
빠른 WAF "편집증" Doctor 평가 | WAFPARAN01D3 도구
웹 애플리케이션 방화벽 패러노이아 레벨 테스트 도구.
— alt3kx.github.io에서
본질적으로 Paranoia Level(PL, 패러노이아 레벨)은 Core Rule Set의 공격성을 얼마나 강하게 설정할지 정의할 수 있게 해줍니다.
참조: https://coreruleset.org/20211028/working-with-paranoia-levels/
wafparan01d3.py python3 스크립트는 GET 파라미터를 기반으로 HTTP 요청의 서로 다른 부분에 배치된 인코딩된 payload를 사용하여 악성 요청을 수집하며, 평가 결과는 사용자 머신에 생성되는 디버그 리포트 파일 wafparan01d3.log에 기록됩니다.mysql_gosecure.txt로, gosecure의 연구 "A Scientific Notation Bug in MySQL left AWS WAF Clients Vulnerable to SQL Injection"(여기 https://www.gosecure.net/blog/2021/10/19/a-scientific-notation-bug-in-mysql-left-aws-waf-clients-vulnerable-to-sql-injection/ 참조)를 기반으로 합니다. 기본 구성에서 또는 다양한 규칙/ID를 단계적이고 신속하게 비활성화하여 modsecurity를 사용하는 WAF를 서로 다른 패러노이아 레벨로 평가합니다.
Pentesters: 권한 있는 "쉘"을 사용하여 WAF Linux 박스에 제한적으로 접근하는 GreyBox 범위로, DEV/STG/TEST 환경에서 다양한 payload를 전송하며 WAF Apache 구성 파일을 시작/리로드 및 편집할 수 있습니다.보안 책임자: 조직의 각 솔루션에 적용할 WAF 패러노이아 레벨에 대한 최선의 결정을 내립니다. 블루팀: 조직에서 규칙을 집행하고, 최상의 알림을 제공하며, 오탐(false positive) 결과를 줄입니다. 통합업체: 더 깊은 트러블슈팅을 수행하고 규칙을 신속하게 커스터마이징하거나 가상 패치를 생성하여 적절한 WAF 패러노이아 레벨을 정의합니다. 참조: https://www.inmotionhosting.com/support/server/apache/install-modsecurity-apache-module/
$ sudo apt update -y && sudo apt dist-upgrade -y
$ sudo apt-get install build-essential -y
$ sudo apt-get install apache2 -y
$ sudo apt install libapache2-mod-security2 -y
$ sudo apt-get install curl vim gridsite-clients net-tools -y
$ sudo systemctl restart apache2
$ sudo apt-cache show libapache2-mod-security2

$ sudo cp /etc/modsecurity/modsecurity.conf-recommended /etc/modsecurity/modsecurity.conf
다음으로 ModSecurity 감지 모드를 변경합니다. 먼저 cd /etc/modsecurity 폴더로 이동합니다.
2. vi, vim, emacs 또는 nano로 ModSecurity 구성 파일을 편집합니다.
$ sudo vim /etc/modsecurity/modsecurity.conf
SecRuleEngine DetectionOnly가 보일 것입니다. DetectionOnly를 On으로 변경합니다. 원래 값: SecRuleEngine DetectionOnly
새 값: SecRuleEngine On

$ sudo systemctl restart apache2
$ cd ~
$ wget https://github.com/coreruleset/coreruleset/archive/refs/tags/v3.3.2.zip
$ sha1sum v3.3.2.zip && echo ProvidedChecksum
88f336ba32a89922cade11a4b8e986f2e46a97cf v3.3.2.zip
ProvidedChecksum

$ unzip v3.3.2.zip
$ sudo mv coreruleset-3.3.2/crs-setup.conf.example /etc/modsecurity/crs/crs-setup.conf
$ sudo mv coreruleset-3.3.2/rules/ /etc/modsecurity/crs/
$ sudo vim /etc/apache2/mods-enabled/security2.conf
<IfModule security2_module>
# Default Debian dir for modsecurity's persistent data
SecDataDir /var/cache/modsecurity
# Include all the *.conf files in /etc/modsecurity.
# Keeping your local configuration in that directory
# will allow for an easy upgrade of THIS file and
# make your life easier
IncludeOptional /etc/modsecurity/crs-setup.conf
IncludeOptional /etc/modsecurity/rules/*.conf
# Include OWASP ModSecurity CRS rules if installed
#IncludeOptional /usr/share/modsecurity-crs/*.load
</IfModule>

$ sudo vim /etc/apache2/apache2.conf
다음 코드를 복사하여 붙여넣고 저장합니다.
# Include list of ports to listen on
Include ports.conf
Include /etc/modsecurity/modsecurity.conf
Include /etc/modsecurity/crs/crs-setup.conf
Include /etc/modsecurity/crs/rules/*.conf

$ cd /etc/apache2
$ sudo cp mods-available/proxy_http.load mods-enabled
$ sudo cp mods-available/proxy.load mods-enabled/
$ sudo cp mods-available/rewrite.load mods-enabled/
$ sudo systemctl restart apache2
/etc/apache2/ports.conf 편집 $ sudo vim /etc/apache2/ports.conf
다음 코드를 복사하여 붙여넣고 저장합니다.
# If you just change the port or add more ports here, you will likely also
# have to change the VirtualHost statement in
# /etc/apache2/sites-enabled/000-default.conf
Listen 8080
Listen 18080
<IfModule ssl_module>
Listen 443
</IfModule>
<IfModule mod_gnutls.c>
Listen 443
</IfModule>

/etc/apache2/sites-enabled로 이동하여 001-test.conf 파일을 생성합니다. $ cd /etc/apache2/sites-enabled/
$ sudo touch 001-test.conf
$ sudo vim 001-test.conf
다음 코드를 복사하여 붙여넣고 저장합니다.
<VirtualHost *:8080>
ServerName test.domain:8080
SecRuleEngine On
ErrorLog ${APACHE_LOG_DIR}/test_error.log
CustomLog ${APACHE_LOG_DIR}/test_access.log combined
SecAuditLog ${APACHE_LOG_DIR}/test_audit.log