{"id":32871,"date":"2023-07-31T13:28:31","date_gmt":"2023-10-12T07:35:24","guid":{"rendered":"https:\/\/www.silicloud.com\/zh\/blog\/modsecurity-nginx-%e5%bf%ab%e9%80%9f%e5%85%a5%e9%97%a8%e6%8c%87%e5%8d%97%e5%a4%87%e5%bf%98%e5%bd%95-2\/"},"modified":"2024-04-30T16:17:29","modified_gmt":"2024-04-30T08:17:29","slug":"modsecurity-nginx-%e5%bf%ab%e9%80%9f%e5%85%a5%e9%97%a8%e6%8c%87%e5%8d%97%e5%a4%87%e5%bf%98%e5%bd%95-2","status":"publish","type":"post","link":"https:\/\/www.silicloud.com\/zh\/blog\/modsecurity-nginx-%e5%bf%ab%e9%80%9f%e5%85%a5%e9%97%a8%e6%8c%87%e5%8d%97%e5%a4%87%e5%bf%98%e5%bd%95-2\/","title":{"rendered":"ModSecurity NGINX \u5feb\u901f\u5165\u95e8\u6307\u5357\u5907\u5fd8\u5f55"},"content":{"rendered":"<h1>\u8d77\u521d<\/h1>\n<p>\u7406\u89e3 ModSecurity \u5e76\u4e86\u89e3 CRS \u7684\u66f4\u65b0\u65b9\u6cd5\u3002<br \/>\n\u57fa\u672c\u4e0a\u662f\u6839\u636e ModSecurity NGINX \u5feb\u901f\u5165\u95e8\u6307\u5357\u6240\u505a\u7684\u7b14\u8bb0\u3002<\/p>\n<h1>\u5c06\u4e0b\u5217\u5185\u5bb9\u4ee5\u4e2d\u6587\u91cd\u8ff0\uff0c\u53ea\u9700\u63d0\u4f9b\u4e00\u4e2a\u9009\u9879\uff1a<\/h1>\n<p>\u79ef\u5206<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">ModSecurity \u306f\u30eb\u30fc\u30eb\u306eDB\u3092\u4f7f\u7528\u3059\u308b<\/ul>\n<\/li>\n<\/ul>\n<p>\u7121\u6599\uff1aOWASP ModSecurity Core Rule Set<br \/>\n\u6709\u6599\uff1aTrustwave \u6709\u511f\u30eb\u30fc\u30eb\u30bb\u30c3\u30c8<\/p>\n<p>ModSecurity 2.9 \u307e\u3067\u306f NGINX \u74b0\u5883\u3067\u30d1\u30d5\u30a9\u30fc\u30de\u30f3\u30b9\u306e\u554f\u984c\u304c\u5b58\u5728\u3057\u305f<br \/>\nModSecurity 2.9 \u307e\u3067\u306f Apache \u306b\u5f37\u304f\u7d10\u3065\u3044\u3066\u3044\u305f\u304c\u30013.0 \u4ee5\u964d\u306f\u30b3\u30fc\u30c9\u3092\u66f8\u304d\u63db\u3048\u3001Apache \u7121\u3057\u3067 Nginx \u3068\u30cd\u30a4\u30c6\u30a3\u30d6\u306b\u9023\u643a\u3067\u304d\u308b\u3088\u3046\u306b\u306a\u308b<br \/>\nModSecurity 3.0 \u306e\u30b3\u30a2\u6a5f\u80fd\u306f libmodsecurity \u3068\u547c\u3070\u308c\u308b\u30b9\u30bf\u30f3\u30c9\u30a2\u30ed\u30f3\u30a8\u30f3\u30b8\u30f3\u306b\u79fb\u52d5\u3057\u305f<br \/>\nModSecurity dynamic module \u306f libmodsecurity \u3068 NGINX connector \u3092\u30b7\u30f3\u30b0\u30eb\u30d1\u30c3\u30b1\u30fc\u30b8\u5316\u3057\u3066\u3044\u308b<br \/>\nNGINX Plus distribution \u306f\u30b3\u30f3\u30d1\u30a4\u30eb\u3055\u308c\u305f dynamic module \u3092\u542b\u3080<br \/>\nNGINX OSS \u30e6\u30fc\u30b6\u306f NGINX version \u5909\u66f4\u6642\u306b\u6bce\u56de\u30b3\u30f3\u30d1\u30a4\u30eb\u8981<\/p>\n<h3>NGINX \u5b89\u88c5 ModSecurity \u7684\u6b65\u9aa4<\/h3>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">NGINX(OSS) : \u30b3\u30f3\u30d1\u30a4\u30eb\u8981<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">NGINX Plus : NGINX\u304b\u3089\u63d0\u4f9b\u3055\u308c\u3066\u3044\u308b\u30b3\u30f3\u30d1\u30a4\u30eb\u6e08\u307f ModSecurity 3.0 dynamic module \u3092\u5229\u7528\u53ef\u80fd<\/ul>\n<h3>\u5b89\u88c5NGINX<\/h3>\n<p>\u4e8b\u524d\u7684\u51c6\u5907\u5de5\u4f5c<\/p>\n<pre