HTTP and HTTPS protocol has several request methods. POST, GET, PUT, PATCH, HEAD and DELETE. When we configuraing NGINX web server we need to restrict PUT,PATCH and DELETE request methods. Only POST, GET and HEAD methods enough to enable from web sever.
In this blog you can find technical matter related to information security. Other than that Linux server configuration, Nginx configuration, high availability techniques etc...
Saturday, July 9, 2022
How to Restrict Request Method in NGINX
How to configure Go-access Real-time HTML Outputs (NGINX)
Requirement
GoAccess has the ability the output real-time data in the HTML report. You can even email the HTML file since it is composed of a single file with no external file dependencies, how neat is that!
The process of generating a real-time HTML report is very similar to the process of creating a static report. Only --real-time-html is needed to make it real-time.
Pre-Requisites
- NGINX web server which support websocket
- Install goaccess on the same server
Step 01: Configure NGINX proxy pass for goaccess real-time push
location /ws-goaccess {proxy_pass http://127.0.0.1:9870;proxy_http_version 1.1;proxy_set_header Upgrade $http_upgrade;proxy_set_header Connection "upgrade";}
In my case Go-Access websocket port listen locally with port 9870.
Step 02: Identify log format of your NGINX web server
I used this GitHum repository to find out log format for goaccess.
URL: https://github.com/stockrt/nginx2goaccess
Command Usage
Usage: ./nginx2goaccess.sh '<log_format>'
NGINX log format u have to get from your web server. It should be in nginx.conf file. Configuration parameter "log_format"
Step 03: Start the Go-Access WebSocket Server
goaccess /var/log/nginx/data.vidutech.org-access.log /var/log/nginx/www.vidutech.org-access.log --log-format='%h - %^ [%d:%t %^] "%r" "%b" "%R" "%u" "%^"' --date-format=%d/%b/%Y --time-format=%T -o /usr/share/nginx/html/goaccess.html --real-time-html --addr=127.0.0.1 --port=9870 --ws-url=data.vidutech.org/ws-goaccess
Command Explanation
We can pass several log files as input
- /var/log/nginx/data.vidutech.org-access.log
- /var/log/nginx/www.vidutech.org-access.log
- You can obtain it from Step 02
- Go-Access report should be save under nginx share location. This file should be accessible via browser with server name.
- Start server as real-time
- Listen address and port
Friday, June 24, 2022
Benchmark Your NGINX WEB Server
There are lots of commercial and open source tools to benchmark your web server. In this blog I and going to demonstrate benchmark your web server with CIS benchmark policies. Any one can freely download CIS documents.
CIS Download URL: https://www.cisecurity.org/benchmark/nginx
"The CIS Benchmarks are distributed free of charge in PDF format to propagate their worldwide use and adoption as user-originated, de facto standards. CIS Benchmarks are the only consensus-based, best-practice security configuration guides both developed and accepted by government, business, industry, and academia."
Download benchmark scrip: https://github.com/viduranga0006/nginx-benchmark
This is a bash shell script. You have to run it with supper user. Once you execute, you have to select relevant category. At the end it will list summary of benchmark results.
Sunday, November 7, 2021
How to Generate Self-Signed Certificate with your own CA
In this blog I am going to demonstrate how to generate a self-sign certificate for your local domain for testing purpose.
Prerequisites
- Select "Genarate New CA Certificate" option
- Enter CA Name without space.
- Select "Genarate New Host Certificate" Option
- Enter Host Certificate name.
- Enter Domain list. If you are going to use it for multiple site, you have to mention each hostnames.
Thursday, November 5, 2020
NGINX with Letsencrypt
Let's Encrypt is a non-profit certificate authority run by Internet Security Research Group (ISRG) that provides X.509 certificates for Transport Layer Security (TLS) encryption at no charge. It launched on April 12, 2016.
Prerequisite
- Linux server with nginx installed (Port 80 and 443 should open for public)
- There should be a DNS entry for your site.
- "git" "wget" packages should install in your server.
