{"id":33335,"date":"2023-08-23T06:30:20","date_gmt":"2023-03-19T11:21:55","guid":{"rendered":"https:\/\/www.silicloud.com\/zh\/blog\/%e5%b0%86nginx-ingress-controller%e8%bd%ac%e5%8c%96%e4%b8%bawaf%e8%a7%a3%e5%86%b3%e6%96%b9%e6%a1%88%e3%80%82\/"},"modified":"2024-04-30T19:44:10","modified_gmt":"2024-04-30T11:44:10","slug":"%e5%b0%86nginx-ingress-controller%e8%bd%ac%e5%8c%96%e4%b8%bawaf%e8%a7%a3%e5%86%b3%e6%96%b9%e6%a1%88%e3%80%82","status":"publish","type":"post","link":"https:\/\/www.silicloud.com\/zh\/blog\/%e5%b0%86nginx-ingress-controller%e8%bd%ac%e5%8c%96%e4%b8%bawaf%e8%a7%a3%e5%86%b3%e6%96%b9%e6%a1%88%e3%80%82\/","title":{"rendered":"\u5c06NGINX Ingress Controller\u8f6c\u5316\u4e3aWAF\u89e3\u51b3\u65b9\u6848"},"content":{"rendered":"<p>\u8fd9\u7bc7\u6587\u7ae0\u662fNTT\u30b3\u30e0\u30a6\u30a7\u30a2 Advent Calendar 2022\u7b2c19\u5929\u7684\u6587\u7ae0\u3002<br \/>\nhttps:\/\/qiita.com\/advent-calendar\/2022\/nttcomware<\/p>\n<p>\u4f60\u597d\u3002\u6211\u662fNTT Comware\u7684\u6771\u3002<br \/>\n\u5927\u5bb6\u90fd\u5728\u4f7f\u7528Kubernetes(k8s)\u5417\uff1f<\/p>\n<p>\u5728Kubernetes\u4e2d\uff0cNGINX Ingress Controller\u88ab\u8ba4\u4e3a\u662fIngress\u63a7\u5236\u5668\u7684\u4e8b\u5b9e\u6807\u51c6\u3002\u5b9e\u9645\u4e0a\uff0cNGINX Ingress Controller\u5185\u7f6e\u4e86\u4e00\u4e2a\u540d\u4e3aModSecurity\u7684\u5f00\u6e90Web\u5e94\u7528\u9632\u706b\u5899\uff08WAF\uff09\u5b9e\u73b0\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0cModSecurity\u5904\u4e8e\u975e\u8fd0\u884c\u72b6\u6001\uff0c\u4f46\u53ea\u9700\u8fdb\u884c\u76f8\u5173\u8bbe\u7f6e\u5c31\u53ef\u4ee5\u542f\u7528\u5b83\u3002\u56e0\u6b64\uff0c\u60a8\u53ef\u4ee5\u514d\u8d39\u5c06Ingress\u8f6c\u5316\u4e3aWAF\u3002\u8fd9\u662f\u4e00\u4e2a\u4e0d\u80fd\u9519\u8fc7\u7684\u529f\u80fd\u3002<\/p>\n<p>\u90a3\u4e48\uff0c\u5728\u672c\u6587\u4e2d\uff0c\u6211\u5c06\u4ecb\u7ecd\u5982\u4f55\u5728NGINX Ingress Controller\u4e2d\u542f\u7528ModSecurity\u7684WAF\u529f\u80fd\u3002<\/p>\n<p>\u987a\u4fbf\u63d0\u4e00\u4e0b\uff0c\u672c\u6587\u9488\u5bf9\u5df2\u7ecf\u638c\u63e1Kubernetes\u57fa\u672c\u6982\u5ff5\u548c\u64cd\u4f5c\u6280\u5de7\u7684\u7528\u6237\u3002<\/p>\n<h2>\u8bf7\u7559\u610f\u4ee5\u4e0b\u6ce8\u610f\u4e8b\u9879\u3002<\/h2>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">\u672c\u5185\u5bb9\u306b\u3064\u3044\u3066\u306f\u3001\u4e0d\u6b63\u30a2\u30af\u30bb\u30b9\u3092\u52a9\u9577\u3059\u308b\u3082\u306e\u3067\u306f\u3054\u3056\u3044\u307e\u305b\u3093\u3002<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">\u672c\u30da\u30fc\u30b8\u306e\u5185\u5bb9\u306b\u3064\u3044\u3066\u306f\u3001\u60aa\u7528\u3092\u7981\u6b62\u81f4\u3057\u307e\u3059\u3002<\/ul>\n<\/li>\n<\/ul>\n<p>\u3042\u304f\u307e\u3067\u81ea\u8eab\u306e\u30b5\u30a4\u30c8\u306e\u30c6\u30b9\u30c8\u76ee\u7684\u3067\u306e\u5229\u7528\u306b\u9650\u308a\u307e\u3059\u3002<br \/>\n\u60aa\u7528\u3057\u305f\u5834\u5408\u3001\u4e0d\u6b63\u30a2\u30af\u30bb\u30b9\u7981\u6b62\u6cd5\u7b49\u3067\u8a34\u3048\u3089\u308c\u308b\u53ef\u80fd\u6027\u304c\u3054\u3056\u3044\u307e\u3059\u3002<\/p>\n<h2>\u5173\u4e8eOWASP ModSecurity\u6838\u5fc3\u89c4\u5219\u96c6(CRS)\u3002<\/h2>\n<p>\u867d\u7136\u6211\u60f3\u7acb\u5373\u4ecb\u7ecd\u64cd\u4f5c\u6b65\u9aa4\uff0c\u4f46\u5728\u6b64\u4e4b\u524d\uff0c\u8ba9\u6211\u4eec\u7b80\u5355\u4ecb\u7ecd\u4e00\u4e0b\u201cOWASP\u201d\u548c\u201cCRS\u201d\u3002\u82e5\u4f60\u5bf9\u8fd9\u4e9b\u540d\u5b57\u6709\u6240\u4e86\u89e3\uff0c\u53ef\u4ee5\u8df3\u8fc7\u672c\u7ae0\u8282\u3002<\/p>\n<p>ModSecurity\u6839\u636e\u5b9a\u4e49\u4e86\u8bb8\u591a\u5e94\u89c6\u4e3a\u653b\u51fb\u7684\u8bbf\u95ee\u6a21\u5f0f\u7684\u89c4\u5219\u96c6\u6765\u5224\u65ad\u8bbf\u95ee\u662f\u5426\u4e3a\u653b\u51fb\u3002\u5f53\u524d\u7684ModSecurity\u4ec5\u662f\u4e00\u4e2a\u57fa\u4e8e\u89c4\u5219\u96c6\u8fdb\u884c\u5224\u65ad\u7684\u6a21\u5757\uff0c\u89c4\u5219\u96c6\u4e0eModSecurity\u662f\u5206\u5f00\u5f00\u53d1\u548c\u7ef4\u62a4\u7684\u3002<\/p>\n<p>\u5728\u8fd9\u4e2a\u89c4\u5219\u96c6\u4e2d\uff0c\u6700\u5f3a\u5927\u7684\u662f\u7531OWASP\u793e\u533a\u7ef4\u62a4\u7684\u540d\u4e3a&#8221;\u6838\u5fc3\u89c4\u5219\u96c6&#8221;\u7684\u5f00\u6e90\u8f6f\u4ef6\u3002\u5b83\u6709\u65f6\u88ab\u79f0\u4e3a&#8221;OWASP ModSecurity CRS&#8221;\u6216\u7b80\u79f0\u4e3a&#8221;CRS&#8221;\u3002<\/p>\n<p>OWASP\uff08Open Web Application Security Project\uff09 \u662f\u4e00\u4e2a\u5f00\u6e90\u793e\u533a\uff0c\u81f4\u529b\u4e8e\u5728\u8f6f\u4ef6\u548cWeb\u5e94\u7528\u5b89\u5168\u9886\u57df\u8fdb\u884c\u7814\u7a76\u548c\u6307\u5bfc\u6027\u51c6\u5219\u7684\u5236\u5b9a\uff0c\u5f00\u53d1\u6f0f\u6d1e\u8bca\u65ad\u5de5\u5177\uff0c\u4e3e\u529e\u6d3b\u52a8\u7b49\u591a\u65b9\u9762\u7684\u6d3b\u52a8\u3002<\/p>\n<p>\u521a\u521a\u6211\u63d0\u5230\u300cNGINX Ingress Controller\u4e2d\u5df2\u7ecf\u96c6\u6210\u4e86ModSecurity\u300d\uff0c\u4f46\u5b9e\u9645\u4e0a\u66f4\u51c6\u786e\u7684\u8bf4\u6cd5\u662f\u5b83\u5b9e\u9645\u4e0a\u96c6\u6210\u4e86ModSecurity\u548cCRS\u3002<\/p>\n<p>\u56e0\u6b64\uff0c\u4ece\u73b0\u5728\u5f00\u59cb\uff0c\u6211\u5c06\u5c55\u793a\u5728NGINX Ingress Controller\u4e2d\u5f15\u5165\u548c\u542f\u7528ModSecurity + CRS\u7684\u6b65\u9aa4\u3002<\/p>\n<h2>\u73af\u5883\u6761\u4ef6<\/h2>\n<p>\u7b46\u8005\u6240\u7528\u7684\u6e2c\u8a66\u74b0\u5883\u5982\u4e0b\u6240\u793a\u3002\u7121\u8ad6\u5982\u4f55\uff0c\u53ea\u8981\u6709\u904b\u884cNGINX Ingress Controller\u7684k8s\u74b0\u5883\uff0c\u4e0d\u9650\u65bcEKS\uff0c\u90fd\u53ef\u4ee5\u3002<\/p>\n<p>Kubernetes v1.24.7<\/p>\n<p>Amazon EKS\u3092\u7528\u3044\u69cb\u7bc9<\/p>\n<p>NGINX Ingress Controller v1.5.1\u3000\uff08\u3053\u306e\u5f8c\u306e\u624b\u9806\u3067\u5c0e\u5165\uff09<\/p>\n<p>\u30b3\u30f3\u30c6\u30ca\u30a4\u30e1\u30fc\u30b8\uff1aregistry.k8s.io\/ingress-nginx\/controller:v1.5.1<br \/>\n\u540c\u68b1\u30e2\u30b8\u30e5\u30fc\u30eb\uff1a<\/p>\n<p>ModSecurity v3.0.8<br \/>\nOWASP ModSecurity CRS v3.3.4<\/p>\n<h2>\u521b\u5efaModSecurity\u63a8\u8350\u914d\u7f6e\u6587\u4ef6<\/h2>\n<p>\u4f5c\u4e3a\u51c6\u5907\u5de5\u4f5c\uff0c\u6211\u4eec\u5c06\u521b\u5efa\u4e00\u4e2a\u914d\u7f6e\u6587\u4ef6\uff0c\u5176\u4e2d\u5305\u542b\u4e86\u8981\u6784\u5efa\u7684ModSecurity\u7684\u5404\u79cd\u63a8\u8350\u53c2\u6570\u3002<br \/>\n\u539f\u56e0\u662f\uff0cNGINX Ingress Controller\u7684\u5bb9\u5668\u955c\u50cf\u5df2\u7ecf\u5b89\u88c5\u4e86ModSecurity\u548cCRS\uff0c\u5e76\u4e14\u914d\u7f6e\u6587\u4ef6\u5df2\u7ecf\u88ab\u90e8\u7f72\uff0c\u4f46\u662f\u8bf7\u6c42\u6b63\u6587\u7684\u68c0\u6d4b\u662f\u65e0\u6548\u7684\uff0c\u6709\u70b9\u4e0d\u592a\u597d\u3002<br \/>\n\u6b64\u5916\uff0cNGINX Ingress Controller\u8fd8\u53ef\u4ee5\u4f7f\u7528modsecurity-snippet\u6dfb\u52a0\u4efb\u610f\u7684ModSecurity\u914d\u7f6e\uff0c\u4f46\u662f\u8be5\u65b9\u6cd5\u6709\u4e00\u4e2a\u9650\u5236\uff0c\u5373\u4e0d\u80fd\u8d85\u8fc74096\u4e2a\u5b57\u7b26\uff0c\u56e0\u6b64\u65e0\u6cd5\u6dfb\u52a0\u592a\u591a\u7684\u8bbe\u7f6e\u548c\u89c4\u5219\u3002<\/p>\n<p>\u56e0\u6b64\uff0c\u5728\u8fd9\u91cc\uff0c\u6211\u4eec\u5c06\u6839\u636eModSecurity\u793e\u533a\u7684\u5efa\u8bae\u521b\u5efa\u914d\u7f6e\u6587\u4ef6\uff0c\u5e76\u5728ConfigMap\u4e2d\u9644\u52a0\u3002<\/p>\n<p>\u9996\u5148\uff0c\u4f7f\u7528\u4ee5\u4e0b\u547d\u4ee4\u4e0b\u8f7dModSecurity\u793e\u533a\u7684\u63a8\u8350\u5185\u5bb9\u3002<br \/>\n\u201cv3\/master\u201d\u90e8\u5206\u662fModSecurity GitHub\u7684\u5f53\u524d\u9ed8\u8ba4\u5206\u652f\uff082022\/12\uff09\u3002\u8bf7\u6ce8\u610f\uff0c\u6b64\u540e\u53ef\u80fd\u4f1a\u53d1\u751f\u66f4\u6539\uff0c\u8bf7\u786e\u4fdd\u67e5\u770bGitHub\u9996\u9875\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"nv\">$ <\/span>curl <span class=\"nt\">-L<\/span> <span class=\"nt\">-O<\/span> https:\/\/raw.githubusercontent.com\/SpiderLabs\/ModSecurity\/v3\/master\/modsecurity.conf-recommended\r\n<\/code><\/pre>\n<p>\u6211\u628a\u4e0b\u8f7d\u7684ModSecurity\u793e\u533a\u5efa\u8bae\u7a0d\u4f5c\u4fee\u6539\uff0c\u7528\u4e8eNGINX Ingress Controller\u3002\u4fee\u6539\u540e\u7684\u6587\u4ef6\u53e6\u5b58\u4e3acustom-modsecurity.conf\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"nv\">$ <\/span><span class=\"nb\">cat <\/span>modsecurity.conf-recommended | <span class=\"nb\">sed<\/span> <span class=\"se\">\\<\/span>\r\n  <span class=\"nt\">-e<\/span> <span class=\"s2\">\"s\/^SecRuleEngine DetectionOnly\/SecRuleEngine On\/\"<\/span> <span class=\"se\">\\<\/span>\r\n  <span class=\"nt\">-e<\/span> <span class=\"s2\">\"s\/^SecAuditLog <\/span><span class=\"se\">\\\/<\/span><span class=\"s2\">var<\/span><span class=\"se\">\\\/<\/span><span class=\"s2\">log<\/span><span class=\"se\">\\\/<\/span><span class=\"s2\">modsec_audit.log\/SecAuditLog <\/span><span class=\"se\">\\\/<\/span><span