class=\"post-pre\"><code>apt-get <span class=\"nb\">install<\/span> <span class=\"nt\">-y<\/span> apt-utils autoconf automake build-essential <span class=\"se\">\\<\/span>\r\ngit libcurl4-openssl-dev libgeoip-dev liblmdb-dev libpcre++-dev <span class=\"se\">\\<\/span>\r\nlibtool libxml2-dev libyajl-dev pkgconf wget zlib1g-dev\r\n<\/code><\/pre>\n<p>libmodsecurity \u306f\u5168\u3066\u306e rule \u3068\u6a5f\u80fd\u3092\u542b\u3080\u30b3\u30a2\u30b3\u30f3\u30dd\u30fc\u30cd\u30f3\u30c8<br \/>\n2\u756a\u76ee\u306e\u30b3\u30a2\u30b3\u30f3\u30dd\u30fc\u30cd\u30f3\u30c8\u306f web server \u306b libmodsecurity \u3092\u30ea\u30f3\u30af(\u7d10\u3065\u3051\u308b)\u30b3\u30cd\u30af\u30bf<br \/>\n\u30b3\u30cd\u30af\u30bf\u306f NGINX \u7528\u3068 Apceh \u7528\u3067\u5225\u3005\u306b\u7528\u610f\u3057\u3066\u3044\u308b<\/p>\n<h3>\u7f16\u8bd1 libmodsecurity<\/h3>\n<pre class=\"post-pre\"><code>git clone <span class=\"nt\">--depth<\/span> 1 <span class=\"nt\">-b<\/span> v3\/master <span class=\"nt\">--single-branch<\/span> https:\/\/github.com\/SpiderLabs\/ModSecurity\r\n<span class=\"nb\">cd <\/span>ModSecurity\r\ngit submodule init\r\ngit submodule update\r\n.\/build.sh\r\n.\/Configure\r\nmake\r\nmake <span class=\"nb\">install<\/span>\r\n<\/code><\/pre>\n<h3>\u901a\u8fc7\u5c06 NGINX \u8fde\u63a5\u5668\u4e0b\u8f7d\u548c\u52a8\u6001\u6a21\u5757\u8fdb\u884c\u7f16\u8bd1\u3002<\/h3>\n<pre class=\"post-pre\"><code>wget https:\/\/nginx.org\/download\/nginx-1.23.3.tar.gz\r\n<span class=\"nb\">tar <\/span>zxvf nginx-1.23.3.tar.gz\r\n\r\n<span class=\"nb\">cd <\/span>nginx-1.23.3\r\n.\/configure <span class=\"nt\">--with-compat<\/span> <span class=\"nt\">--add-dynamic-module<\/span><span class=\"o\">=<\/span>..\/ModSecurity-nginx\r\nmake modules\r\n<span class=\"nb\">cp <\/span>objs\/ngx_http_modsecurity_module.so \/etc\/nginx\/modules\r\n<\/code><\/pre>\n<h3>\u4fee\u6539nginx.conf<\/h3>\n<ul class=\"post-ul\">\u30b3\u30f3\u30d1\u30a4\u30eb\u3057\u305f ngx_http_modsecurity_module.so \u3092 nginx.conf \u306b\u8ffd\u8a18<\/ul>\n<pre class=\"post-pre\"><code><span class=\"c\"># cat \/etc\/nginx\/nginx.conf |grep mod<\/span>\r\nload_module modules\/ngx_http_modsecurity_module.so<span class=\"p\">;<\/span>\r\n\r\n<span class=\"c\"># nginx -t<\/span>\r\n2023\/01\/20 03:31:35 <span class=\"o\">[<\/span>notice] 17570#17570: ModSecurity-nginx v1.0.3 <span class=\"o\">(<\/span>rules loaded inline\/local\/remote: 0\/0\/0<span class=\"o\">)<\/span>\r\nnginx: the configuration file \/etc\/nginx\/nginx.conf syntax is ok\r\nnginx: configuration file \/etc\/nginx\/nginx.conf <span class=\"nb\">test <\/span>is successful\r\n\/\/ \u8a2d\u5b9a\u30d5\u30a1\u30a4\u30eb\u78ba\u8a8d\r\n\r\n<span class=\"c\"># nginx -s reload<\/span>\r\n2023\/01\/20 03:32:43 <span class=\"o\">[<\/span>notice] 17571#17571: ModSecurity-nginx v1.0.3 <span class=\"o\">(<\/span>rules loaded inline\/local\/remote: 0\/0\/0<span class=\"o\">)<\/span>\r\n2023\/01\/20 