Step 01: Install Prerequisite
Step 02: Install NGINX
rpm -ivh nginx-1.18.0-2.el8.ngx.x86_64.rpm
systemctl enable nginxsystemctl start nginx
git clone https://github.com/letsencrypt/letsencrypt
server {listen 443 ssl;server_name <Your-Site-Name>;ssl_certificate /etc/letsencrypt/live/<Your-Site-Name>/fullchain.pem;ssl_certificate_key /etc/letsencrypt/live/<Your-Site-Name>/privkey.pem;ssl_session_cache shared:SSL:10m;ssl_session_timeout 5m;ssl_protocols TLSv1.2;ssl_ciphers ECDH+AESGCM:DH+AESGCM:ECDH+AES256:DH+AES256:ECDH+AES128:DH+AES:RSA+AESGCM:RSA+AES:!aNULL:!eNULL:!MD5:!DSS;ssl_prefer_server_ciphers on;# HSTSadd_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;access_log /var/log/nginx/<Your-Site-Name>-access main;error_log /var/log/nginx/<Your-Site-Name>-error warn;location / {root /usr/share/nginx/html;}location /.well-known/acme-challenge/ {root /usr/share/nginx/html;}}server {listen 80;server_name <Your-Site-Name>;rewrite ^ https://<Your-Site-Name>$request_uri? permanent;}
nginx -t
Wednesday, October 21, 2020
NGINX RPM Build with Third-party Modules
Prerequisites
- OS with Centos 7 installed.
- Enable "epel-release" repo
- Install below packages
- openssl openssl-devel gcc gd-devel GeoIP GeoIP-devel libgdata-devel.x86_64 libgdata.x86_64 gcc-c++ flex bison yajl yajl-devel curl-devel curl GeoIP-devel doxygen zlib-devel gcc make automake autoconf libtool pcre pcre-devel libxml2 libxml2-devel curl curl-devel httpd-devel rpm-build.x86_64 rpm-build-libs.x86_64 redhat-lsb-core.x86_64 mhash.x86_64 mhash-devel.x86_64 patch.x86_64 luajit.x86_64 libmodsecurity.x86_64 dkms gcc make kernel-devel bzip2 binutils patch libgomp glibc-headers glibc-devel kernel-headers libXrandr libmodsecurity-devel.x86_64 git mlocate
- Download and install nginx source RPM from nginx repo (http://nginx.org/packages/centos/7/SRPMS)
- Download third-party modules from github or nginx module page
- GitHub : https://github.com/
- Nginx : https://www.nginx.com/resources/wiki/modules/
- Modules we are going to include are as follow
- echo-nginx-module : https://github.com/openresty/echo-nginx-module
- lua-nginx-module : https://github.com/openresty/lua-nginx-module
- memc-nginx-module : https://github.com/openresty/memc-nginx-module
- nginx_cross_origin_module : https://github.com/yaoweibin/nginx_cross_origin_module
- nginx-goodies-nginx-sticky : https://github.com/Refinitiv/nginx-sticky-module-ng
- nginx-modsecurity-module : https://github.com/SpiderLabs/ModSecurity-nginx
- nginx-sticky-module
- nginx_upstream_check_module : https://github.com/yaoweibin/nginx_upstream_check_module
- ngx_devel_kit : https://github.com/vision5/ngx_devel_kit
- ngx_http_enhanced_memcached_module : https://github.com/bpaquet/ngx_http_enhanced_memcached_module
- ngx-http-secure-download : https://www.nginx.com/resources/wiki/modules/secure_download/
- redis2-nginx-module : https://github.com/openresty/redis2-nginx-module
- redis-nginx-module : https://github.com/onnimonni/redis-nginx-module
- set-misc-nginx-module : https://github.com/openresty/set-misc-nginx-module
- srcache-nginx-module : https://github.com/openresty/srcache-nginx-module
- We need to build modsecurity and LuaJit libiries separately and install on the server
- Modsecurity : https://github.com/SpiderLabs/ModSecurity
- LuaJIT: https://luajit.org/download/LuaJIT-2.0.5.tar.gz
Build ModSecurity
- Download ModSecurity from above URL
- Execute below commands to build it.
./build.sh
./configure
make
make install
Build LuaJIT
makemake install
Build NGINX with Modules
Apply Patches
Then execute this command
patch -p0 < /root/rpmbuild/SOURCES/modules/nginx-goodies-nginx-sticky/patches/cookies.patch
You have to put full path when it prompt for File path. You find the path from locate command.
Once you applied all the patches, create a tar.gz file of nginx source code. Backup old one before do it.
Then include module you want to build with nginx to nginx.spec file.
To build the nginx execute this command.
rpmbuild -bb nginx.spec
If you successfully completed the build you will get some thing like this at the end.
Note: If you are a beginner, add module by module and build.


















