class=\"s2\">dev<\/span><span class=\"se\">\\\/<\/span><span class=\"s2\">stdout\/\"<\/span> <span class=\"se\">\\<\/span>\r\n  <span class=\"nt\">-e<\/span> <span class=\"s2\">\"s\/^SecUnicodeMapFile unicode.mapping 20127\/SecUnicodeMapFile <\/span><span class=\"se\">\\\/<\/span><span class=\"s2\">etc<\/span><span class=\"se\">\\\/<\/span><span class=\"s2\">nginx<\/span><span class=\"se\">\\\/<\/span><span class=\"s2\">modsecurity<\/span><span class=\"se\">\\\/<\/span><span class=\"s2\">unicode.mapping 20127\/\"<\/span> <span class=\"se\">\\<\/span>\r\n  <span class=\"nt\">-e<\/span> <span class=\"s2\">\"s\/^SecStatusEngine On\/SecStatusEngine Off\/\"<\/span> <span class=\"se\">\\<\/span>\r\n  <span class=\"nt\">-e<\/span> <span class=\"s1\">'$aSecAuditLogFormat JSON'<\/span> <span class=\"se\">\\<\/span>\r\n  <span class=\"nt\">-e<\/span> <span class=\"s1\">'$aSecRuleRemoveById 920350'<\/span> <span class=\"o\">&gt;<\/span> custom-modsecurity.conf\r\n<\/code><\/pre>\n<p>\u4ee5\u4e0b\u662f\u4e66\u5199\u4fee\u6539\u7684\u8981\u70b9\u3002<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">SecRuleEngine<\/ul>\n<\/li>\n<\/ul>\n<p>\u30c7\u30d5\u30a9\u30eb\u30c8\u306eDetectionOnly\u3067\u306f\u691c\u51fa\u3057\u30ed\u30b0\u51fa\u529b\u3059\u308b\u306e\u307f\u3067\u30a2\u30af\u30bb\u30b9\u306f\u901a\u3059\u305f\u3081\u3001&#8221;On&#8221;\u3068\u3057\u691c\u77e5\u3057\u305f\u653b\u6483\u30a2\u30af\u30bb\u30b9\u3092\u62d2\u5426\u3055\u305b\u308b\u3002<\/p>\n<p>SecAuditLog<\/p>\n<p>ModSecurity\u306e\u30ed\u30b0\u3092\u30b3\u30f3\u30c6\u30ca\u306e\u6a19\u6e96\u51fa\u529b\u306b\u51fa\u529b\u3059\u308b\u3002<\/p>\n<p>SecUnicodeMapFile<\/p>\n<p>unicode.mapping\u306e\u30d1\u30b9\u3092NGINX Ingress Controller\u30a4\u30e1\u30fc\u30b8\u306b\u5408\u308f\u305b\u66f8\u304d\u63db\u3048\u308b\u3002<\/p>\n<p>SecStatusEngine<\/p>\n<p>NGINX\u8d77\u52d5\u6642\u306b\u30b9\u30c6\u30fc\u30bf\u30b9\u30ec\u30dd\u30fc\u30c8\u3092ModSecurity\u30d7\u30ed\u30b8\u30a7\u30af\u30c8\u30c1\u30fc\u30e0\u306b\u9001\u4fe1\u3057\u306a\u3044(Off)\u3002<\/p>\n<p>SecAuditLogFormat<\/p>\n<p>\u30ed\u30b0\u5f62\u5f0f\u3092JSON\u306b\u6307\u5b9a\u3002(\u8ffd\u8a18)<\/p>\n<p>SecRuleRemoveById<\/p>\n<p>CRS\u306e id:920350 \u3068\u3044\u3046\u30eb\u30fc\u30eb\u306f\u3001localhost\u304b\u3089\u306e\u30a2\u30af\u30bb\u30b9\u3092\u62d2\u5426\u3059\u308b\u30eb\u30fc\u30eb\u3060\u304c\u3001k8s\u306e\u5834\u5408\u3001\u5185\u90e8\u30b3\u30f3\u30dd\u30fc\u30cd\u30f3\u30c8\u304b\u3089\u306e\u30a2\u30af\u30bb\u30b9\u304clocalhost\u304b\u3089\u3042\u308b\u305f\u3081\u3053\u306e\u30eb\u30fc\u30eb\u3092\u7121\u52b9\u5316\u3059\u308b\u884c\u3092\u8ffd\u52a0\u3002<\/p>\n<div>\u5728\u8fd9\u91cc\uff0c\u6211\u4eec\u53ea\u8fdb\u884c\u4e86\u5fc5\u8981\u7684\u6700\u5c0f\u66f4\u6539\u6765\u4f7f\u5176\u6b63\u5e38\u8fd0\u884c\uff0c\u4f46\u4e5f\u53ef\u4ee5\u5305\u542b\u5176\u4ed6ModSecurity\u7684\u8c03\u6574\u548c\u81ea\u5b9a\u4e49\u9644\u52a0\u89c4\u5219\u3002<\/div>\n<p>\u4f7f\u7528\u4fee\u6539\u540e\u7684\u6587\u4ef6(custom-modsecurity.conf)\u4f5c\u4e3a\u57fa\u7840\u521b\u5efaConfigMap\u3002\u7136\u540e\u5c06\u6b64ConfigMap\u9644\u52a0\u4e3a\u540e\u7eedNGINX Ingress Controller(Pod)\u7684\u914d\u7f6e\u6587\u4ef6\u3002<br \/>\n\u8bf7\u6839\u636e\u90e8\u7f72NGINX Ingress Controller\u7684\u76ee\u6807\u8fdb\u884c\u9002\u5f53\u66f4\u6539\uff0c\u5c06\u547d\u540d\u7a7a\u95f4\u540d&#8221;ingress-nginx&#8221;\u66ff\u6362\u4e3a\u5408\u9002\u7684\u503c\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"nv\">$ <\/span>kubectl create namespace ingress-nginx\r\n<span class=\"nv\">$ <\/span>kubectl <span class=\"nt\">-n<\/span> ingress-nginx create configmap modsecurity-config <span class=\"se\">\\<\/span>\r\n  <span class=\"nt\">--from-file<\/span><span class=\"o\">=<\/span>custom-modsecurity.conf<span class=\"o\">=<\/span>custom-modsecurity.conf\r\n<\/code><\/pre>\n<h2>\u90e8\u7f72NGINX Ingress Controller<\/h2>\n<p>\u9274\u4e8e\u7b14\u8005\u4f7f\u7528\u7684\u662fAWS\uff08EKS\uff09\u73af\u5883\uff0c\u56e0\u6b64\u5c06\u6309\u7167\u6b64\u73af\u5883\u76f4\u63a5\u6307\u5b9a\u6e05\u5355\u7684\u65b9\u5f0f\u8fdb\u884c\u90e8\u7f72\u3002<\/p>\n<div>\u5982\u679c\u60a8\u4f7f\u7528helm\uff0c\u8bf7\u53c2\u8003\u672c\u6587\u5e95\u90e8\u7684\u201c\u53c2\u8003\uff09\u4f7f\u7528helm\u201d\u7684\u90e8\u5206\u3002<\/div>\n<p>\u9996\u5148\uff0c\u4f7f\u7528\u4ee5\u4e0b\u547d\u4ee4\u4e0b\u8f7dNGINX Ingress Controller\u7684\u6e05\u5355\u6587\u4ef6\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"nv\">$ <\/span>curl <span class=\"nt\">-L<\/span> <span class=\"nt\">-O<\/span> https:\/\/raw.githubusercontent.com\/kubernetes\/ingress-nginx\/controller-v1.5.1\/deploy\/static\/provider\/aws\/deploy.yaml\r\n<\/code><\/pre>\n<p>\u5728deploy.yaml\u6587\u4ef6\u4e2d\uff0c\u6dfb\u52a0\u542f\u7528ModSecurity\u7684\u914d\u7f6e\u548c\u9644\u52a0\u4e4b\u524d\u521b\u5efa\u7684ConfigMap\u201cmodsecurity-config\u201d\u7684\u914d\u7f6e\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"nv\">$ <\/span>vi deploy.yaml\r\n\u2192\u4ee5\u4e0bdiff\u306e\u5185\u5bb9\u3092\u8ffd\u8a18\r\n<\/code><\/pre>\n<p>\u4ee5\u4e0b\u662f\u8ffd\u52a0\u5185\u5bb9\u524d\u540e\u7684\u53d8\u52a8\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"gd\">--- deploy.yaml.org     2022-12-08 10:03:37.083369804 +0900\r\n<\/span><span class=\"gi\">+++ deploy.yaml 2022-12-08 10:07:20.720523517 +0900\r\n<\/span><span class=\"p\">@@ -336,6 +336,10 @@<\/span>\r\n apiVersion: v1\r\n data:\r\n   allow-snippet-annotations: \"true\"\r\n<span class=\"gi\">+  enable-modsecurity: \"true\"\r\n+  enable-owasp-modsecurity-crs: \"true\"\r\n+  modsecurity-snippet: |\r\n+    Include \/etc\/nginx\/owasp-modsecurity-crs\/custom\/custom-modsecurity.conf\r\n<\/span> kind: ConfigMap\r\n metadata:\r\n   labels:\r\n<span class=\"p\">@@ -509,6 +513,8 @@<\/span>\r\n         - mountPath: \/usr\/local\/certificates\/\r\n           name: webhook-cert\r\n           readOnly: true\r\n<span class=\"gi\">+        - mountPath: \/etc\/nginx\/owasp-modsecurity-crs\/custom\/\r\n+          name: modsecurity-config\r\n<\/span>       dnsPolicy: ClusterFirst\r\n       nodeSelector:\r\n         kubernetes.io\/os: linux\r\n<span class=\"p\">@@ -518,6 +524,9 @@<\/span>\r\n       - name: webhook-cert\r\n         secret:\r\n           secretName: ingress-nginx-admission\r\n<span class=\"gi\">+      - name: modsecurity-config\r\n+        configMap:\r\n+          name: modsecurity-config\r\n<\/span> ---\r\n apiVersion: batch\/v1\r\n kind: Job\r\n<\/code><\/pre>\n<p>\u4f7f\u7528\u66f4\u6539\u540e\u7684deploy.yaml\u6587\u4ef6\u8fdb\u884cNGINX Ingress Controller\u7684\u90e8\u7f72\u3002<\/p>\n<div>\u5982\u679c\u60a8\u4e0d\u6253\u7b97\u5c06NGINX Ingress Controller\u7684Service\u8d44\u6e90\u66b4\u9732\u7ed9\u5168\u4e16\u754c\uff0c\u53ef\u4ee5\u8003\u8651\u901a\u8fc7\u5916\u90e8\u8d1f\u8f7d\u5747\u8861\u5668\u9650\u5236\u8bbf\u95ee\u6e90IP\u5730\u5740\u7b49\u65b9\u5f0f\u6765\u5b9e\u73b0\uff08\u4f8b\u5982\u7528\u4e8e\u9a8c\u8bc1\u76ee\u7684\u7b49\u60c5\u51b5\uff09\u3002<\/div>\n<pre class=\"post-pre\"><code><span class=\"nv\">$ <\/span>kubectl apply <span class=\"nt\">-f<\/span> deploy.yaml\r\n<\/code><\/pre>\n<h2>\u786e\u8ba4\u884c\u52a8<\/h2>\n<p>\u5728\u5df2\u542f\u52a8\u7684 NGINX Ingress Controller \u7684 Pod \u5185\u90e8\u6267\u884c &#8220;nginx -T&#8221; \u547d\u4ee4\uff0c\u4ee5\u786e\u8ba4 NGINX \u662f\u5426\u5df2\u52a0\u8f7d ModSecurity \u6a21\u5757\u3002<\/p>\n<p>\u4ee5\u4e0b\u7684\u4ee3\u7801\u5c06\u5728PODNAME\u73af\u5883\u53d8\u91cf\u4e2d\u8bb0\u5f55NGINX Ingress Controller\u7684Pod\u540d\u79f0\uff0c\u5e76\u901a\u8fc7kubectl exec\u6267\u884c\u547d\u4ee4\u3002\u53ef\u4ee5\u786e\u8ba4\u5b58\u5728\u51e0\u884c\u5305\u542b&#8221;ModSecurity&#8221;\u8fd9\u4e2a\u8bcd\u7684\u884c\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"nv\">$ PODNAME<\/span><span class=\"o\">=<\/span><span class=\"si\">$(<\/span> kubectl <span class=\"nt\">-n<\/span> ingress-nginx get pod <span class=\"nt\">-l<\/span> app.kubernetes.io\/component<span class=\"o\">=<\/span>controller <span class=\"nt\">-o<\/span><span class=\"o\">=<\/span><span class=\"nv\">jsonpath<\/span><span class=\"o\">=<\/span><span class=\"s1\">'{.items[0].metadata.name}'<\/span> <span class=\"si\">)<\/span>\r\n<span class=\"nv\">$ <\/span>kubectl <span class=\"nt\">-n<\/span> ingress-nginx <span class=\"nb\">exec<\/span> <span class=\"nt\">-it<\/span> <span class=\"nv\">$PODNAME<\/span> <span class=\"nt\">--<\/span> nginx <span class=\"nt\">-T<\/span> | <span class=\"nb\">grep<\/span> <span class=\"nt\">-i<\/span> modsecurity\r\n2022\/12\/08 02:46:15 <span class=\"o\">[<\/span>notice] 579#579: ModSecurity-nginx v1.0.2 <span class=\"o\">(<\/span>rules loaded inline\/local\/remote: 7\/782\/0<span class=\"o\">)<\/span>\r\nload_module \/etc\/nginx\/modules\/ngx_http_modsecurity_module.so<span class=\"p\">;<\/span>\r\n        modsecurity on<span class=\"p\">;<\/span>\r\n        modsecurity_rules <span class=\"s1\">'\r\n        Include \/etc\/nginx\/owasp-modsecurity-crs\/custom\/custom-modsecurity.conf\r\n        modsecurity_rules_file \/etc\/nginx\/owasp-modsecurity-crs\/nginx-modsecurity.conf;\r\n<\/span><\/code><\/pre>\n<p>\u4e0b\u4e00\u6b65\uff0c\u6211\u4f1a\u5b9e\u9645\u8fdb\u884c\u4e00\u4e9b\u653b\u51fb\u6a21\u62df\uff0c\u5e76\u786e\u4fdd\u5b83\u4eec\u80fd\u591f\u88ab\u6709\u6548\u5730\u9632\u5fa1\u3002\u6211\u5c06\u6839\u636e\u8fd9\u91cc\u63d0\u4f9b\u7684\u6307\u5357\uff0c\u5f15\u5165\u4e00\u6b3e\u4f5c\u4e3aIngress\u540e\u7aef\u7684\u793a\u8303\u5e94\u7528\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"nv\">$ <\/span>kubectl create deployment demo <span class=\"nt\">--image<\/span><span class=\"o\">=<\/span>httpd <span class=\"nt\">--port<\/span><span class=\"o\">=<\/span>80\r\n<span class=\"nv\">$ <\/span>kubectl expose deployment demo\r\n<span class=\"nv\">$ <\/span>kubectl create ingress demo-localhost <span class=\"nt\">--class<\/span><span class=\"o\">=<\/span>nginx <span class=\"se\">\\<\/span>\r\n  <span class=\"nt\">--rule<\/span><span class=\"o\">=<\/span><span class=\"s2\">\"demo.localdev.me\/*=demo:80\"<\/span>\r\n<span class=\"nv\">$ <\/span>kubectl port-forward <span class=\"nt\">--namespace<\/span><span class=\"o\">=<\/span>ingress-nginx service\/ingress-nginx-controller 8080:80\r\n<\/code><\/pre>\n<p>\u4f7f\u7528curl\u7b49\u5de5\u5177\uff0c\u786e\u8ba4\u80fd\u591f\u8bbf\u95ee\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"nv\">$ <\/span>curl http:\/\/demo.localdev.me:8080\/\r\n&lt;html&gt;&lt;body&gt;&lt;h1&gt;It works!&lt;\/h1&gt;&lt;\/body&gt;&lt;\/html&gt;\r\n<\/code><\/pre>\n<p>\u6211\u4f1a\u7528\u4e00\u79cd\u653b\u51fb\u7684\u65b9\u5f0f\u5c1d\u8bd5\u8bbf\u95ee\u8fd9\u4e2a\u793a\u4f8b\u5e94\u7528\u7a0b\u5e8f\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"nv\">$ <\/span>curl <span class=\"nt\">-X<\/span> POST <span class=\"nt\">-d<\/span> <span class=\"s2\">\"cmd=&lt;script&gt;\"<\/span> http:\/\/demo.localdev.me:8080\/\r\n&lt;html&gt;\r\n&lt;<span class=\"nb\">head<\/span><span class=\"o\">&gt;<\/span>&lt;title&gt;403 Forbidden&lt;\/title&gt;&lt;\/head&gt;\r\n&lt;body&gt;\r\n&lt;center&gt;&lt;h1&gt;403 Forbidden&lt;\/h1&gt;&lt;\/center&gt;\r\n&lt;hr&gt;&lt;center&gt;nginx&lt;\/center&gt;\r\n&lt;\/body&gt;\r\n&lt;\/html&gt;\r\n<\/code><\/pre>\n<p>\u8fd4\u56de\u4e86\u201c403 Forbidden\u201d\u3002<\/p>\n<p>\u67e5\u770bNGINX Ingress Controller\u7684\u65e5\u5fd7\uff0c\u53ef\u4ee5\u770b\u5230ModSecurity\u7684\u53cd\u5e94\uff0c\u4f3c\u4e4e\u6210\u529f\u5730\u963b\u6b62\u4e86\u8bbf\u95ee\u3002\u6211\u4eec\u53ef\u4ee5\u786e\u8ba4ModSecurity\u6b63\u5e38\u8fd0\u884c\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"nv\">$ <\/span>kubectl <span class=\"nt\">-n<\/span> ingress-nginx logs <span class=\"nv\">$PODNAME<\/span> | <span class=\"nb\">grep <\/span>ModSecurity:\r\n\u30fb\u30fb\u30fb\r\n2022\/12\/08 03:01:34 <span class=\"o\">[<\/span>error] 844#844: <span class=\"k\">*<\/span>47316 <span class=\"o\">[<\/span>client 127.0.0.1] ModSecurity: Access denied with code 403 <span class=\"o\">(<\/span>phase 2<span class=\"o\">)<\/span><span class=\"nb\">.<\/span> Matched <span class=\"s2\">\"Operator <\/span><span class=\"sb\">`<\/span>Ge<span class=\"s1\">' with parameter `5'<\/span> against variable <span class=\"sb\">`<\/span><span class=\"s2\">TX:ANOMALY_SCORE' (Value: <\/span><span class=\"sb\">`<\/span>15<span class=\"s1\">' ) [file \"\/etc\/nginx\/owasp-modsecurity-crs\/rules\/REQUEST-949-BLOCKING-EVALUATION.conf\"] [line \"81\"] [id \"949110\"] [rev \"\"] [msg \"Inbound Anomaly Score Exceeded (Total Score: 15)\"] [data \"\"] [severity \"2\"] [ver \"OWASP_CRS\/3.3.4\"] [maturity \"0\"] [accuracy \"0\"] [tag \"application-multi\"] [tag \"language-multi\"] [tag \"platform-multi\"] [tag \"attack-generic\"] [hostname \"127.0.0.1\"] [uri \"\/\"] [unique_id \"167046849467.029474\"] [ref \"\"], client: 127.0.0.1, server: demo.localdev.me, request: \"POST \/ HTTP\/1.1\", host: \"demo.localdev.me:8080\"\r\n<\/span><\/code><\/pre>\n<p>\u6b64\u5916\uff0cNGINX Ingress Controller\u7684\u65e5\u5fd7\u4ee5JSON\u683c\u5f0f\u66f4\u8be6\u7ec6\u5730\u8f93\u51fa\u4e86ModSecurity\u7684\u68c0\u6d4b\u7ed3\u679c\u3002<\/p>\n<p>\u4ee5\u4e0b\u662f\u901a\u8fc7\u4f7f\u7528grep\u548cjq\u547d\u4ee4\u5bf9\u4ee5&#8221;^{&#8220;transaction&#8221;: &#8220;\u5f00\u5934\u7684\u884c\u8fdb\u884c\u683c\u5f0f\u5316\u7684\u7ed3\u679c\uff08\u7531\u4e8e\u957f\u5ea6\u8f83\u957f\uff0c\u5df2\u6298\u53e0\uff09\u3002\u60a8\u53ef\u4ee5\u83b7\u53d6\u5230\u8bbf\u95ee\u6765\u6e90\u3001\u54cd\u5e94\u5185\u5bb9\u4ee5\u53ca\u88ab\u68c0\u6d4b\u7684\u89c4\u5219\u548c\u539f\u56e0\u7b49\u8be6\u7ec6\u4fe1\u606f\u3002<\/p>\n<details>\u8a73\u7d30\u65e5\u5fd7<br \/>\n$ kubectl -n ingress-nginx logs $PODNAME | grep &#8216;^{&#8220;transaction&#8221;:&#8217; | jq<br \/>\n{<br \/>\n&#8220;transaction&#8221;: {<br \/>\n&#8220;client_ip&#8221;: &#8220;127.0.0.1&#8221;,<br \/>\n&#8220;time_stamp&#8221;: &#8220;2022\u5e7412\u67088\u65e5\u661f\u671f\u56db 03:01:34&#8221;,<br \/>\n&#8220;server_id&#8221;: &#8220;d0fb58befb07ce0cec85f68d9197f05ab5150f14&#8221;,<br \/>\n&#8220;client_port&#8221;: 34376,<br \/>\n&#8220;host_ip&#8221;: &#8220;127.0.0.1&#8221;,<br \/>\n&#8220;host_port&#8221;: 80,<br \/>\n&#8220;unique_id&#8221;: &#8220;167046849467.029474&#8221;,<br \/>\n&#8220;request&#8221;: {<br \/>\n&#8220;method&#8221;: &#8220;POST&#8221;,<br \/>\n&#8220;http_version&#8221;: 1.1,<br \/>\n&#8220;uri&#8221;: &#8220;\/&#8221;,<br \/>\n&#8220;headers&#8221;: {<br \/>\n&#8220;Host&#8221;: &#8220;demo.localdev.me:8080&#8221;,<br \/>\n&#8220;User-Agent&#8221;: &#8220;curl\/7.61.1&#8221;,<br \/>\n&#8220;Accept&#8221;: &#8220;*\/*&#8221;,<br \/>\n&#8220;Content-Length&#8221;: &#8220;12&#8221;,<br \/>\n&#8220;Content-Type&#8221;: &#8220;application\/x-www-form-urlencoded&#8221;<br \/>\n}<br \/>\n},<br \/>\n&#8220;response&#8221;: {<br \/>\n&#8220;body&#8221;: &#8220;\\r\\n\\r\\n\\r\\n<center><\/p>\n<h1>403 Forbidden<\/h1>\n<p>&nbsp;<\/p>\n<p><\/center>\\r\\n<\/p>\n<hr \/>\n<p><center>nginx<\/center>\\r\\n<\/p>\n<p>\\r\\n\\r\\n&#8221;,<br \/>\n&#8220;http_code&#8221;: 403,<br \/>\n&#8220;headers&#8221;: {<br \/>\n&#8220;Server&#8221;: &#8220;&#8221;,<br \/>\n&#8220;Date&#8221;: &#8220;2022\u5e7412\u67088\u65e5\u661f\u671f\u56db 03:01:34 GMT&#8221;,<br \/>\n&#8220;Content-Length&#8221;: &#8220;146&#8221;,<br \/>\n&#8220;Content-Type&#8221;: &#8220;text\/html&#8221;,<br \/>\n&#8220;Connection&#8221;: &#8220;keep-alive&#8221;<br \/>\n}<br \/>\n},<br \/>\n&#8220;producer&#8221;: {<br \/>\n&#8220;modsecurity&#8221;: &#8220;ModSecurity v3.0.8 (Linux)&#8221;,<br \/>\n&#8220;connector&#8221;: &#8220;ModSecurity-nginx v1.0.2&#8221;,<br \/>\n&#8220;secrules_engine&#8221;: &#8220;Enabled&#8221;,<br \/>\n&#8220;components&#8221;: [<br \/>\n&#8220;OWASP_CRS\/3.3.4\\&#8221;&#8221;<br \/>\n]<br \/>\n},<br \/>\n&#8220;messages&#8221;: [<br \/>\n{<br \/>\n&#8220;message&#8221;: &#8220;\u68c0\u6d4b\u5230XSS\u653b\u51fb(libinjection)&#8221;,<br \/>\n&#8220;details&#8221;: {<br \/>\n&#8220;match&#8221;: &#8220;\u68c0\u6d4b\u5230\u4f7f\u7528libinjection\u7684XSS\u653b\u51fb\u3002&#8221;,<br \/>\n&#8220;reference&#8221;: &#8220;v152,8t:utf8toUnicode,t:urlDecodeUni,t:htmlEntityDecode,t:jsDecode,t:cssDecode,t:removeNulls&#8221;,<br \/>\n&#8220;ruleId&#8221;: &#8220;941100&#8221;,<br \/>\n&#8220;file&#8221;: &#8220;\/etc\/nginx\/owasp-modsecurity-crs\/rules\/REQUEST-941-APPLICATION-ATTACK-XSS.conf&#8221;,<br \/>\n&#8220;lineNumber&#8221;: &#8220;38&#8221;,<br \/>\n&#8220;data&#8221;: &#8220;\u5339\u914d\u5230\u7684\u6570\u636e: \u5728ARGS:cmd\u5185\u53d1\u73b0XSS\u6570\u636e:<script>\",<br \/>\n          \"severity\": \"2\",<br \/>\n          \"ver\": \"OWASP_CRS\/3.3.4\",<br \/>\n          \"rev\": \"\",<br \/>\n          \"tags\": [<br \/>\n            \"application-multi\",<br \/>\n            \"language-multi\",<br \/>\n            \"platform-multi\",<br \/>\n            \"attack-xss\",<br \/>\n            \"paranoia-level\/1\",<br \/>\n            \"OWASP_CRS\",<br \/>\n            \"capec\/1000\/152\/242\"<br \/>\n          ],<br \/>\n          \"maturity\": \"0\",<br \/>\n          \"accuracy\": \"0\"<br \/>\n        }<br \/>\n      },<br \/>\n      {<br \/>\n        \"message\": \"XSS\u8fc7\u6ee4 - \u7c7b\u522b1: \u811a\u672c\u6807\u7b7e\u5411\u91cf\",<br \/>\n        \"details\": {<br \/>\n          \"match\": \"\u5339\u914d \\\"\u4f7f\u7528\u53c2\u6570`(?i)<script[^>]*>[\\\\s\\\\S]*?'