSecurity原本是Apache上的一款开源WAF模块,可以有效的增强Web安全性。目前已经支持Nginx和IIS,配合Nginx的灵活和高效可以打造成生产级的WAF,是保护和审核Web安全的利器。3 C4 K# B4 h, d* M1 P

4 d, P& T3 H6 j' b# w$ ~
# Y. c. \" D* \1 R. D/ \* t在这篇文章中,我们将学习配置ModSecurity与OWASP的核心规则集。& I" R5 s" `" N* t
# Y/ g' [8 S9 @4 |
% @. H  _  R# `
什么是ModSecurity
3 d7 }7 j8 x5 s! c. mModSecurity是一个入侵侦测与防护引擎,它主要是用于Web应用程序,所以也被称为Web应用程序防火墙(WAF)。它可以作为Web服务器的模块或是单独的应用程序来运作。ModSecurity的功能是增强Web Application 的安全性和保护Web application以避免遭受来自已知与未知的攻击。
. R2 ?. x. p0 H, ]4 ]) w" ~; |% F3 B) |2 }& j: h
7 R' ^8 g; D1 K' V- Y( Z$ S) _
ModSecurity计划是从2002年开始,后来由Breach Security Inc.收购,但Breach Security Inc.允诺ModSecurity仍旧为Open Source,并开放源代码给大家使用。最新版的ModSecurity开始支持核心规则集(Core Rule Set),CRS可用于定义旨在保护Web应用免受0day及其它安全攻击的规则。
% G# @. f1 `7 o) v3 {8 ^
: A4 ?# o9 C9 @& P1 e3 z
' U1 R1 @, m( E1 JModSecurity还包含了其他一些特性,如并行文本匹配、Geo IP解析和信用卡号检测等,同时还支持内容注入、自动化的规则更新和脚本等内容。此外,它还提供了一个面向Lua语言的新的API,为开发者提供一个脚本平台以实现用于保护Web应用的复杂逻辑。
: `7 f. p. r' M" K3 n1 \- E  b' k2 L' u+ u" j1 Q" p) O% z+ a

* l8 A8 H8 C* g" i% V8 C6 x3 ]官网: https://www.modsecurity.org/
" `& h& i! y7 ^8 Z2 b* B3 M% u1 Y$ g9 z: S( t, `

* z4 z4 n- p: K$ m6 z; [5 V: x什么是OWASP CRS
' W- u3 p2 ~' _( ZOWASP是一个安全社区,开发和维护着一套免费的应用程序保护规则,这就是所谓OWASP的ModSecurity的核心规则集(即CRS)。ModSecurity之所以强大就在于OWASP提供的规则,我们可以根据自己的需求选择不同的规则,也可以通过ModSecurity手工创建安全过滤器、定义攻击并实现主动的安全输入验证。3 B' {  v9 l: V( ^$ M+ k4 U

1 g# h3 O9 X: {# k; ^1 t  S/ F0 _( W4 U4 K6 u4 s/ L
ModSecurity核心规则集(CRS)提供以下类别的保护来防止攻击。/ `( `1 X5 D9 G

# _( |  D* m% j" i& ~
4 a5 A2 I: \( `" m3 N0 mHTTP Protection(HTTP防御)& w. i6 O2 |$ Q+ l+ n
HTTP协议和本地定义使用的detectsviolations策略。
% _- V& Q3 s# \3 x# |7 W6 M  n- v; ]! m$ [6 N, B# N

( u4 k/ f: {9 b+ r7 _Real-time Blacklist Lookups(实时黑名单查询)4 S# A3 ?: R) y
利用第三方IP名单。
* @- ^. X/ ~3 K1 Y4 g
, i; h: N0 |' P7 Z4 @; l# E: k
2 P& n+ x. O5 S# P4 n# EHTTP Denial of Service Protections(HTTP的拒绝服务保护)) C4 m! c, Y1 y# |  j2 s
防御HTTP的洪水攻击和HTTP Dos攻击。9 S8 E( l8 D. k! g
& ~9 W: g$ `3 e8 c* R

4 O7 \4 |4 @; c" _/ O4 \6 o+ yCommon Web Attacks Protection(常见的Web攻击防护)" K1 o, ]6 F& c, F. X
检测常见的Web应用程序的安全攻击。3 H8 H6 F* }$ d