03:32:43 <span class=\"o\">[<\/span>notice] 17571#17571: signal process started\r\n\/\/ \u8a2d\u5b9a\u30d5\u30a1\u30a4\u30eb\u30ed\u30fc\u30c9\r\n<\/code><\/pre>\n<h3>\u8bbe\u7f6e\u540e\u7684\u64cd\u4f5c\u786e\u8ba4<\/h3>\n<pre class=\"post-pre\"><code>cat &lt;&lt;EOF &gt; \/etc\/nginx\/conf.d\/echo.conf\r\nserver {\r\n    location \/ {\r\n        default_type text\/plain;\r\n        return 200 \"Thank you for requesting ${request_uri}\\n\";\r\n    }\r\n}\r\nEOF\r\n\r\n# curl -D - http:\/\/localhost:80 HTTP\/1.1 200 OK\r\n\r\nmkdir \/etc\/nginx\/modsec\r\ncd \/etc\/nginx\/modsec\r\nwget https:\/\/raw.githubusercontent.com\/SpiderLabs\/ModSecurity\/v3\/master\/modsecurity.conf-recommended\r\nmv modsecurity.conf-recommended modsecurity.conf\r\n<\/code><\/pre>\n<h3>ModSecurity\u7684\u914d\u7f6e<\/h3>\n<pre class=\"post-pre\"><code><span class=\"nb\">mkdir<\/span> \/etc\/nginx\/modsec\r\n<span class=\"nb\">cd<\/span> \/etc\/nginx\/modsec\r\nwget https:\/\/raw.githubusercontent.com\/SpiderLabs\/ModSecurity\/v3\/master\/modsecurity.conf-recommended\r\n<span class=\"nb\">mv <\/span>modsecurity.conf-recommended modsecurity.conf\r\n\r\n<span class=\"nb\">sed<\/span> <span class=\"nt\">-i<\/span> <span class=\"s1\">'s\/SecRuleEngine DetectionOnly\/SecRuleEngine On\/'<\/span> \/etc\/nginx\/modsec\/modsecurity.conf\r\n\r\n<span class=\"nb\">cat<\/span> <span class=\"o\">&lt;&lt;<\/span><span class=\"no\">EOF<\/span><span class=\"sh\"> &gt; \/etc\/nginx\/modsec\/main.conf\r\n# Include the recommended configuration\r\nInclude \/etc\/nginx\/modsec\/modsecurity.conf\r\n# A test rule\r\nSecRule ARGS:testparam \"@contains test\" \"id:1234,deny,log,status:403\"\r\n<\/span><span class=\"no\">EOF\r\n\r\n<\/span><span class=\"nb\">cat<\/span> <span class=\"o\">&lt;&lt;<\/span><span class=\"no\">EOF<\/span><span class=\"sh\"> &gt;\/etc\/nginx\/conf.d\/proxy.conf\r\nserver {\r\n    listen 80;\r\n\r\n    modsecurity on;\r\n    modsecurity_rules_file \/etc\/nginx\/modsec\/main.conf;\r\n    \r\n    location \/ {\r\n        proxy_pass http:\/\/localhost:8085;\r\n        proxy_set_header Host <\/span><span class=\"nv\">$host<\/span><span class=\"sh\">;\r\n    }\r\n}\r\n<\/span><span class=\"no\">EOF\r\n\r\n<\/span><span class=\"nb\">cp<\/span> \/ModSecurity\/unicode.mapping \/etc\/nginx\/modsec\/\r\n\r\nnginx <span class=\"nt\">-t<\/span>\r\nnginx <span class=\"nt\">-s<\/span> reload\r\n<\/code><\/pre>\n<h3>OWASP\u6838\u5fc3\u89c4\u5219\u96c6\u5b89\u88c5<\/h3>\n<p>&#8211; CRS3 \u57282016\u5e7411\u6708\u53d1\u5e03\u3002<br \/>\n&#8211; crs-setup.conf.example \u662fCRS\u7684\u4e3b\u8981\u914d\u7f6e\u6587\u4ef6\uff0c\u53ef\u8bbe\u7f6e\u64cd\u4f5c\u6a21\u5f0f\u7b49\u3002<br \/>\n&#8211; rules\/* \u662f\u89c4\u5219\u6587\u4ef6\u5b58\u50a8\u76ee\u5f55\u3002<br \/>\n&#8211; 90x\u6587\u4ef6\u7528\u4e8e\u6392\u9664\u8bef\u62a5\u3002<br \/>\n&#8211; 91x\u6587\u4ef6\u7528\u4e8e\u68c0\u6d4b\u6076\u610f\u5ba2\u6237\u7aef\u7684\u89c4\u5219\u3002<br \/>\n&#8211; 