\u68c0\u6d4b\u53d8\u91cf`ARGS:cmd'\u662f\u5426\u4e0e\u8fd0\u7b97\u7b26`Rx'\u5339\u914d (\u503c: `<script>')\"\",<br \/>\n          \"reference\": \"o0,8v152,8t:utf8toUnicode,t:urlDecodeUni,t:htmlEntityDecode,t:jsDecode,t:cssDecode,t:removeNulls\",<br \/>\n          \"ruleId\": \"941110\",<br \/>\n          \"file\": \"\/etc\/nginx\/owasp-modsecurity-crs\/rules\/REQUEST-941-APPLICATION-ATTACK-XSS.conf\",<br \/>\n          \"lineNumber\": \"64\",<br \/>\n          \"data\": \"\u5339\u914d\u5230\u7684\u6570\u636e: \u5728ARGS:cmd\u5185\u53d1\u73b0 <script>: <script>\",<br \/>\n          \"severity\": \"2\",<br \/>\n          \"ver\": \"OWASP_CRS\/3.3.4\",<br \/>\n          \"rev\": \"\",<br \/>\n          \"tags\": [<br \/>\n            \"application-multi\",<br \/>\n            \"language-multi\",<br \/>\n            \"platform-multi\",<br \/>\n            \"attack-xss\",<br \/>\n            \"paranoia-level\/1\",<br \/>\n            \"OWASP_CRS\",<br \/>\n            \"capec\/1000\/152\/242\"<br \/>\n          ],<br \/>\n          \"maturity\": \"0\",<br \/>\n          \"accuracy\": \"0\"<br \/>\n        }<br \/>\n      },<br \/>\n      {<br \/>\n        \"message\": \"NoScript XSS InjectionChecker: HTML\u6ce8\u5165\",<br \/>\n        \"details\": {<br \/>\n          \"match\": \"\u5339\u914d \\\"\u4f7f\u7528\u53c2\u6570`(?i:(?:<\\\\w[\\\\s\\\\S]*[\\\\s\\\\\/]|['\\\\\\\"](?:[\\\\s\\\\S]*[\\\\s\\\\\/]?)?)?(?:on(?:d(?:e(?:vice(?:(?:orienta|mo)tion|proximity|found|light)|livery(?:success|error)|activate)|r(?:ag(?:e(?:n(?:ter|d)|xit)|(?:gestur|leav)e|start|d (3146\u4e2a\u5b57\u7b26\u7701\u7565)'\u68c0\u6d4b\u53d8\u91cf`ARGS:cmd'\u662f\u5426\u4e0e\u8fd0\u7b97\u7b26`Rx'\u5339\u914d (\u503c: `<script>')\"\",<br \/>\n          \"reference\": \"o0,7v152,8t:utf8toUnicode,t:urlDecodeUni,t:htmlEntityDecode,t:jsDecode,t:cssDecode,t:removeNulls\",<br \/>\n          \"ruleId\": \"941160\",<br \/>\n          \"file\": \"\/etc\/nginx\/owasp-modsecurity-crs\/rules\/REQUEST-941-APPLICATION-ATTACK-XSS.conf\",<br \/>\n          \"lineNumber\": \"181\",<br \/>\n          \"data\": \"\u5339\u914d\u5230\u7684\u6570\u636e: <script> \u5728ARGS:cmd\u5185\u53d1\u73b0: <script>\",<br \/>\n          \"severity\": \"2\",<br \/>\n          \"ver\": \"OWASP_CRS\/3.3.4\",<br \/>\n          \"rev\": \"\",<br \/>\n          \"tags\": [<br \/>\n            \"application-multi\",<br \/>\n            \"language-multi\",<br \/>\n            \"platform-multi\",<br \/>\n            \"attack-xss\",<br \/>\n            \"paranoia-level\/1\",<br \/>\n            \"OWASP_CRS\",<br \/>\n            \"capec\/1000\/152\/242\"<br \/>\n          ],<br \/>\n          \"maturity\": \"0\",<br \/>\n          \"accuracy\": \"0\"<br \/>\n        }<br \/>\n      },<br \/>\n      {<br \/>\n        \"message\": \"\u5165\u7ad9\u5f02\u5e38\u5206\u6570\u8d85\u8fc7\u9650\u5236 (\u603b\u5206: 15)\",<br \/>\n        \"details\": {<br \/>\n          \"match\": \"\u5339\u914d \\\"\u4f7f\u7528\u53c2\u6570`Ge'\u6bd4\u8f83`TX:ANOMALY_SCORE'\u662f\u5426\u5927\u4e8e\u7b49\u4e8e`5' (\u503c: `15')\"\",<br \/>\n          \"reference\": \"\",<br \/>\n          \"ruleId\": \"949110\",<br \/>\n          \"file\": \"\/etc\/nginx\/owasp-modsecurity-crs\/rules\/REQUEST-949-BLOCKING-EVALUATION.conf\",<br \/>\n          \"lineNumber\": \"81\",<br \/>\n          \"data\": \"\",<br \/>\n          \"severity\": \"2\",<br \/>\n          \"ver\": \"OWASP_CRS\/3.3.4\",<br \/>\n          \"rev\": \"\",<br \/>\n          \"tags\": [<br \/>\n            \"application-multi\",<br \/>\n            \"language-multi\",<br \/>\n            \"platform-multi\",<br \/>\n            \"attack-generic\"<br \/>\n          ],<br \/>\n          \"maturity\": \"0\",<br \/>\n          \"accuracy\": \"0\"<br \/>\n        }<br \/>\n      }<br \/>\n    ]<br \/>\n  }<br \/>\n}<\/details>\n<p>\u7136\u800c\uff0cModSecurity\u65e5\u5fd7(JSON)\u53ef\u4ee5\u63d0\u4f9b\u8be6\u7ec6\u4fe1\u606f\uff0c\u4f46\u6709\u65f6\u592a\u957f\u4ee5\u81f3\u4e8e\u4e00\u773c\u96be\u4ee5\u7406\u89e3\u3002\u56e0\u6b64\uff0c\u4ee5\u4e0b\u5c06\u4ecb\u7ecd\u4e00\u79cd\u5229\u7528jq\u5de5\u5177\u6765\u8fdb\u884c\u5927\u81f4\u603b\u7ed3\u7684\u65b9\u6cd5\uff0c\u4f9b\u53c2\u8003\u3002<\/p>\n<p>\u4e0b\u9762\u7684\u547d\u4ee4\u662f\u4e3a\u4e86\u4eceNGINX Ingress Controller\u7684\u65e5\u5fd7\u4e2dgrep\u51faModSecurity\u65e5\u5fd7\uff08\u4ee5JSON\u683c\u5f0f\uff0c\u5e76\u4ee5'^{\"transaction\":'\u5f00\u5934\u7684\u884c\uff09\uff0c\u7136\u540e\u901a\u8fc7jq\u4ec5\u63d0\u53d6\u4ee5\u4e0b\u4fe1\u606f\u3002<\/p>\n<ul class=\"post-ul\">\n\u30bf\u30a4\u30e0\u30b9\u30bf\u30f3\u30d7<br \/>\n\u30ea\u30af\u30a8\u30b9\u30c8\u60c5\u5831<br \/>\n\u5f15\u3063\u639b\u304b\u3063\u305f\u30eb\u30fc\u30eb<\/p>\n<p>\u30eb\u30fc\u30ebID<br \/>\n\u30eb\u30fc\u30eb\u306e\u6982\u8981<\/p>\n<\/ul>\n<pre class=\"post-pre\"><code><span class=\"nv\">$ PODNAME<\/span><span class=\"o\">=<\/span><span class=\"si\">$(<\/span> kubectl <span class=\"nt\">-n<\/span> ingress-nginx get pod <span class=\"nt\">-l<\/span> app.kubernetes.io\/component<span class=\"o\">=<\/span>controller <span class=\"nt\">-o<\/span><span class=\"o\">=<\/span><span class=\"nv\">jsonpath<\/span><span class=\"o\">=<\/span><span class=\"s1\">'{.items[].metadata.name}'<\/span> <span class=\"si\">)<\/span>\r\n<span class=\"nv\">$ <\/span>kubectl <span class=\"nt\">-n<\/span> ingress-nginx logs <span class=\"nv\">$PODNAME<\/span> | <span class=\"nb\">grep<\/span> <span class=\"s1\">'^{\"transaction\"'<\/span> | <span class=\"se\">\\<\/span>\r\n  jq <span class=\"nt\">-r<\/span> <span class=\"s1\">'.\"transaction\" | { time_stamp:.\"time_stamp\", request:.\"request\",  messages:[.\"messages\"[] | { ruleId:.\"details\".\"ruleId\", message:.\"message\" }] }'<\/span>\r\n\r\n<span class=\"o\">{<\/span>\r\n  <span class=\"s2\">\"time_stamp\"<\/span>: <span class=\"s2\">\"Thu Dec  8 07:00:13 2022\"<\/span>,\r\n  <span class=\"s2\">\"request\"<\/span>: <span class=\"o\">{<\/span>\r\n    <span class=\"s2\">\"method\"<\/span>: <span class=\"s2\">\"POST\"<\/span>,\r\n    <span class=\"s2\">\"http_version\"<\/span>: 1.1,\r\n    <span class=\"s2\">\"uri\"<\/span>: <span class=\"s2\">\"\/\"<\/span>,\r\n    <span class=\"s2\">\"headers\"<\/span>: <span class=\"o\">{<\/span>\r\n      <span class=\"s2\">\"Host\"<\/span>: <span class=\"s2\">\"demo.localdev.me:8080\"<\/span>,\r\n      <span class=\"s2\">\"User-Agent\"<\/span>: <span class=\"s2\">\"curl\/7.61.1\"<\/span>,\r\n      <span class=\"s2\">\"Accept\"<\/span>: <span class=\"s2\">\"*\/*\"<\/span>,\r\n      <span class=\"s2\">\"Content-Length\"<\/span>: <span class=\"s2\">\"12\"<\/span>,\r\n      <span class=\"s2\">\"Content-Type\"<\/span>: <span class=\"s2\">\"application\/x-www-form-urlencoded\"<\/span>\r\n    <span class=\"o\">}<\/span>\r\n  <span class=\"o\">}<\/span>,\r\n  <span class=\"s2\">\"messages\"<\/span>: <span class=\"o\">[<\/span>\r\n    <span class=\"o\">{<\/span>\r\n      <span class=\"s2\">\"ruleId\"<\/span>: <span class=\"s2\">\"941100\"<\/span>,\r\n      <span class=\"s2\">\"message\"<\/span>: <span class=\"s2\">\"XSS Attack Detected via libinjection\"<\/span>\r\n    <span class=\"o\">}<\/span>,\r\n    <span class=\"o\">{<\/span>\r\n      <span class=\"s2\">\"ruleId\"<\/span>: <span class=\"s2\">\"941110\"<\/span>,\r\n      <span class=\"s2\">\"message\"<\/span>: <span class=\"s2\">\"XSS Filter - Category 1: Script Tag Vector\"<\/span>\r\n    <span class=\"o\">}<\/span>,\r\n    <span class=\"o\">{<\/span>\r\n      <span class=\"s2\">\"ruleId\"<\/span>: <span class=\"s2\">\"941160\"<\/span>,\r\n      <span class=\"s2\">\"message\"<\/span>: <span class=\"s2\">\"NoScript XSS InjectionChecker: HTML Injection\"<\/span>\r\n    <span class=\"o\">}<\/span>,\r\n    <span class=\"o\">{<\/span>\r\n      <span class=\"s2\">\"ruleId\"<\/span>: <span class=\"s2\">\"949110\"<\/span>,\r\n      <span class=\"s2\">\"message\"<\/span>: <span class=\"s2\">\"Inbound Anomaly Score Exceeded (Total Score: 15)\"<\/span>\r\n    <span class=\"o\">}<\/span>\r\n  <span class=\"o\">]<\/span>\r\n<span class=\"o\">}<\/span>\r\n<\/code><\/pre>\n<p>\u6839\u636e\u4ee5\u4e0a\u60c5\u51b5\uff0c\u4f3c\u4e4e\u89e6\u53d1\u4e863\u79cd\u89c4\u5219\u7684\u89c4\u5219ID 941100\u3001941110\u548c941160\u3002<br \/>\n\uff08\u89c4\u5219ID 