This article briefly introduces WAF, then discusses some mainstream WAF bypass technologies, and demonstrates how to try to bypass WAF protection and successfully attack its backend Web applications based on real cases, finally, the security of WAF is summarized to tell readers how to look at WAF products with a correct and rational view.
This article consists of four parts,
I. Brief Introduction to WAF, which gives readers a general idea about WAF products;
2. demonstrate through examples how to use WAF to provide security protection for its backend Web applications;
3. Discuss the security of WAF, introduce some mainstream WAF bypass technologies, and use real cases to demonstrate how to try to bypass WAF protection and successfully attack its backend Web applications;
4. Summarize the security of WAF and tell readers how to look at WAF products with a correct and rational view.
WAF Introduction
The Chinese name of WAF (Web Application Firewall) is "Web Application Firewall". The definition of WAF is as follows: web Application Firewall is a product that provides protection for Web applications by executing a series of HTTP/HTTPS security policies. From the definition of WAF, we can clearly understand: WAF is a product that works at the application layer and provides security protection for Web applications through specific security policies.
WAF can be divided into multiple types based on different classification methods. WAF is divided into the following three categories:
Hardware
In the current security market, most WAF instances belong to this category. They exist in the form of an independent hardware device and support multiple methods (such as transparent bridging mode, bypass mode, reverse proxy, etc.) to be deployed in the network to provide security protection for the backend Web applications. Compared with WAF for software products, WAF has good performance, comprehensive functions, and supports multiple deployment modes. However, it is usually expensive. WAF manufactured by lumeng, anheng, and Qiming stars in China belongs to this category.
Software Products
This type of WAF is implemented by means of pure software. It features simple installation, easy to use, and low cost, but its disadvantages are also obvious-because it must be installed on the Web application server, in addition to performance restrictions, there may also be compatibility, security, and other issues. Representatives of such WAF include ModSecurity, Naxsi, and website security dog.
Cloud-based WAF
With the rapid development of cloud computing technology, it is possible to implement cloud-based WAF. The security products under the innovation workshop in China and 360 of website treasures are typical representatives of such WAF. It has the advantages of Fast deployment, Zero maintenance, and low cost, which is very attractive for small and medium-sized enterprises and personal webmasters.
Use WAF to protect Web Applications
Here, we take Naxsi as an example to demonstrate how to use WAF to provide security protection for its backend Web applications. Naxsi is an open-source, efficient, and low-maintenance Nginx web application firewall module. The main goal of Naxsi is to help people reinforce their web applications, to defend against SQL injection, cross-site scripting, cross-domain forgery requests, local and remote file inclusion vulnerabilities, etc., see http://code.google.com/p/naxsi/wiki/TableOfContents? Tm = 6. Here we will not detail it because of the length. This article describes how to install, configure, and protect Naxsi.
Deployment Architecture
1. Configure Nginx as a reverse proxy so that the traffic to the backend Web server passes through Nginx
2. Enable Nasxi (WAF) to detect Nginx traffic and block the attack traffic according to the relevant configuration to protect applications running on backend Web servers.
The user's normal access request processing process is shown in 1:
Figure 1
The attacker's malicious request processing process is shown in Figure 2:
Figure 2
Nginx + Naxsi Installation
Installation package:
Nginx 1.3.15: http://nginx.org/download/nginx-1.3.15.tar.gz
Naxsi 0.50: http://naxsi.googlecode.com/files/naxsi-core-0.50.tgz
Pcre-8.32: http://sourceforge.net/projects/pcre/files/pcre/8.32/pcre-8.32.tar.gz/download
Installation Process:
Install necessary support components
Install necessary support components before installing Nginx. Otherwise, Nginx cannot be installed normally.
Pcre installation process:
[Root @ localhost LNMP] # wget http://sourceforge.net/projects/pcre/files/pcre/8.32/pcre-8.32.tar.gz/download
[Root @ localhost LNMP] # tar-zxvf pcre-8.32.tar.gz
[Root @ localhost nginx-1.3.15] # cd pcre-8.32
[Root @ localhost pcre-8.32] #./configure
[Root @ localhost pcre-8.32] # make & make install
Install the zlib library components:
[Root @ localhost LNMP] # yum-y install zlib-devel
Nginx and Naxsi Installation Process
[Root @ localhost LNMP] # wget http://nginx.org/download/nginx-1.3.15.tar.gz
[Root @ localhost LNMP] # wget http://naxsi.googlecode.com/files/naxsi-core-0.50.tgz
[Root @ localhost LNMP] # tar-zxvf nginx-1.3.15.tar.gz
[Root @ localhost LNMP] # tar-zxvf naxsi-core-0.50.tgz
[Root @ localhost LNMP] # cd nginx-1.3.15
[Root @ localhost nginx-1.3.15] #./configure -- add-module = ../naxsi-core-0.50/naxsi_src
[Root @ localhost nginx-1.3.15] # make & make install
Start Nginx and test it, as shown in 3:
/Usr/local/nginx/sbin/nginx # Start Nginx
/Usr/local/nginx/sbin/nginx-t # test whether the configuration file is normal
Killall-9 nginx # Kill nginx Process
Kill-HUP 'cat/usr/local/www/nginx/logs/nginx. Pi' # restart Nginx smoothly
Figure 3
If error 4 is prompted when Nginx is started,
Figure 4
You can solve the problem as follows:
32-bit system [root @ localhost lib] # ln-s/usr/local/lib/libpcre. so.1/lib
64-bit system [root @ localhost lib] # ln-s/usr/local/lib/libpcre. so.1/lib64
Configuration process
This configuration is divided into two steps: 1. Modify Nginx. conf configuration file. Configure the options related to Naxsi (WAF). 2. Configure Nginx as a reverse proxy to provide protection for the backend Web server.