0 j6 r) f- _) U" D6 x% v; m* N9 S6 H/ [; D! ^7 k& Y6 [- N
Automation Detection(自动化检测)6 ?# p* F3 q2 Z$ C
检测机器人,爬虫,扫描仪和其他表面恶意活动。
( I9 Y: ?/ x) C6 K) R2 ^+ X1 ]) |  o' s. q5 Q6 g; H0 q
0 z" X6 Z% T! D+ B" S7 P: `
Integration with AV Scanning for File Uploads(文件上传防病毒扫描)0 p# J. I+ N' n+ o  e- A# a
检测通过Web应用程序上传的恶意文件。& Y' E" p1 \2 h0 b, I6 l8 ?
8 A  V2 ^1 k) V* d. A) z

* p; M6 S9 I, P* uTracking Sensitive Data(跟踪敏感数据)- L3 r+ ~$ g3 Z7 z
信用卡通道的使用,并阻止泄漏。
5 ~' _& G% p6 }8 I1 y+ `
3 v1 O% }1 T. B6 _6 |2 M( M' F/ K9 K7 K8 G; @' g& a, u
Trojan Protection(木马防护)
0 E) _$ u2 O9 o: M* i: Q2 n- g2 k检测访问木马。& N# C: P4 m* i! q/ o  X
# s% ?* O- P4 x: [: i, F
' T7 c/ d; o1 x3 K
Identification of Application Defects(应用程序缺陷的鉴定). n/ V, d9 ~% A% w: t
检测应用程序的错误配置警报。
6 R, E5 W( x' n* J0 T- c! h) |; l9 A/ e7 C% ^( M7 @5 u
7 E! X4 a, [2 b
Error Detection and Hiding(错误检测和隐藏)( d9 ]% P& ]) K7 r
检测伪装服务器发送错误消息。
1 D4 m! o# r8 ^; o0 p$ a* k
; q: s, ], T& f1 O4 Z: @* N' K: l, t* y5 r
安装ModSecurity& u* g% c2 y6 d- F2 O
软件基础环境准备$ f/ @1 U$ v& o8 t# E
下载对应软件包
/ N4 _# F; X2 m$ cd /root" g5 `8 _$ z6 w# F# D' M
$ wget 'http://nginx.org/download/nginx-1.9.2.tar.gz'
- |2 T1 V8 r9 ]- w2 X% Y7 y$ wget -O modsecurity-2.9.1.tar.gz https://github.com/SpiderLabs/ModSecurity/releases/download/v2.9.1/modsecurity-2.9.1.tar.gz
2 A; D: r1 g8 v2 r) n/ m安装Nginx和ModSecurity依赖包
* N& j' D2 ^2 y4 c: h& {6 t3 r- \Centos/RHEL
7 U0 j3 X/ L* }8 |, E" [( V) l  U$ J$ Y0 J  U9 r4 G
6 w5 V) Q+ ~( {3 C* t
$ yum install httpd-devel apr apr-util-devel apr-devel  pcre pcre-devel  libxml2 libxml2-devel zlib zlib-devel openssl openssl-devel; m0 p* g0 u: `7 \3 G5 x- d
Ubuntu/Debian) B+ o/ f- ~+ {- m
, I! R4 V0 g$ ~% i2 ]8 _' h1 {

  Q+ A, G$ f' k7 k3 s* v$ apt-get install libreadline-dev libncurses5-dev libssl-dev perl make build-essential git  libpcre3 libpcre3-dev libtool autoconf apache2-dev libxml2 libxml2-dev libcurl4-openssl-dev g++ flex bison curl doxygen libyajl-dev libgeoip-dev dh-autoreconf libpcre++-dev4 {8 A) T1 v; ?" c( k
编译安装ModSecurity
( w% M8 B3 ^9 J1 X7 s- _Nginx加载ModSecurity模块有两种方式:一种是编译为Nginx静态模块,一种是通过ModSecurity-Nginx Connector加载动态模块。6 i1 B8 p, S" u# O8 s' w