92x\u6587\u4ef6\u7528\u4e8e\u68c0\u6d4b\u534f\u8bae\u8fdd\u89c4\u7684\u89c4\u5219\u3002<br \/>\n&#8211; 93x\u548c94x\u6587\u4ef6\u7528\u4e8e\u68c0\u6d4b\u5e94\u7528\u7a0b\u5e8f\u653b\u51fb\u7684\u89c4\u5219\u3002<br \/>\n&#8211; 95x\u6587\u4ef6\u7528\u4e8e\u68c0\u6d4b\u51fa\u7ad9\u6570\u636e\u6cc4\u9732\u7684\u89c4\u5219\u3002<br \/>\n&#8211; .data\u6587\u4ef6\u7528\u4e8e\u5404\u79cd\u89c4\u5219\u6240\u4f7f\u7528\u7684\u6570\u636e\u3002<br \/>\n&#8211; \u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0cCRS\u4f1a\u963b\u6b625\u5206\u4ee5\u4e0a\u7684\u5f02\u5e38\u5206\u6570\u3002<\/p>\n<h6>\u5728\u5b89\u88c5CRS\u4e4b\u524d\uff0c\u51c6\u5907\u6f0f\u6d1e\u626b\u63cf\u5de5\u5177\u3002<\/h6>\n<pre class=\"post-pre\"><code>git clone https:\/\/github.com\/sullo\/nikto\r\n\r\n<span class=\"nb\">cd <\/span>nikto\r\nperl program\/nikto.pl <span class=\"nt\">-h<\/span> localhost\r\n\r\ngit clone https:\/\/github.com\/coreruleset\/coreruleset \r\n<span class=\"nb\">cp <\/span>crs-setup.conf.example crs-setup.conf\r\n<span class=\"nb\">echo<\/span> <span class=\"s2\">\"Include \/etc\/nginx\/coreruleset\/crs-setup.conf\"<\/span> <span class=\"o\">&gt;&gt;<\/span> \/etc\/nginx\/modsec\/main.conf\r\n<span class=\"nb\">echo<\/span> <span class=\"s2\">\"Include \/etc\/nginx\/coreruleset\/rules\/*.conf\"<\/span> <span class=\"o\">&gt;&gt;<\/span> \/etc\/nginx\/modsec\/main.conf\r\n\/\/ CRS \u3092\u914d\u7f6e\u3057\u3066\u304b\u3089\u518d\u5ea6 nikto \u3092\u5b9f\u884c\u3057\u3066 report \u6570\u306e\u6e1b\u5c11\u3092\u78ba\u8a8d\u3059\u308b\r\n<\/code><\/pre>\n<h3>&#8220;Project Honeypot&#8221;\u662f\u4ec0\u4e48\uff1f<\/h3>\n<p>\u88ab\u79f0\u4e3aIP\u58f0\u8a89\u6570\u636e\u5e93\u3002\u7531\u793e\u533a\u9a71\u52a8\u5e76\u7ba1\u7406\uff0c\u5c06\u53ef\u7591\u7684\u5783\u573e\u90ae\u4ef6\u53d1\u9001\u8005\u3001\u673a\u5668\u4eba\u7b49\u5217\u5165\u540d\u5355\u3002<\/p>\n<h3>\u5173\u4e8eLogging<\/h3>\n<ul class=\"post-ul\">ModSecurity \u306f\u30c7\u30d5\u30a9\u30eb\u30c8\u3067 warning \u53ca\u3073 error \u3092\u30ed\u30ae\u30f3\u30b0\u3059\u308b<\/ul>\n<div>\n<div class=\"post-table\">SectionDescriptionAAudit log header(mandatory)BRequest HeadersCRequest bodyDReservedEResponse bodyFResponse headersGReservedHAudit log trailer, which contains additional dataICompact request body alternative (to part C), which excludes filesJInformation on uploaded filesKContains a list of all rules that mathched for the transactionZFinal boundary (mandatory)<\/div>\n<\/div>\n<h3>\u5728\u8fdb\u884c\u751f\u4ea7\u73af\u5883\u8fc1\u79fb\u4e4b\u524d<\/h3>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">Audit \u30ed\u30b0\u306e\u7121\u52b9\u5316(nginx \u5074\u306e\u30ed\u30b0\u3067\u5341\u5206\u3060\u304b\u3089)<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\u9759\u7684\u30b3\u30f3\u30c6\u30f3\u30c4(.gif|jpg\u7b49)\u306f WAF \u691c\u67fb\u5bfe\u8c61\u304b\u3089\u9664\u5916\u3059\u308b<\/ul>\n<h1>\u6700\u540e<\/h1>\n<p>\u4ecegit\u4e0b\u8f7dModSecurity\u7684CRS\uff0c\u5c06crs-setup.conf.example\u91cd\u547d\u540d\u4e3acrs-setup.conf\u3002<br \/>\n\u53ef\u4ee5\u901a\u8fc7nginx -t &amp; nginx -s reload\u547d\u4ee4\u6765\u52a0\u8f7dCRS\u3002<\/p>\n<p>ModSecurity\u5728\u751f\u4ea7\u73af\u5883\u4e2d\u7684\u8c03\u4f18\u91cd\u70b9\u662f\u7981\u7528\u65e5\u5fd7\u8bb0\u5f55\u3001\u5728Nginx\u4e4b\u524d\u5f15\u5165\u7f13\u5b58\u673a\u5236\u3001\u6392\u9664\u626b\u63cf\u9759\u6001\u5185\u5bb9\uff0c\u4ee5\u53ca\u542f\u7528DDOS\u529f\u80fd\u3002<\/p>\n<p>\u4e0d\u8bba\u5982\u4f55\uff0c\u5148\u901a\u8fc7 DetectionOnly \u8fdb\u884c\u65e5\u5fd7\u786e\u8ba4\uff0c\u7136\u540e\u518d\u8c03\u6574\u5047\u9633\u6027\u7684\u68c0\u6d4b\u7ed3\u679c\u8bbe\u7f6e\u4e3a On\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u8d77\u521d \u7406\u89e3 ModSecurity \u5e76\u4e86\u89e3 CRS \u7684\u66f4\u65b0\u65b9\u6cd5\u3002 \u57fa\u672c\u4e0a\u662f\u6839\u636e ModSecurity NGI [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-32871","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v21.5 (Yoast SEO v21.5) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>ModSecurity NGINX \u5feb\u901f\u5165\u95e8\u6307\u5357\u5907\u5fd8\u5f55 - Blog - Silicon Cloud<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.silicloud.com\/zh\/blog\/modsecurity-nginx-\u5feb\u901f\u5165\u95e8\u6307\u5357\u5907\u5fd8\u5f55-2\/\" \/>\n<meta property=\"og:locale\" content=\"zh_CN\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"ModSecurity NGINX \u5feb\u901f\u5165\u95e8\u6307\u5357\u5907\u5fd8\u5f55\" \/>\n<meta property=\"og:description\" content=\"\u8d77\u521d \u7406\u89e3 ModSecurity \u5e76\u4e86\u89e3 CRS \u7684\u66f4\u65b0\u65b9\u6cd5\u3002 \u57fa\u672c\u4e0a\u662f\u6839\u636e ModSecurity NGI [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.silicloud.com\/zh\/blog\/modsecurity-nginx-\u5feb\u901f\u5165\u95e8\u6307\u5357\u5907\u5fd8\u5f55-2\/\" \/>\n<meta property=\"og:site_name\" content=\"Blog - Silicon Cloud\" \/>\n<meta property=\"article:published_time\" content=\"2023-10-12T07:35:24+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-04-30T08:17:29+00:00\" \/>\n<meta name=\"author\" content=\"\u6e05, \u5b87\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u4f5c\u8005\" \/>\n\t<meta name=\"twitter:data1\" content=\"\u6e05, \u5b87\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 \u5206\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/modsecurity-nginx-%e5%bf%ab%e9%80%9f%e5%85%a5%e9%97%a8%e6%8c%87%e5%8d%97%e5%a4%87%e5%bf%98%e5%bd%95-2\/\",\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/modsecurity-nginx-%e5%bf%ab%e9%80%9f%e5%85%a5%e9%97%a8%e6%8c%87%e5%8d%97%e5%a4%87%e5%bf%98%e5%bd%95-2\/\",\"name\":\"ModSecurity NGINX \u5feb\u901f\u5165\u95e8\u6307\u5357\u5907\u5fd8\u5f55 - Blog - Silicon