949110\u8868\u793a\u7531\u4e8e\u5176\u4ed6\u89c4\u5219\u5bfc\u81f4\u7684\u7d2f\u8ba1\u5206\u6570\u8d85\u8fc7\uff0c\u5fc5\u5b9a\u4f1a\u88abModSecurity\u963b\u65ad\uff0c\u56e0\u6b64\u88ab\u6392\u9664\u5728\u5916\u3002\uff09<\/p>\n<p>\u987a\u4fbf\u63d0\u4e00\u4e0b\uff0cCRS\u7684\u89c4\u5219\u5b9a\u4e49\u5728\u8fd9\u91cc\u3002\u6587\u4ef6\u6309\u7167\u89c4\u5219ID\u7684\u524d\u4e09\u4f4d\u8fdb\u884c\u5206\u5272\u3002<br \/>\n\u4f8b\u5982\uff0c\u89c4\u5219ID\u4e3a941100\u7684\u60c5\u51b5\u4e0b\uff0c\u5b9a\u4e49\u5728\u540d\u4e3aREQUEST-941-APPLICATION-ATTACK-XSS.conf\u7684\u6587\u4ef6\u4e2d\u3002<\/p>\n<h2>\u4e00\u5343\u6b21\u7684\u6572\u95e8<\/h2>\n<p>\u53c2\u8003\u8fd9\u7bc7\u6587\u7ae0\u8fdb\u884c\u5343\u672c\u6572\u95e8\u6d4b\u8bd5\u540e\uff0c\u6211\u5c1d\u8bd5\u4f7f\u7528\u5176\u4ed6\u653b\u51fb\u6a21\u5f0f\u8fdb\u884c\u8bbf\u95ee\uff0c\u7ed3\u679c\u5927\u90e8\u5206\u88ab\u6210\u529f\u5730\u963b\u6b62\u4e86403\u9519\u8bef\u3002\u4ee5\u4e0b\u662fcurl\u547d\u4ee4\u548c\u5bf9\u5e94ModSecurity\u65e5\u5fd7\u7684\u6458\u5f55\uff1a<br \/>\n\u4ee5\u4e0b\u662f\u53c2\u8003\u8be5\u6587\u7ae0\u8fdb\u884c\u5343\u672c\u6572\u95e8\u6d4b\u8bd5\u540e\uff0c\u6211\u5c1d\u8bd5\u7528\u5176\u4ed6\u653b\u51fb\u6a21\u5f0f\u8fdb\u884c\u8bbf\u95ee\u7684\u7ed3\u679c\uff0c\u5927\u90e8\u5206\u6210\u529f\u5730\u88ab403\u963b\u6b62\u3002\u4ee5\u4e0b\u662fcurl\u547d\u4ee4\u548c\u7ed3\u679c\u8f93\u51fa\u7684ModSecurity\u65e5\u5fd7\u6458\u5f55\u3002<\/p>\n<p>\u6b64\u5916\uff0c\u7531\u4e8eModSecurity\u65e5\u5fd7\u4e2d\u7684\u89c4\u5219ID\uff1a949110\u5c06\u59cb\u7ec8\u5728\u88abModSecurity\u963b\u65ad\u65f6\u51fa\u73b0\uff0c\u6211\u4eec\u5c06\u7701\u7565\u5176\u8bb0\u5f55\u3002<\/p>\n<h3>User-Agent\u88ab\u7be1\u6539\u7684\u673a\u5668\u4eba<\/h3>\n<pre class=\"post-pre\"><code><span class=\"nv\">$ <\/span>curl http:\/\/demo.localdev.me:8080\/ <span class=\"nt\">-H<\/span> <span class=\"s2\">\"User-Agent: Mozilla\/5.0 (compatible; Nmap Scripting Engine; http:\/\/nmap.org\/book\/nse.html)\"<\/span>\r\n<\/code><\/pre>\n<pre class=\"post-pre\"><code><span class=\"p\">{<\/span><span class=\"w\">\r\n  <\/span><span class=\"nl\">\"time_stamp\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"Thu Dec  8 04:48:40 2022\"<\/span><span class=\"p\">,<\/span><span class=\"w\">\r\n  <\/span><span class=\"nl\">\"request\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"p\">{<\/span><span class=\"w\">\r\n    <\/span><span class=\"nl\">\"method\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"GET\"<\/span><span class=\"p\">,<\/span><span class=\"w\">\r\n    <\/span><span class=\"nl\">\"http_version\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"mf\">1.1<\/span><span class=\"p\">,<\/span><span class=\"w\">\r\n    <\/span><span class=\"nl\">\"uri\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"\/\"<\/span><span class=\"p\">,<\/span><span class=\"w\">\r\n    <\/span><span class=\"nl\">\"headers\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"p\">{<\/span><span class=\"w\">\r\n      <\/span><span class=\"nl\">\"Host\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"demo.localdev.me:8080\"<\/span><span class=\"p\">,<\/span><span class=\"w\">\r\n      <\/span><span class=\"nl\">\"Accept\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"*\/*\"<\/span><span class=\"p\">,<\/span><span class=\"w\">\r\n      <\/span><span class=\"nl\">\"User-Agent\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"Mozilla\/5.0 (compatible; Nmap Scripting Engine; http:\/\/nmap.org\/book\/nse.html)\"<\/span><span class=\"w\">\r\n    <\/span><span class=\"p\">}<\/span><span class=\"w\">\r\n  <\/span><span class=\"p\">},<\/span><span class=\"w\">\r\n  <\/span><span class=\"nl\">\"messages\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"p\">[<\/span><span class=\"w\">\r\n    <\/span><span class=\"p\">{<\/span><span class=\"w\">\r\n      <\/span><span class=\"nl\">\"ruleId\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"913100\"<\/span><span class=\"p\">,<\/span><span class=\"w\">\r\n      <\/span><span class=\"nl\">\"message\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"Found User-Agent associated with security scanner\"<\/span><span class=\"w\">\r\n    <\/span><span class=\"p\">},<\/span><span class=\"w\">\r\n    <\/span><span class=\"err\">\u30fb\u30fb\u30fb<\/span><span class=\"w\">\r\n  <\/span><span class=\"p\">]<\/span><span class=\"w\">\r\n<\/span><span class=\"p\">}<\/span><span class=\"w\">\r\n<\/span><\/code><\/pre>\n<h3>\u672c\u5730\u6587\u4ef6\u5305\u542b\u6f0f\u6d1e\uff08LFI\uff09<\/h3>\n<pre class=\"post-pre\"><code><span class=\"nv\">$ <\/span>curl http:\/\/demo.localdev.me:8080\/script.php?page<span class=\"o\">=<\/span>..\/..\/..\/..\/..\/..\/etc\/passwd\r\n<\/code><\/pre>\n<pre class=\"post-pre\"><code><span class=\"p\">{<\/span><span class=\"w\">\r\n  <\/span><span class=\"nl\">\"time_stamp\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"Thu Dec  8 04:49:11 2022\"<\/span><span class=\"p\">,<\/span><span class=\"w\">\r\n  <\/span><span class=\"nl\">\"request\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"p\">{<\/span><span class=\"w\">\r\n    <\/span><span class=\"nl\">\"method\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"GET\"<\/span><span class=\"p\">,<\/span><span class=\"w\">\r\n    <\/span><span class=\"nl\">\"http_version\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"mf\">1.1<\/span><span class=\"p\">,<\/span><span class=\"w\">\r\n    <\/span><span class=\"nl\">\"uri\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"\/script.php?page=..\/..\/..\/..\/..\/..\/etc\/passwd\"<\/span><span class=\"p\">,<\/span><span class=\"w\">\r\n    <\/span><span class=\"nl\">\"headers\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"p\">{<\/span><span class=\"w\">\r\n      <\/span><span class=\"nl\">\"Host\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"demo.localdev.me:8080\"<\/span><span class=\"p\">,<\/span><span class=\"w\">\r\n      <\/span><span class=\"nl\">\"User-Agent\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"curl\/7.61.1\"<\/span><span class=\"p\">,<\/span><span class=\"w\">\r\n      <\/span><span class=\"nl\">\"Accept\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"*\/*\"<\/span><span class=\"w\">\r\n    <\/span><span class=\"p\">}<\/span><span class=\"w\">\r\n  <\/span><span class=\"p\">},<\/span><span class=\"w\">\r\n  <\/span><span class=\"nl\">\"messages\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"p\">[<\/span><span class=\"w\">\r\n    <\/span><span class=\"p\">{<\/span><span class=\"w\">\r\n      <\/span><span class=\"nl\">\"ruleId\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"930100\"<\/span><span class=\"p\">,<\/span><span class=\"w\">\r\n      <\/span><span class=\"nl\">\"message\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"Path Traversal Attack (\/..\/)\"<\/span><span class=\"w\">\r\n    <\/span><span class=\"p\">},<\/span><span class=\"w\">\r\n    <\/span><span class=\"p\">{<\/span><span class=\"w\">\r\n      <\/span><span class=\"nl\">\"ruleId\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"930110\"<\/span><span class=\"p\">,<\/span><span class=\"w\">\r\n      <\/span><span class=\"nl\">\"message\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"Path Traversal Attack (\/..\/)\"<\/span><span class=\"w\">\r\n    <\/span><span class=\"p\">},<\/span><span class=\"w\">\r\n    <\/span><span class=\"p\">{<\/span><span class=\"w\">\r\n      <\/span><span class=\"nl\">\"ruleId\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"930110\"<\/span><span class=\"p\">,<\/span><span class=\"w\">\r\n      <\/span><span class=\"nl\">\"message\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"Path Traversal Attack (\/..