+ m" d0 V1 J" G3 ?/ B0 N# D) a" m. O$ D2 k- c" f* L- V: E8 `$ w
方法一:编译为Nginx静态模块9 @# k8 T! i4 W3 J) V  q: Q8 O6 |8 c

* @1 d# p0 e5 x7 q& }/ [1 l- g
- R5 \7 H) F) I/ ]7 p& p9 k编译为独立模块(modsecurity-2.9.1)
* \' x$ r  D' r8 H9 k' A- Q$ tar xzvf modsecurity-2.9.1.tar.gz
0 ?3 C0 K- x9 [. v$ cd modsecurity-2.9.1/
, I7 P# r" N0 P  Z0 _, y$ ./autogen.sh" \$ d3 U: u$ K) H, y( Z0 T
$ ./configure --enable-standalone-module --disable-mlogc
) @( a8 x! e2 K- R# R, M! k$ make
9 g; E+ m9 g7 G编译安装Nginx并添加ModSecurity模块  G) R+ b* j' ~% }
$ tar xzvf nginx-1.9.2.tar.gz5 k# w8 M2 {$ G
$ cd nginx-1.9.24 l* Q4 R7 l' C' h9 M1 F) l
$ ./configure --add-module=/root/modsecurity-2.9.1/nginx/modsecurity/, Z% T6 ~5 f+ ?6 N: `
$ make && make install
; I9 a% N2 P6 e& L方法二:编译通过ModSecurity-Nginx Connector加载的动态模块9 R' s* D  ^* e0 y
7 ]' S6 _7 K% d
, p0 t! B5 p8 q" c; T2 B4 s5 Y2 @
编译LibModSecurity(modsecurity-3.0)
0 w9 {" h) U; K/ C$ cd /root$ W8 `' u( \" H
$ git clone https://github.com/SpiderLabs/ModSecurity
+ h/ [7 v& R% V$ cd ModSecurity6 t1 r6 y* _& _8 B+ w5 i* {% C9 N
$ git checkout -b v3/master origin/v3/master
! Z: Z0 e1 ]+ L6 f$ sh build.sh
( y! `# X* X- n; \! x. A( Q$ git submodule init# [: p& ]/ D3 b: g  B9 t- e
$ git submodule update  C' ^1 O& N! X  i# g
$ ./configure
* q$ e3 D1 A) c  V. F$ make) v0 w! C3 d, R4 K& x9 v
$ make install" W- V0 X9 p4 c; K0 V
LibModSecurity会安装在 /usr/local/modsecurity/lib 目录下。
2 z* G1 p" T% d9 {6 I" {* `, D: ~5 D5 X- s: r9 H' @6 z8 I& i0 H0 B