Configure Naxsi
First, copy the core configuration rule library of Naxsi to the directory where the Nginx file is located, 5:
Figure 5
Then modify the Nginx. conf configuration file and add the following configuration to it to include the core rule repository file of Naxsi, 6:
Figure 6
Then define a security rule for a VM. refer to the following content:
LearningMode; # Enables learning mode
SecRulesEnabled;
# SecRulesDisabled;
DeniedUrl "/RequestDenied ";
Include "/tmp/naxsi_rules.tmp ";
# Check rules
CheckRule "$ SQL> = 8" BLOCK;
CheckRule "$ RFI> = 8" BLOCK;
CheckRule "$ TRAVERSAL> = 4" BLOCK;
CheckRule "$ EVADE> = 4" BLOCK;
CheckRule "$ XSS> = 8" BLOCK;
Save the above content in a file, such as test. rules, which will be used below.
Customize a blocking page. When WAF detects an attack, it returns the page to the user. See the following content:
<Html>
<Head>
<Title> Error 403 Request Denied </title>
</Head>
<Body>
<H2> Error 403 Request Denied
For some reasons, your request has been denied.
</Body>
</Html>
Configure reverse proxy
Create a configuration file for the VM, as shown in figure 7:
Figure 7
Finally, modify Nginx. conf to include the defined virtual host configuration file, which is 8.
Figure 8
After the Nginx service is restarted, the configuration takes effect.
Demonstration of Protection Effect
When WAF is not used, it does not have attack protection capabilities, such as 9, figure 10, and Figure 11.
Figure 9
Figure 10
Figure 11
After WAF is used, malicious attacks are blocked, as shown in figure 12, figure 13, and Figure 14.
Figure 12
Figure 13
Figure 14
WAF Security
As a security product, WAF provides security protection for Web applications, which increases the difficulty and cost of attacks. However, WAF is not omnipotent. No security product in the world can provide 100% security protection. Because of the product design and implementation principles and other problems, attackers may successfully bypass WAF protection to attack backend Web applications. In addition to the security of WAF, the most discussed here is the WAF bypass technology.
Before introducing the WAF bypass technology, we must understand the problem, that is, why does WAF have the risk of being bypassed? This is because there is a difference between WAF's data packet parsing and Web server's data packet parsing, so there is a possibility of being bypassed. The following lists some mainstream WAF bypass technologies in the SQL Injection Process:
1. Convert the case sensitivity of feature characters
2. Bypass with annotations
3. encoding feature character Bypass
4. Separate and override feature characters to bypass
5. Bypass with truncated characters
6. Change the variable location to bypass
7. Domain Name Protection
8. Large data packet Bypass
9. Switch data submission method Bypass
10. HPP (HTTP parameter contamination) Bypass
The WAF bypass technologies listed above are described in detail on the Internet. We will not discuss them here because of the length. Interested readers can find relevant information on their own. Next, we will introduce the WAF bypass through a real case.
WAF bypass technical instance
In a WAF bypass activity held by quickshield some time ago, white hats used various techniques to successfully bypass the WAF of quickshield. The following describes a WAF bypass technique I have discovered:
Cloud WAF of quickshield is deployed before a Web application with the SQL Injection Vulnerability. The traffic to Web applications must first pass through WAF to detect whether attacks exist. If WAF detects malicious attacks, it will return a specific blocking page to the attacker. Otherwise, a normal page is returned.
1. First, use the classic "and 1 = 1" to determine whether the Web application has the SQL injection vulnerability. Because the front-end has WAF protection, the request should be intercepted by WAF under normal circumstances. As expected, when we send a request with attack characteristics, it is blocked by WAF and a 405 error page is returned, 15.
2. Now we try to convert the GET request to POST, and attach an attack string to the POST request to determine whether the request is intercepted by WAF. Result 16.
Figure 16
3. In Figure 16, we can see that the request is not blocked by WAF, but the normal Web page of the Web application is returned, indicating that we have successfully bypassed WAF. However, at this point, we only confirmed that the Web application has the SQL injection vulnerability. Next, we will try to construct an SQL statement to extract information about the Web application database. Result 17.
Figure 17
4. Through the test above, we can confirm that after converting the GET request to POST, we can successfully bypass WAF detection and obtain the relevant information and data of the target Web application. In addition, other WAF may have the same problem.
Summary
Through the above introduction and corresponding instance demonstrations, I believe everyone has a comprehensive understanding of WAF. So what should we look at such products as WAF? Two extreme understandings are incorrect. 1. After deploying WAF, you can rest assured that you do not have to worry about security issues. 2. WAF is useless because it may be bypassed.
Why are these two ideas incorrect? First of all, as a security product, WAF protects against general-purpose attacks and generally acts as a virtual patch. The WAF implementation principles, technical capabilities, models, and other reasons vary in terms of performance and protection capabilities. WAF can defend against most common attacks and block a large number of attackers. This is undeniable. Otherwise, WAF will not have any value. However, for some attackers with strong technical capabilities, WAF cannot block their attacks. They can bypass WAF to launch attacks. Second, security is relative. No security product in the world can provide 100% security protection. Therefore, the author's attitude towards WAF is that there is no need to turn on WAF. It is not as magical as the vendor said, but it does not need to look too lightly at WAF. After all, WAF can block most conventional attacks, it can greatly improve the security of Web applications and is an effective means of Web application protection.