\/)\"<\/span><span class=\"w\">\r\n    <\/span><span class=\"p\">},<\/span><span class=\"w\">\r\n    <\/span><span class=\"p\">{<\/span><span class=\"w\">\r\n      <\/span><span class=\"nl\">\"ruleId\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"930120\"<\/span><span class=\"p\">,<\/span><span class=\"w\">\r\n      <\/span><span class=\"nl\">\"message\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"OS File Access Attempt\"<\/span><span class=\"w\">\r\n    <\/span><span class=\"p\">},<\/span><span class=\"w\">\r\n    <\/span><span class=\"p\">{<\/span><span class=\"w\">\r\n      <\/span><span class=\"nl\">\"ruleId\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"932160\"<\/span><span class=\"p\">,<\/span><span class=\"w\">\r\n      <\/span><span class=\"nl\">\"message\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"Remote Command Execution: Unix Shell Code Found\"<\/span><span class=\"w\">\r\n    <\/span><span class=\"p\">},<\/span><span class=\"w\">\r\n    <\/span><span class=\"err\">\u30fb\u30fb\u30fb<\/span><span class=\"w\">\r\n  <\/span><span class=\"p\">]<\/span><span class=\"w\">\r\n<\/span><span class=\"p\">}<\/span><span class=\"w\">\r\n<\/span><\/code><\/pre>\n<h3>\u7cfb\u7edf\u6587\u4ef6\u8bfb\u53d6<\/h3>\n<pre class=\"post-pre\"><code><span class=\"nv\">$ <\/span>curl http:\/\/demo.localdev.me:8080\/test.ini\r\n<\/code><\/pre>\n<pre class=\"post-pre\"><code><span class=\"p\">{<\/span><span class=\"w\">\r\n  <\/span><span class=\"nl\">\"time_stamp\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"Thu Dec  8 04:49:28 2022\"<\/span><span class=\"p\">,<\/span><span class=\"w\">\r\n  <\/span><span class=\"nl\">\"request\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"p\">{<\/span><span class=\"w\">\r\n    <\/span><span class=\"nl\">\"method\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"GET\"<\/span><span class=\"p\">,<\/span><span class=\"w\">\r\n    <\/span><span class=\"nl\">\"http_version\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"mf\">1.1<\/span><span class=\"p\">,<\/span><span class=\"w\">\r\n    <\/span><span class=\"nl\">\"uri\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"\/test.ini\"<\/span><span class=\"p\">,<\/span><span class=\"w\">\r\n    <\/span><span class=\"nl\">\"headers\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"p\">{<\/span><span class=\"w\">\r\n      <\/span><span class=\"nl\">\"Host\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"demo.localdev.me:8080\"<\/span><span class=\"p\">,<\/span><span class=\"w\">\r\n      <\/span><span class=\"nl\">\"User-Agent\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"curl\/7.61.1\"<\/span><span class=\"p\">,<\/span><span class=\"w\">\r\n      <\/span><span class=\"nl\">\"Accept\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"*\/*\"<\/span><span class=\"w\">\r\n    <\/span><span class=\"p\">}<\/span><span class=\"w\">\r\n  <\/span><span class=\"p\">},<\/span><span class=\"w\">\r\n  <\/span><span class=\"nl\">\"messages\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"p\">[<\/span><span class=\"w\">\r\n    <\/span><span class=\"p\">{<\/span><span class=\"w\">\r\n      <\/span><span class=\"nl\">\"ruleId\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"920440\"<\/span><span class=\"p\">,<\/span><span class=\"w\">\r\n      <\/span><span class=\"nl\">\"message\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"URL file extension is restricted by policy\"<\/span><span class=\"w\">\r\n    <\/span><span class=\"p\">},<\/span><span class=\"w\">\r\n    <\/span><span class=\"err\">\u30fb\u30fb\u30fb<\/span><span class=\"w\">\r\n  <\/span><span class=\"p\">]<\/span><span class=\"w\">\r\n<\/span><span class=\"p\">}<\/span><span class=\"w\">\r\n<\/span><\/code><\/pre>\n<h3>RFI (\u8fdc\u7a0b\u6587\u4ef6\u5305\u542b\u6f0f\u6d1e\uff0c\u53ef\u4ee5\u8ba9\u653b\u51fb\u8005\u67e5\u770b\u8fdc\u7a0b\u670d\u52a1\u5668\u4e0a\u7684\u6587\u4ef6)<\/h3>\n<pre class=\"post-pre\"><code><span class=\"nv\">$ <\/span>curl http:\/\/demo.localdev.me:8080\/display.php?FORMAT<span class=\"o\">=<\/span>http:\/\/192.168.11.1\/test.txt\r\n<\/code><\/pre>\n<pre class=\"post-pre\"><code><span class=\"p\">{<\/span><span class=\"w\">\r\n  <\/span><span class=\"nl\">\"time_stamp\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"Thu Dec  8 04:49:50 2022\"<\/span><span class=\"p\">,<\/span><span class=\"w\">\r\n  <\/span><span class=\"nl\">\"request\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"p\">{<\/span><span class=\"w\">\r\n    <\/span><span class=\"nl\">\"method\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"GET\"<\/span><span class=\"p\">,<\/span><span class=\"w\">\r\n    <\/span><span class=\"nl\">\"http_version\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"mf\">1.1<\/span><span class=\"p\">,<\/span><span class=\"w\">\r\n    <\/span><span class=\"nl\">\"uri\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"\/display.php?FORMAT=http:\/\/192.168.11.1\/test.txt\"<\/span><span class=\"p\">,<\/span><span class=\"w\">\r\n    <\/span><span class=\"nl\">\"headers\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"p\">{<\/span><span class=\"w\">\r\n      <\/span><span class=\"nl\">\"Host\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"demo.localdev.me:8080\"<\/span><span class=\"p\">,<\/span><span class=\"w\">\r\n      <\/span><span class=\"nl\">\"User-Agent\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"curl\/7.61.1\"<\/span><span class=\"p\">,<\/span><span class=\"w\">\r\n      <\/span><span class=\"nl\">\"Accept\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"*\/*\"<\/span><span class=\"w\">\r\n    <\/span><span class=\"p\">}<\/span><span class=\"w\">\r\n  <\/span><span class=\"p\">},<\/span><span class=\"w\">\r\n  <\/span><span class=\"nl\">\"messages\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"p\">[<\/span><span class=\"w\">\r\n    <\/span><span class=\"p\">{<\/span><span class=\"w\">\r\n      <\/span><span class=\"nl\">\"ruleId\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"931100\"<\/span><span class=\"p\">,<\/span><span class=\"w\">\r\n      <\/span><span class=\"nl\">\"message\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"Possible Remote File Inclusion (RFI) Attack: URL Parameter using IP Address\"<\/span><span class=\"w\">\r\n    <\/span><span class=\"p\">},<\/span><span class=\"w\">\r\n    <\/span><span class=\"err\">\u30fb\u30fb\u30fb<\/span><span class=\"w\">\r\n  <\/span><span class=\"p\">]<\/span><span class=\"w\">\r\n<\/span><span class=\"p\">}<\/span><span class=\"w\">\r\n<\/span><\/code><\/pre>\n<h3>\u8de8\u7ad9\u811a\u672c\u653b\u51fb (XSS)<\/h3>\n<pre class=\"post-pre\"><code><span class=\"nv\">$ <\/span>curl <span class=\"s1\">'http:\/\/demo.localdev.me:8080\/?script=&lt;script&gt;alert(\"hello\")&lt;\/script&gt;'<\/span>\r\n<\/code><\/pre>\n<pre class=\"post-pre\"><code><span class=\"p\">{<\/span><span class=\"w\">\r\n  <\/span><span class=\"nl\">\"time_stamp\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"Thu Dec  8 04:50:17 2022\"<\/span><span class=\"p\">,<\/span><span class=\"w\">\r\n  <\/span><span class=\"nl\">\"request\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"p\">{<\/span><span class=\"w\">\r\n    <\/span><span class=\"nl\">\"method\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"GET\"<\/span><span class=\"p\">,<\/span><span class=\"w\">\r\n    <\/span><span class=\"nl\">\"http_version\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"mf\">1.1<\/span><span class=\"p\">,<\/span><span class=\"w\">\r\n    <\/span><span class=\"nl\">\"uri\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"\/?script=&lt;script&gt;alert(<\/span><span class=\"se\">\\\"<\/span><span class=\"s2\">hello<\/span><span class=\"se\">\\\"<\/span><span class=\"s2\">)&lt;\/script&gt;\"<\/span><span class=\"p\">,<\/span><span class=\"w\">\r\n    <\/span><span class=\"nl\">\"headers\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"p\">{<\/span><span class=\"w\">\r\n      <\/span><span class=\"nl\">\"Host\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"demo.localdev.me:8080\"<\/span><span class=\"p\">,<\/span><span class=\"w\">\r\n      <\/span><span class=\"nl\">\"User-Agent\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"curl\/7.61.1\"<\/span><span class=\"p\">,<\/span><span class=\"w\">\r\n      <\/span><span class=\"nl\">\"Accept\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"*\/*\"<\/span><span class=\"w\">\r\n    <\/span><span class=\"p\">}<\/span><span class=\"w\">\r\n  <\/span><span class=\"p\">},<\/span><span class=\"w\">\r\n  <\/span><span class=\"nl\">\"messages\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"p\">[<\/span><span class=\"w\">\r\n    <\/span><span class=\"p\">{<\/span><span class=\"w\">\r\n      <\/span><span class=\"nl\">\"ruleId\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"941100\"<\/span><span class=\"p\">,<\/span><span class=\"w\">\r\n      <\/span><span class=\"nl\">\"message\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"XSS Attack Detected via libinjection\"<\/span><span class=\"w\">\r\n    <\/span><span class=\"p\">},<\/span><span class=\"w\">\r\n    <\/span><span class=\"p\">{<\/span><span class=\"w\">\r\n      <\/span><span class=\"nl\">\"ruleId\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"941110\"<\/span><span class=\"p\">,<\/span><span class=\"w\">\r\n      <\/span><span class=\"nl\">\"message\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"XSS Filter - Category 1: Script Tag