& X8 o3 m7 c3 ^" d$ ls /usr/local/modsecurity/lib
+ f' S0 x  S; Y% f# }libmodsecurity.a  libmodsecurity.la  libmodsecurity.so  libmodsecurity.so.3  libmodsecurity.so.3.0.0
: i: E. ]: k& R; m编译安装Nginx并添加ModSecurity-Nginx Connector模块2 |8 \+ E2 F  h6 ]7 Y& e, t7 g: c
使用ModSecurity-Nginx模块来连接LibModSecurity, i) y4 T5 J1 S) l* P
7 H/ r& l& I1 W6 A' I) O
2 E4 [+ F; |, O8 M
$ cd /root. Y: M) i' H8 o
$ git clone https://github.com/SpiderLabs/ModSecurity-nginx.git modsecurity-nginx! B) n  J: V0 w7 V6 I! B4 W. `
$ tar xzvf nginx-1.9.2.tar.gz
! Q$ {8 n7 w' z( F5 U$ cd nginx-1.9.29 w9 S4 G- z( u* O) `5 V  l1 [  @8 `
$ ./configure --add-module=/root/modsecurity-nginx2 M: ~" ]- H8 \  e$ e
$ make4 z' r4 w7 r3 v. v
$ make && make install& P4 x& R: R; H% A" S
添加OWASP规则
5 d( V/ Q) r2 ~, w1 U) |, O+ ~ModSecurity倾向于过滤和阻止Web危险,之所以强大就在于规则。OWASP提供的规则是社区志愿者维护的被称为核心规则CRS,规则可靠强大,当然也可以自定义规则来满足各种需求。
* ?. |4 K! H# ~2 A4 c& m9 \4 l: b6 C8 Y5 y' ?* t0 Y7 V1 _* T& O& Z
: B3 w8 `( x- ^: J
下载OWASP规则并生成配置文件
2 h0 S% }$ i; [- L! r$ git clone https://github.com/SpiderLabs/owasp-modsecurity-crs.git
/ Y& _; `, @1 e5 l/ s$ cp -rf owasp-modsecurity-crs  /usr/local/nginx/conf/. ^& G- W3 b* T! d3 n  o9 E) Z% g& U5 o
$ cd /usr/local/nginx/conf/owasp-modsecurity-crs& z6 n2 Y% E; D- @* L( c
$ cp crs-setup.conf.example  crs-setup.conf
9 b. O; H7 G+ U% C+ A配置OWASP规则
$ e0 `$ P3 ~* V9 B0 T, W  ]( E编辑crs-setup.conf文件
! M0 }- }3 W+ `8 [  `8 }/ U
; J- J4 F* C7 r0 `* o2 v: K) Z" k& S; n; s- ~$ q1 h7 ~/ I; X- Y: i. G
$ sed -ie 's/SecDefaultAction "phase:1,log,auditlog,pass"/#SecDefaultAction "phase:1,log,auditlog,pass"/g' crs-setup.conf
1 w$ }/ C6 S  J( l1 o4 ~: Y8 k# s$ Z$ sed -ie 's/SecDefaultAction "phase:2,log,auditlog,pass"/#SecDefaultAction "phase:2,log,auditlog,pass"/g' crs-setup.conf
7 V- S2 g+ e. J3 k4 `$ sed -ie 's/#.*SecDefaultAction "phase:1,log,auditlog,deny,status:403"/SecDefaultAction "phase:1,log,auditlog,deny,status:403"/g' crs-setup.conf% M2 V8 J. v2 P, U; |7 l
$ sed -ie 's/# SecDefaultAction "phase:2,log,auditlog,deny,status:403"/SecDefaultAction "phase:2,log,auditlog,deny,status:403"/g' crs-setup.conf3 I" }+ I2 U/ J! x7 k# x& P  G
默认ModSecurity不会阻挡恶意连接,只会记录在Log里。修改SecDefaultAction选项,默认开启阻挡。
: n0 W) I% d0 Q; k6 X
* B- b+ m9 v9 _$ F, r9 J% x9 v9 B% x
启用ModSecurity模块和CRS规则
( `! H, q0 V. J' }# L复制ModSecurity源码目录下的modsecurity.conf-recommended和unicode.mapping到Nginx的conf目录下,并将modsecurity.conf-recommended重新命名为modsecurity.conf。
2 M; K" W7 _, Q7 X+ U
$ w* B' {6 l% B2 V/ W$ U. y4 w4 b9 o% ~: r  E0 C5 i$ R
modsecurity.conf-recommended是ModSecurity工作的主配置文件。默认情况下,它带有.recommended扩展名。要初始化ModSecurity,我们就要重命名此文件。) J* }8 I! ~  n6 E/ c0 b8 T
1 h/ ^/ ]! [+ j" t9 m: B3 l# h
1 _& {! h' i' _/ U: X
$ cd /root/modsecurity-2.9.1/# y. D5 \# R1 U2 i5 x' @4 l
$ cp modsecurity.conf-recommended /usr/local/nginx/conf/modsecurity.conf  
; g  t4 H4 A1 P$ U/ e3 N$ cp unicode.mapping  /usr/local/nginx/conf/
! ?! B/ j* y/ w" M9 u  m将SecRuleEngine设置为On,默认值为DetectOnly即为观察模式,建议大家在安装时先默认使用这个模式,规则测试完成后在设置为On,避免出现对网站、服务器某些不可知的影响。
& V; ~7 ^  J. [
: T8 S) Z2 ^( ~& `! x
1 c. E7 T6 h7 {0 C5 _$ vim /usr/local/nginx/conf/modsecurity.conf# l1 r) b9 v+ E) t) R
SecRuleEngine On$ D2 u0 i8 O( Q8 w, J4 I7 A
ModSecurity中几个常用配置说明:$ P; O. L2 e. f
: [" h; y: K$ L+ t
% V( U  X- J' S; H! ~5 j: c
1.SecRuleEngine:是否接受来自ModSecurity-CRS目录下的所有规则的安全规则引擎。因此,我们可以根据需求设置不同的规则。要设置不同的规则有以下几种。SecRuleEngine On:将在服务器上激活ModSecurity防火墙,它会检测并阻止该服务器上的任何恶意攻击。SecRuleEngine Detection Only:如果设置这个规则它只会检测到所有的攻击,并根据攻击产生错误,但它不会在服务器上阻止任何东西。SecRuleEngine Off:这将在服务器上上停用ModSecurity的防火墙。3 h& {' W* D9 W0 Q. D8 y