Cloud\",\"isPartOf\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#website\"},\"datePublished\":\"2023-10-12T07:35:24+00:00\",\"dateModified\":\"2024-04-30T08:17:29+00:00\",\"author\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/1a6ecd3d914d22a5ac32791ffc1fbd8e\"},\"breadcrumb\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/modsecurity-nginx-%e5%bf%ab%e9%80%9f%e5%85%a5%e9%97%a8%e6%8c%87%e5%8d%97%e5%a4%87%e5%bf%98%e5%bd%95-2\/#breadcrumb\"},\"inLanguage\":\"zh-Hans\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.silicloud.com\/zh\/blog\/modsecurity-nginx-%e5%bf%ab%e9%80%9f%e5%85%a5%e9%97%a8%e6%8c%87%e5%8d%97%e5%a4%87%e5%bf%98%e5%bd%95-2\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/modsecurity-nginx-%e5%bf%ab%e9%80%9f%e5%85%a5%e9%97%a8%e6%8c%87%e5%8d%97%e5%a4%87%e5%bf%98%e5%bd%95-2\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\u9996\u9875\",\"item\":\"https:\/\/www.silicloud.com\/zh\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"ModSecurity NGINX \u5feb\u901f\u5165\u95e8\u6307\u5357\u5907\u5fd8\u5f55\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#website\",\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/\",\"name\":\"Blog - Silicon Cloud\",\"description\":\"\",\"inLanguage\":\"zh-Hans\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/1a6ecd3d914d22a5ac32791ffc1fbd8e\",\"name\":\"\u6e05, \u5b87\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/4b2016c18459a605fc469c7566608f5686491baa112d0871ee613f61b7210565?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/4b2016c18459a605fc469c7566608f5686491baa112d0871ee613f61b7210565?s=96&d=mm&r=g\",\"caption\":\"\u6e05, \u5b87\"},\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/author\/qingyu\/\"},{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/modsecurity-nginx-%e5%bf%ab%e9%80%9f%e5%85%a5%e9%97%a8%e6%8c%87%e5%8d%97%e5%a4%87%e5%bf%98%e5%bd%95-2\/#local-main-organization-logo\",\"url\":\"\",\"contentUrl\":\"\",\"caption\":\"Blog - Silicon Cloud\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"ModSecurity NGINX \u5feb\u901f\u5165\u95e8\u6307\u5357\u5907\u5fd8\u5f55 - Blog - Silicon Cloud","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.silicloud.com\/zh\/blog\/modsecurity-nginx-\u5feb\u901f\u5165\u95e8\u6307\u5357\u5907\u5fd8\u5f55-2\/","og_locale":"zh_CN","og_type":"article","og_title":"ModSecurity NGINX \u5feb\u901f\u5165\u95e8\u6307\u5357\u5907\u5fd8\u5f55","og_description":"\u8d77\u521d \u7406\u89e3 ModSecurity \u5e76\u4e86\u89e3 CRS \u7684\u66f4\u65b0\u65b9\u6cd5\u3002 \u57fa\u672c\u4e0a\u662f\u6839\u636e ModSecurity NGI [&hellip;]","og_url":"https:\/\/www.silicloud.com\/zh\/blog\/modsecurity-nginx-\u5feb\u901f\u5165\u95e8\u6307\u5357\u5907\u5fd8\u5f55-2\/","og_site_name":"Blog - Silicon Cloud","article_published_time":"2023-10-12T07:35:24+00:00","article_modified_time":"2024-04-30T08:17:29+00:00","author":"\u6e05, \u5b87","twitter_card":"summary_large_image","twitter_misc":{"\u4f5c\u8005":"\u6e05, \u5b87","\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4":"3 \u5206"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.silicloud.com\/zh\/blog\/modsecurity-nginx-%e5%bf%ab%e9%80%9f%e5%85%a5%e9%97%a8%e6%8c%87%e5%8d%97%e5%a4%87%e5%bf%98%e5%bd%95-2\/","url":"https:\/\/www.silicloud.com\/zh\/blog\/modsecurity-nginx-%e5%bf%ab%e9%80%9f%e5%85%a5%e9%97%a8%e6%8c%87%e5%8d%97%e5%a4%87%e5%bf%98%e5%bd%95-2\/","name":"ModSecurity NGINX \u5feb\u901f\u5165\u95e8\u6307\u5357\u5907\u5fd8\u5f55 - Blog - Silicon Cloud","isPartOf":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/#website"},"datePublished":"2023-10-12T07:35:24+00:00","dateModified":"2024-04-30T08:17:29+00:00","author":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/1a6ecd3d914d22a5ac32791ffc1fbd8e"},"breadcrumb":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/modsecurity-nginx-%e5%bf%ab%e9%80%9f%e5%85%a5%e9%97%a8%e6%8c%87%e5%8d%97%e5%a4%87%e5%bf%98%e5%bd%95-2\/#breadcrumb"},"inLanguage":"zh-Hans","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.silicloud.com\/zh\/blog\/modsecurity-nginx-%e5%bf%ab%e9%80%9f%e5%85%a5%e9%97%a8%e6%8c%87%e5%8d%97%e5%a4%87%e5%bf%98%e5%bd%95-2\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.silicloud.com\/zh\/blog\/modsecurity-nginx-%e5%bf%ab%e9%80%9f%e5%85%a5%e9%97%a8%e6%8c%87%e5%8d%97%e5%a4%87%e5%bf%98%e5%bd%95-2\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\u9996\u9875","item":"https:\/\/www.silicloud.com\/zh\/blog\/"},{"@type":"ListItem","position":2,"name":"ModSecurity NGINX \u5feb\u901f\u5165\u95e8\u6307\u5357\u5907\u5fd8\u5f55"}]},{"@type":"WebSite","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#website","url":"https:\/\/www.silicloud.com\/zh\/blog\/","name":"Blog - Silicon Cloud","description":"","inLanguage":"zh-Hans"},{"@type":"Person","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/1a6ecd3d914d22a5ac32791ffc1fbd8e","name":"\u6e05, \u5b87","image":{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/4b2016c18459a605fc469c7566608f5686491baa112d0871ee613f61b7210565?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/4b2016c18459a605fc469c7566608f5686491baa112d0871ee613f61b7210565?s=96&d=mm&r=g","caption":"\u6e05, \u5b87"},"url":"https:\/\/www.silicloud.com\/zh\/blog\/author\/qingyu\/"},{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/www.silicloud.com\/zh\/blog\/modsecurity-nginx-%e5%bf%ab%e9%80%9f%e5%85%a5%e9%97%a8%e6%8c%87%e5%8d%97%e5%a4%87%e5%bf%98%e5%bd%95-2\/#local-main-organization-logo","url":"","contentUrl":"","caption":"Blog - Silicon Cloud"}]}},"_links":{"self":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/32871","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/comments?post=32871"}],"version-history":[{"count":2,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/32871\/revisions"}],"predecessor-version":[{"id":92954,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/32871\/revisions\/92954"}],"wp:attachment":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/media?parent=32871"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/categories?post=32871"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/tags?post=32871"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}