Vector\"<\/span><span class=\"w\">\r\n    <\/span><span class=\"p\">},<\/span><span class=\"w\">\r\n    <\/span><span class=\"p\">{<\/span><span class=\"w\">\r\n      <\/span><span class=\"nl\">\"ruleId\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"941160\"<\/span><span class=\"p\">,<\/span><span class=\"w\">\r\n      <\/span><span class=\"nl\">\"message\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"NoScript XSS InjectionChecker: HTML Injection\"<\/span><span class=\"w\">\r\n    <\/span><span class=\"p\">},<\/span><span class=\"w\">\r\n    <\/span><span class=\"err\">\u30fb\u30fb\u30fb<\/span><span class=\"w\">\r\n  <\/span><span class=\"p\">]<\/span><span class=\"w\">\r\n<\/span><span class=\"p\">}<\/span><span class=\"w\">\r\n<\/span><\/code><\/pre>\n<h3>\u9605\u8bfb Amazon EC2 \u5143\u6570\u636e<\/h3>\n<pre class=\"post-pre\"><code><span class=\"nv\">$ <\/span>curl http:\/\/demo.localdev.me:8080\/?site<span class=\"o\">=<\/span>http:\/\/169.254.169.254\/latest\/meta-data\/\r\n<\/code><\/pre>\n<pre class=\"post-pre\"><code><span class=\"p\">{<\/span><span class=\"w\">\r\n  <\/span><span class=\"nl\">\"time_stamp\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"Thu Dec  8 04:50:36 2022\"<\/span><span class=\"p\">,<\/span><span class=\"w\">\r\n  <\/span><span class=\"nl\">\"request\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"p\">{<\/span><span class=\"w\">\r\n    <\/span><span class=\"nl\">\"method\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"GET\"<\/span><span class=\"p\">,<\/span><span class=\"w\">\r\n    <\/span><span class=\"nl\">\"http_version\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"mf\">1.1<\/span><span class=\"p\">,<\/span><span class=\"w\">\r\n    <\/span><span class=\"nl\">\"uri\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"\/?site=http:\/\/169.254.169.254\/latest\/meta-data\/\"<\/span><span class=\"p\">,<\/span><span class=\"w\">\r\n    <\/span><span class=\"nl\">\"headers\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"p\">{<\/span><span class=\"w\">\r\n      <\/span><span class=\"nl\">\"Host\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"demo.localdev.me:8080\"<\/span><span class=\"p\">,<\/span><span class=\"w\">\r\n      <\/span><span class=\"nl\">\"User-Agent\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"curl\/7.61.1\"<\/span><span class=\"p\">,<\/span><span class=\"w\">\r\n      <\/span><span class=\"nl\">\"Accept\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"*\/*\"<\/span><span class=\"w\">\r\n    <\/span><span class=\"p\">}<\/span><span class=\"w\">\r\n  <\/span><span class=\"p\">},<\/span><span class=\"w\">\r\n  <\/span><span class=\"nl\">\"messages\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"p\">[<\/span><span class=\"w\">\r\n    <\/span><span class=\"p\">{<\/span><span class=\"w\">\r\n      <\/span><span class=\"nl\">\"ruleId\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"931100\"<\/span><span class=\"p\">,<\/span><span class=\"w\">\r\n      <\/span><span class=\"nl\">\"message\"<\/span><span class=\"p\">:<\/span><span class=\"w\"> <\/span><span class=\"s2\">\"Possible Remote File Inclusion (RFI) Attack: URL Parameter using IP Address\"<\/span><span class=\"w\">\r\n    <\/span><span class=\"p\">},<\/span><span class=\"w\">\r\n    <\/span><span class=\"err\">\u30fb\u30fb\u30fb<\/span><span class=\"w\">\r\n  <\/span><span class=\"p\">]<\/span><span class=\"w\">\r\n<\/span><span class=\"p\">}<\/span><span class=\"w\">\r\n<\/span><\/code><\/pre>\n<h3>\u6ca1\u6709\u7528\u6237\u4ee3\u7406<\/h3>\n<p>\u5728\u672c\u6587\u6240\u8ff0\u7684ModSecurity\u6784\u5efa\u8fc7\u7a0b\u4e2d\uff0c\u6ca1\u6709\u68c0\u6d4b\u5230\u6ca1\u6709User-Agent\u7684\u60c5\u51b5\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"nv\">$ <\/span>curl http:\/\/demo.localdev.me:8080\/ <span class=\"nt\">-H<\/span> <span class=\"s2\">\"User-Agent: \"<\/span>\r\n&lt;html&gt;&lt;body&gt;&lt;h1&gt;It works!&lt;\/h1&gt;&lt;\/body&gt;&lt;\/html&gt;\r\n\u2192\u906e\u65ad\u3055\u308c\u306a\u304b\u3063\u305f\u3002\r\n<\/code><\/pre>\n<p>CRS\u63d0\u4f9b\u4e86\u6ca1\u6709User-Agent\u7684\u89c4\u5219\uff0c\u4f46\u7531\u4e8e\u5b83\u7684\u5206\u6570\u8f83\u4f4e\uff08Notice\u7ea7\u522b\uff09\uff0c\u6240\u4ee5\u5e76\u6ca1\u6709\u89e6\u53d1\u963b\u65ad\u52a8\u4f5c\u3002<br \/>\nModSecurity\u53ef\u4ee5\u4fee\u6539\u6bcf\u4e2a\u89c4\u5219\u6216\u6dfb\u52a0\u81ea\u5b9a\u4e49\u89c4\u5219\uff0c\u56e0\u6b64\u5982\u679c\u60a8\u6709\u7591\u8651\uff0c\u53ef\u4ee5\u5c1d\u8bd5\u4fee\u6539\u89c4\u5219\u3002<\/p>\n<h2>\u6700\u540e<\/h2>\n<p>\u867d\u7136\u4e5f\u6709\u4e0d\u9700\u8981\u8fdb\u884c\u9632\u5fa1\u7684\u60c5\u51b5\uff0c\u4f46\u662f\u5982\u679c\u80fd\u591f\u514d\u8d39\u4e14\u4fbf\u6377\u5730\u63d0\u4f9b\u5982\u6b64\u7a0b\u5ea6\u7684\u9632\u5fa1\u63aa\u65bd\uff0c\u6ca1\u6709\u7406\u7531\u4e0d\u91c7\u7528\u3002<br \/>\n\u5927\u5bb6\u90fd\u53ef\u4ee5\u5229\u7528NGINX Ingress Controller + ModSecurity\u6765\u66f4\u5b89\u5168\u5730\u8fd0\u8425k8s\uff0c\u5e76\u5728\u5723\u8bde\u8282\u548c\u5e74\u672b\u6109\u5feb\u5b89\u5fc3\u5730\u5ea6\u8fc7\u3002<\/p>\n<h2>\u53c2\u8003\uff1a\u4f7f\u7528Helm\u7684\u60c5\u51b5\u4e0b<\/h2>\n<p>\u5982\u679c\u8981\u4f7f\u7528helm\u6765\u5b89\u88c5NGINX Ingress Controller\uff0c\u4f60\u53ef\u4ee5\u6309\u5982\u4e0b\u65b9\u5f0f\u521b\u5efa\u540d\u4e3amyvalues.yaml\u7684\u6587\u4ef6\uff0c\u5e76\u5728helm\u6267\u884c\u65f6\u4f7f\u7528\"--values\"\u9009\u9879\uff0c\u4ee5\u542f\u7528ModSecurity\u5e76\u9644\u52a0ConfigMap \"modsecurity-config\"\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"na\">controller<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">config<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"na\">enable-modsecurity<\/span><span class=\"pi\">:<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">true\"<\/span>\r\n    <span class=\"na\">enable-owasp-modsecurity-crs<\/span><span class=\"pi\">:<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">true\"<\/span>\r\n    <span class=\"na\">modsecurity-snippet<\/span><span class=\"pi\">:<\/span> <span class=\"pi\">|<\/span>\r\n      <span class=\"s\">Include \/etc\/nginx\/owasp-modsecurity-crs\/custom\/custom-modsecurity.conf<\/span>\r\n\r\n  <span class=\"na\">extraVolumeMounts<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"pi\">-<\/span> <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">modsecurity-config<\/span>\r\n      <span class=\"na\">mountPath<\/span><span class=\"pi\">:<\/span> <span class=\"s\">\/etc\/nginx\/owasp-modsecurity-crs\/custom\/<\/span>\r\n  <span class=\"na\">extraVolumes<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"pi\">-<\/span> <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">modsecurity-config<\/span>\r\n      <span class=\"na\">configMap<\/span><span class=\"pi\">:<\/span>\r\n        <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">modsecurity-config<\/span>\r\n<\/code><\/pre>\n<pre class=\"post-pre\"><code><span class=\"nv\">$ <\/span>helm repo add ingress-nginx https:\/\/kubernetes.github.io\/ingress-nginx\r\n<span class=\"nv\">$ <\/span>helm repo update\r\n<span class=\"nv\">$ <\/span>helm search repo ingress-nginx\r\nNAME                            CHART VERSION   APP VERSION     DESCRIPTION\r\ningress-nginx\/ingress-nginx     4.4.0           1.5.1           Ingress controller <span class=\"k\">for <\/span>Kubernetes using NGINX a...