, ]. t! T; r1 K% l0 b: u! q  P' w0 l! [% Y! h% S- \7 J' W
2.SecRequestBodyAccess:它会告诉ModSecurity是否会检查请求,它起着非常重要的作用。它只有两个参数ON或OFF。
5 A  D, s  i% \' d" ^, o9 M- O+ s* o: b  [+ a& R" o* I' ^
& G5 r3 o% g  W; @4 v. B$ v7 C
3.SecResponseBodyAccess:如果此参数设置为ON,然后ModeSecurity可以分析服务器响应,并做适当处理。它也有只有两个参数ON和Off,我们可以根据求要进行设置。
% v1 ]8 t( z  Q  n9 r' p& ]5 R% b8 X  Z  U+ n

* |- S) c2 e9 A/ O4 ?8 j! D4.SecDataDir:定义ModSecurity的工作目录,该目录将作为ModSecurity的临时目录使用。3 B4 e' g8 k4 Q! d: z# K1 Y: f
% c) q1 d5 x' P- N  ^0 v( C

( z! P) N/ G: J6 @. M4 n在 owasp-modsecurity-crs/rules 下有很多定义好的规则,将需要启用的规则用Include指令添加进来就可以了。  K% g/ h# @9 ]3 F+ F4 Z7 ]$ F

; M1 @/ {+ D, M
2 W- t# V( g2 G! l3 J1 O! N/ b3.x版本CRS2 h  P6 }; q' ]" p2 v9 ?# S& I
$ cd /usr/local/nginx/conf/owasp-modsecurity-crs
8 a+ t, g: y, n$ V& U2 I# 生成例外排除请求的配置文件1 Y7 b$ m" v% b5 }7 Z# P$ C' v
$ cp rules/REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf.example rules/REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf! d/ P# g: ]" \8 s5 o6 j8 B$ [
$ cp rules/RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf.example rules/RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf
, d. p  H( X% C$ cp rules/*.data /usr/local/nginx/conf
% V5 w4 B4 c9 C' n6 {为了保持modsecurity.conf简洁,这里新建一个modsec_includes.conf文件,内容为需要启用的规则。2 o) y! s# |- @, R: N3 Z7 z: j9 `
% G8 i3 h, Z( L+ a  P) `

) d' R  N& [& _- H7 M7 Q; a$ vim /usr/local/nginx/conf/modsec_includes.conf
- v* @. L4 E& d6 e& s( T) J% e4 y' i0 J8 H, k  u' I4 z, Y- W
[Bash shell] 纯文本查看 复制代码
include modsecurity.conf
include owasp-modsecurity-crs/crs-setup.conf
include owasp-modsecurity-crs/rules/REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf
include owasp-modsecurity-crs/rules/REQUEST-901-INITIALIZATION.conf
Include owasp-modsecurity-crs/rules/REQUEST-903.9002-WORDPRESS-EXCLUSION-RULES.conf
include owasp-modsecurity-crs/rules/REQUEST-905-COMMON-EXCEPTIONS.conf
include owasp-modsecurity-crs/rules/REQUEST-910-IP-REPUTATION.conf
include owasp-modsecurity-crs/rules/REQUEST-911-METHOD-ENFORCEMENT.conf
include owasp-modsecurity-crs/rules/REQUEST-912-DOS-PROTECTION.conf
include owasp-modsecurity-crs/rules/REQUEST-913-SCANNER-DETECTION.conf
include owasp-modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf
include owasp-modsecurity-crs/rules/REQUEST-921-PROTOCOL-ATTACK.conf
include owasp-modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf
include owasp-modsecurity-crs/rules/REQUEST-931-APPLICATION-ATTACK-RFI.conf
include owasp-modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf
include owasp-modsecurity-crs/rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf
include owasp-modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf
include owasp-modsecurity-crs/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf
include owasp-modsecurity-crs/rules/REQUEST-943-APPLICATION-ATTACK-SESSION-FIXATION.conf
include owasp-modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf
include owasp-modsecurity-crs/rules/RESPONSE-950-DATA-LEAKAGES.conf
include owasp-modsecurity-crs/rules/RESPONSE-951-DATA-LEAKAGES-SQL.conf
include owasp-modsecurity-crs/rules/RESPONSE-952-DATA-LEAKAGES-JAVA.conf
include owasp-modsecurity-crs/rules/RESPONSE-953-DATA-LEAKAGES-PHP.conf
include owasp-modsecurity-crs/rules/RESPONSE-954-DATA-LEAKAGES-IIS.conf
include owasp-modsecurity-crs/rules/RESPONSE-959-BLOCKING-EVALUATION.conf
include owasp-modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf
include owasp-modsecurity-crs/rules/RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf
- V' m$ y3 T2 I/ u' \4 P

+ G1 X6 z( p9 ?7 g: w' l. j- Q注:考虑到可能对主机性能上的损耗,可以根据实际需求加入对应的漏洞的防护规则即可。- Q: V8 v* B% _9 V0 u' ^7 P3 v' {# O
' O# X8 b. c% y5 m2 h# a

: `- h/ }6 y& m! }) Q配置Nginx支持Modsecurity
% X! {+ a7 e! }$ |& `启用Modsecurity; V' C+ t; F; `  d. F9 e! Z' b
使用静态模块加载的配置方法4 @3 H" b6 ?9 l0 ^& K# s
在需要启用Modsecurity的主机的location下面加入下面两行即可:
0 E, V2 h5 _, J- Z# m9 u' l" P% c7 o

8 ~$ o' Y0 W: }( A/ I1 M7 I6 aModSecurityEnabled on;! u' y5 `* @1 c( S8 u
ModSecurityConfig modsec_includes.conf;1 {& r" U5 ?/ m8 M& U- k& l
修改Nginx配置文件,在需要启用Modsecurity的location开启Modsecurity。& d( s: F9 Y" A# H' S% l3 {' W$ f
! t9 Q9 y3 p5 S* l, X1 U$ E* z
6 V4 }$ X4 a) j
$ vim /usr/local/nginx/conf/nginx.conf( y2 M  n$ n) _2 G7 G7 f% l0 B/ n  F
' d. x* D3 F/ s
- g6 q& V* A$ ?* {- b# c. Y/ l
server {9 ~$ d# {& @+ R. w4 V# k
  listen       80;2 r# B' O3 b( Y- G' s# I
  server_name  example.com;
5 T# n/ S$ _- K( O$ R1 ~. |5 w# u: Y$ X8 U
. J, R) _- l! s5 v2 Y8 d
  location / {
9 u$ k$ [6 v. `- o+ p, B' J    ModSecurityEnabled on;
- n/ O* s8 i: d: d    ModSecurityConfig modsec_includes.conf;
% }# D. G  C4 L5 R- C    root   html;
/ i% O6 y" Z) }7 }; i    index  index.html index.htm;& ^& d2 v! C0 l; ]. l
  }, B( Z2 K6 z4 a' i( ^, P2 @
}
9 \4 v) _9 d) S( k1 o使用动态模块加载的配置方法, V- b- _! t5 S  U8 w' G
在需要启用Modsecurity的主机的location下面加入下面两行即可:
1 w) \0 ^  a0 p* G  K
1 _( z3 q! I8 u0 X/ o* _( @% L% Z
' H# B7 n; S) Hmodsecurity on;
+ j6 M: M! i9 Tmodsecurity_rules_file modsec_includes.conf;" s. q4 U2 b0 y. H! l
修改Nginx配置文件,在需要启用Modsecurity的location开启Modsecurity。! j9 u9 ?7 H, L
) ]/ B0 f7 A* Z
. E. [( O8 z. q4 f% @
$ vim /usr/local/nginx/conf/nginx.conf
' u9 b. @+ v: I% t; I4 ~2 w; v" X, q$ }& c3 L/ v- B
* S, H7 E4 {, j5 r$ p
server {
: Y. o. @9 t. H9 L9 O' ]  listen  80;
0 l2 R' L) n; J5 F- W" x/ m  server_name localhost mike.hi-linux.com;  @1 N) |; ^$ z$ X7 o7 F. o
  access_log /var/log/nginx/yourdomain.log;
4 v4 b5 x, O9 f. d7 N# N$ X' ~3 J6 [/ Z+ o
8 v; G. |' t. G3 j1 x& F
  location / {
6 m8 ^5 o1 w# I  \+ |$ _% x$ R# {3 o1 o, y
! ^4 k) v' F7 g6 h
  modsecurity on;8 `- C7 j$ s' ]; W! o
  modsecurity_rules_file modsec_includes.conf;
# D3 O& t0 s" C/ o$ K. t1 k  root   html;: x# a. b* \6 G- R& }
  index  index.html index.htm;
$ q* ]+ y0 W5 V% `9 X}9 |6 g5 X& E- b6 [( Z- m, n
}
$ x& A) i0 q- D" T' s验证Nginx配置文件/ @' x9 n3 d  d2 s* h! P( F
$ /usr/local/nginx/sbin/nginx -t
; S9 W2 u1 M. E7 B( vnginx: the configuration file /usr/local/nginx/conf/nginx.conf syntax is ok- Y7 _+ O1 S/ Z  t4 I( _4 n8 b
nginx: configuration file /usr/local/nginx/conf/nginx.conf test is successful$ V" p- j; e8 q6 O5 Y
启动Nginx. f3 l  A& h% E
$ /usr/local/nginx/sbin/nginx -c /usr/local/nginx/conf/nginx.conf
. \: B5 v$ v8 V" h+ F% o( R
# s: r. j! k4 |! s