\r\n<span class=\"nv\">$ <\/span>helm <span class=\"nb\">install <\/span>ingress-nginx <span class=\"se\">\\<\/span>\r\n  <span class=\"nt\">--namespace<\/span><span class=\"o\">=<\/span>ingress-nginx <span class=\"se\">\\<\/span>\r\n  <span class=\"nt\">--version<\/span> 4.4.0 <span class=\"se\">\\<\/span>\r\n  <span class=\"nt\">--values<\/span> myvalues.yaml <span class=\"se\">\\<\/span>\r\n  ingress-nginx\/ingress-nginx\r\n<\/code><\/pre>\n<h2>\u6587\u732e\u5f15\u7528<\/h2>\n<p>\u4ee5\u4e0b\u662f\u5bf9\u4e0a\u8ff0\u5185\u5bb9\u7684\u4e2d\u6587\u7ffb\u8bd1\uff1a<\/p>\n<p>https:\/\/kubernetes.github.io\/ingress-nginx\/<br \/>\nhttps:\/\/github.com\/SpiderLabs\/ModSecurity<br \/>\nhttps:\/\/github.com\/coreruleset\/coreruleset<br \/>\nhttps:\/\/coreruleset.org\/<br \/>\nhttps:\/\/www.netnea.com\/cms\/nginx-modsecurity-tutorials\/<\/p>\n<p>https:\/\/kubernetes.github.io\/ingress-nginx\/ - Kubernetes Ingress-Nginx\u5b98\u65b9\u6587\u6863<\/p>\n<p>https:\/\/github.com\/SpiderLabs\/ModSecurity - SpiderLabs\u7684ModSecurity\u9879\u76ee<\/p>\n<p>https:\/\/github.com\/coreruleset\/coreruleset - Coreruleset\u9879\u76ee<\/p>\n<p>https:\/\/coreruleset.org\/ - Coreruleset\u5b98\u65b9\u7f51\u7ad9<\/p>\n<p>https:\/\/www.netnea.com\/cms\/nginx-modsecurity-tutorials\/ - Netnea\u7684Nginx ModSecurity\u6559\u7a0b<\/p>\n<p>\u203b\u672c\u6587\u4e2d\u63d0\u53ca\u7684\u4ea7\u54c1\u540d\u79f0\u548c\u670d\u52a1\u540d\u79f0\u662f\u5404\u4e2a\u7ec4\u7ec7\u7684\u5546\u6807\u6216\u6ce8\u518c\u5546\u6807\u3002<\/p>\n<p><\/script><\/details>\n","protected":false},"excerpt":{"rendered":"<p>\u8fd9\u7bc7\u6587\u7ae0\u662fNTT\u30b3\u30e0\u30a6\u30a7\u30a2 Advent Calendar 2022\u7b2c19\u5929\u7684\u6587\u7ae0\u3002 https:\/\/qiit [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-33335","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v21.5 (Yoast SEO v21.5) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>\u5c06NGINX Ingress Controller\u8f6c\u5316\u4e3aWAF\u89e3\u51b3\u65b9\u6848 - Blog - Silicon Cloud<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.silicloud.com\/zh\/blog\/\u5c06nginx-ingress-controller\u8f6c\u5316\u4e3awaf\u89e3\u51b3\u65b9\u6848\u3002\/\" \/>\n<meta property=\"og:locale\" content=\"zh_CN\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\u5c06NGINX Ingress Controller\u8f6c\u5316\u4e3aWAF\u89e3\u51b3\u65b9\u6848\" \/>\n<meta property=\"og:description\" content=\"\u8fd9\u7bc7\u6587\u7ae0\u662fNTT\u30b3\u30e0\u30a6\u30a7\u30a2 Advent Calendar 2022\u7b2c19\u5929\u7684\u6587\u7ae0\u3002 https:\/\/qiit [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.silicloud.com\/zh\/blog\/\u5c06nginx-ingress-controller\u8f6c\u5316\u4e3awaf\u89e3\u51b3\u65b9\u6848\u3002\/\" \/>\n<meta property=\"og:site_name\" content=\"Blog - Silicon Cloud\" \/>\n<meta property=\"article:published_time\" content=\"2023-03-19T11:21:55+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-04-30T11:44:10+00:00\" \/>\n<meta name=\"author\" content=\"\u97f5, \u79d1\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u4f5c\u8005\" \/>\n\t<meta name=\"twitter:data1\" content=\"\u97f5, \u79d1\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 \u5206\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e5%b0%86nginx-ingress-controller%e8%bd%ac%e5%8c%96%e4%b8%bawaf%e8%a7%a3%e5%86%b3%e6%96%b9%e6%a1%88%e3%80%82\/\",\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e5%b0%86nginx-ingress-controller%e8%bd%ac%e5%8c%96%e4%b8%bawaf%e8%a7%a3%e5%86%b3%e6%96%b9%e6%a1%88%e3%80%82\/\",\"name\":\"\u5c06NGINX Ingress Controller\u8f6c\u5316\u4e3aWAF\u89e3\u51b3\u65b9\u6848 - Blog - Silicon Cloud\",\"isPartOf\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#website\"},\"datePublished\":\"2023-03-19T11:21:55+00:00\",\"dateModified\":\"2024-04-30T11:44:10+00:00\",\"author\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/6530331a63adef3b3443a1fab53a0e6e\"},\"breadcrumb\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e5%b0%86nginx-ingress-controller%e8%bd%ac%e5%8c%96%e4%b8%bawaf%e8%a7%a3%e5%86%b3%e6%96%b9%e6%a1%88%e3%80%82\/#breadcrumb\"},\"inLanguage\":\"zh-Hans\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.silicloud.com\/zh\/blog\/%e5%b0%86nginx-ingress-controller%e8%bd%ac%e5%8c%96%e4%b8%bawaf%e8%a7%a3%e5%86%b3%e6%96%b9%e6%a1%88%e3%80%82\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e5%b0%86nginx-ingress-controller%e8%bd%ac%e5%8c%96%e4%b8%bawaf%e8%a7%a3%e5%86%b3%e6%96%b9%e6%a1%88%e3%80%82\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\u9996\u9875\",\"item\":\"https:\/\/www.silicloud.com\/zh\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"\u5c06NGINX Ingress Controller\u8f6c\u5316\u4e3aWAF\u89e3\u51b3\u65b9\u6848\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#website\",\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/\",\"name\":\"Blog - Silicon Cloud\",\"description\":\"\",\"inLanguage\":\"zh-Hans\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/6530331a63adef3b3443a1fab53a0e6e\",\"name\":\"\u97f5, \u79d1\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/429ccb39b3fff5188bc17986222cfb0936cbadb8cc933cff04ab5ca01bd30a08?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/429ccb39b3fff5188bc17986222cfb0936cbadb8cc933cff04ab5ca01bd30a08?s=96&d=mm&r=g\",\"caption\":\"\u97f5, \u79d1\"},\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/author\/yunke\/\"},{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e5%b0%86nginx-ingress-controller%e8%bd%ac%e5%8c%96%e4%b8%bawaf%e8%a7%a3%e5%86%b3%e6%96%b9%e6%a1%88%e3%80%82\/#local-main-organization-logo\",\"url\":\"\",\"contentUrl\":\"\",\"caption\":\"Blog - Silicon Cloud\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"\u5c06NGINX Ingress Controller\u8f6c\u5316\u4e3aWAF\u89e3\u51b3\u65b9\u6848 - Blog - Silicon Cloud","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.silicloud.com\/zh\/blog\/\u5c06nginx-ingress-controller\u8f6c\u5316\u4e3awaf\u89e3\u51b3\u65b9\u6848\u3002\/","og_locale":"zh_CN","og_type":"article","og_title":"\u5c06NGINX Ingress Controller\u8f6c\u5316\u4e3aWAF\u89e3\u51b3\u65b9\u6848","og_description":"\u8fd9\u7bc7\u6587\u7ae0\u662fNTT\u30b3\u30e0\u30a6\u30a7\u30a2 Advent Calendar 2022\u7b2c19\u5929\u7684\u6587\u7ae0\u3002 https:\/\/qiit [&hellip;]","og_url":"https:\/\/www.silicloud.com\/zh\/blog\/\u5c06nginx-ingress-controller\u8f6c\u5316\u4e3awaf\u89e3\u51b3\u65b9\u6848\u3002\/","og_site_name":"Blog - Silicon Cloud","article_published_time":"2023-03-19T11:21:55+00:00","article_modified_time":"2024-04-30T11:44:10+00:00","author":"\u97f5, \u79d1","twitter_card":"summary_large_image","twitter_misc":{"\u4f5c\u8005":"\u97f5, \u79d1","\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4":"4 \u5206"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e5%b0%86nginx-ingress-controller%e8%bd%ac%e5%8c%96%e4%b8%bawaf%e8%a7%a3%e5%86%b3%e6%96%b9%e6%a1%88%e3%80%82\/","url":"https:\/\/www.silicloud.com\/zh\/blog\/%e5%b0%86nginx-ingress-controller%e8%bd%ac%e5%8c%96%e4%b8%bawaf%e8%a7%a3%e5%86%b3%e6%96%b9%e6%a1%88%e3%80%82\/","name":"\u5c06NGINX Ingress Controller\u8f6c\u5316\u4e3aWAF\u89e3\u51b3\u65b9\u6848 - Blog - Silicon Cloud","isPartOf":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/#website"},"datePublished":"2023-03-19T11:21:55+00:00","dateModified":"2024-04-30T11:44:10+00:00","author":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/6530331a63adef3b3443a1fab53a0e6e"},"breadcrumb":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e5%b0%86nginx-ingress-controller%e8%bd%ac%e5%8c%96%e4%b8%bawaf%e8%a7%a3%e5%86%b3%e6%96%b9%e6%a1%88%e3%80%82\/#breadcrumb"},"inLanguage":"zh-Hans","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.silicloud.com\/zh\/blog\/%e5%b0%86nginx-ingress-controller%e8%bd%ac%e5%8c%96%e4%b8%bawaf%e8%a7%a3%e5%86%b3%e6%96%b9%e6%a1%88%e3%80%82\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e5%b0%86nginx-ingress-controller%e8%bd%ac%e5%8c%96%e4%b8%bawaf%e8%a7%a3%e5%86%b3%e6%96%b9%e6%a1%88%e3%80%82\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\u9996\u9875","item":"https:\/\/www.silicloud.com\/zh\/blog\/"},{"@type":"ListItem","position":2,"name":"\u5c06NGINX Ingress Controller\u8f6c\u5316\u4e3aWAF\u89e3\u51b3\u65b9\u6848"}]},{"@type":"WebSite","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#website","url":"https:\/\/www.silicloud.com\/zh\/blog\/","name":"Blog - Silicon Cloud","description":"","inLanguage":"zh-Hans"},{"@type":"Person","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/6530331a63adef3b3443a1fab53a0e6e","name":"\u97f5, \u79d1","image":{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/429ccb39b3fff5188bc17986222cfb0936cbadb8cc933cff04ab5ca01bd30a08?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/429ccb39b3fff5188bc17986222cfb0936cbadb8cc933cff04ab5ca01bd30a08?s=96&d=mm&r=g","caption":"\u97f5, \u79d1"},"url":"https:\/\/www.silicloud.com\/zh\/blog\/author\/yunke\/"},{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e5%b0%86nginx-ingress-controller%e8%bd%ac%e5%8c%96%e4%b8%bawaf%e8%a7%a3%e5%86%b3%e6%96%b9%e6%a1%88%e3%80%82\/#local-main-organization-logo","url":"","contentUrl":"","caption":"Blog - Silicon Cloud"}]}},"_links":{"self":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/33335","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/comments?post=33335"}],"version-history":[{"count":2,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/33335\/revisions"}],"predecessor-version":[{"id":93915,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/33335\/revisions\/93915"}],"wp:attachment":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/media?parent=33335"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/categories?post=33335"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/tags?post=33335"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}