测试Modsecurity

ModSecurity现在已经成功配置了OWASP的规则。现在我们将测试对一些最常见的Web应用攻击。来测试ModSecurity是否挡住了攻击。这里我们启用了XSS和SQL注入的过滤规则,下面的例子中不正常的请求会直接返回403。

在浏览器中访问默认首页,会看到Nginx默认的欢迎页:

[/url]

这时我们在网址后面自己加上正常参数,例如: 。同样会看到Nginx默认的欢迎页:

[url=http://img.colabug.com/2017/06/842f48f203c6c2cd30144f29b57af97a.png]

接下来,我们在前面正常参数的基础上再加上  ,整个请求变成:

[/url]

就会看到Nginx返回403 Forbidden的信息了,说明Modsecurity成功拦截了此请求。再来看一个的例子,同样会被Modsecurity拦截。

[url=http://img.colabug.com/2017/06/246ce28e95310a32f791893d4f5c55ca.png]

查看Modsecurity日志

[url=http://img.colabug.com/2017/06/ae44dcb58b8a4a0ea761317e398b3101.png][/url]

所有命中规则的外部攻击均会存在modsec_audit.log,用户可以对这个文件中记录进行审计。Log文件位置在modsecurity.conf中SecAuditLog选项配置,Linux默认在 /var/log/modsec_audit.log 。

$ cat /usr/local/nginx/conf/modsecurity.confSecAuditLog /var/log/modsec_audit.log

Modsecurity主要是规则验证(验证已知漏洞),Nginx下还有另一个功能强大的WAF模块Naxsi。Naxsi最大特点是可以设置学习模式,抓取您的网站产生必要的白名单,以避免误报!Naxsi不依赖于预先定义的签名,Naxsi能够战胜更多复杂/未知/混淆的攻击模式。


$ a7 C2 p# D* ~0 d! v+ y

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有账号?立即注册

×
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

QQ|Archiver|手机版|小黑屋|第一站论坛 ( 蜀ICP备06004864号-6 )

GMT+8, 2026-10-5 01:45 , Processed in 0.096816 second(s), 22 queries .

Powered by Discuz! X3.5

© 2001-2026 Discuz! Team.

快速回复 返回顶部 返回列表