From 78bd98e72f86711cb7ca9f811023b528002a4834 Mon Sep 17 00:00:00 2001 From: Xor290 Date: Wed, 10 Jun 2026 17:50:44 +0200 Subject: [PATCH] chore: update --- monitoring/s3/.env | 9 + monitoring/s3/docker-compose-s3.yml | 99 +++ monitoring/s3/nginx/nginx.conf | 98 +++ monitoring/{ => security}/.env | 0 monitoring/security/CLAMAV_INTEGRATION.md | 283 ++++++++ monitoring/security/FIREWALL_RULES.md | 165 +++++ .../security/OWASP_MODSECURITY_RULES.md | 246 +++++++ monitoring/security/VPN_DEPLOYMENT_SUMMARY.md | 258 +++++++ monitoring/security/VPN_SETUP.md | 255 +++++++ monitoring/security/admin1.conf | 10 + .../docker-compose-security.yml} | 124 +--- monitoring/{ => security}/dozzle/users.yml | 2 +- .../security/firewall-monitoring-uber.sh | 106 +++ monitoring/security/firewall-vpn-server.sh | 80 +++ monitoring/security/nginx/nginx-fixed.conf | 74 +++ monitoring/security/nginx/nginx-simple.conf | 83 +++ monitoring/{ => security}/nginx/nginx.conf | 202 +++--- monitoring/security/rebind-services-to-vpn.sh | 61 ++ .../{ => security}/wazuh/config/certs.yml | 0 .../wazuh_dashboard/opensearch_dashboards.yml | 0 .../config/wazuh_indexer/internal_users.yml | 45 ++ .../config/wazuh_indexer/wazuh.indexer.yml | 0 .../decoders/modsecurity_decoder.xml | 4 + .../wazuh/config/wazuh_manager/init.sh | 0 .../wazuh_manager/localfile_clamav.conf | 23 + .../wazuh/config/wazuh_manager/ossec.conf | 628 ++++++++++++++++++ .../wazuh_manager/rules/clamav_rules.xml | 143 ++++ .../rules/local_active_response_rules.xml | 45 ++ .../rules/local_modsecurity_rules.xml | 39 ++ .../wazuh_manager/rules/local_sca_noise.xml | 113 ++++ .../rules/local_ssh_pam_noise.xml | 23 +- .../rules/modsecurity_owasp_rules.xml | 352 ++++++++++ .../wazuh_manager/rules/modsecurity_rules.xml | 44 ++ .../{ => security}/wazuh/generate-certs.sh | 0 monitoring/security/wireguard-admin-client.sh | 68 ++ monitoring/security/wireguard-client-setup.sh | 104 +++ monitoring/security/wireguard-server-setup.sh | 89 +++ .../decoders/modsecurity_decoder.xml | 35 - .../rules/local_modsecurity_rules.xml | 37 -- .../wazuh_manager/rules/modsecurity_rules.xml | 94 --- 40 files changed, 3661 insertions(+), 380 deletions(-) create mode 100644 monitoring/s3/.env create mode 100644 monitoring/s3/docker-compose-s3.yml create mode 100644 monitoring/s3/nginx/nginx.conf rename monitoring/{ => security}/.env (100%) create mode 100644 monitoring/security/CLAMAV_INTEGRATION.md create mode 100644 monitoring/security/FIREWALL_RULES.md create mode 100644 monitoring/security/OWASP_MODSECURITY_RULES.md create mode 100644 monitoring/security/VPN_DEPLOYMENT_SUMMARY.md create mode 100644 monitoring/security/VPN_SETUP.md create mode 100644 monitoring/security/admin1.conf rename monitoring/{docker-compose.yml => security/docker-compose-security.yml} (61%) mode change 100644 => 100755 rename monitoring/{ => security}/dozzle/users.yml (55%) mode change 100644 => 100755 create mode 100644 monitoring/security/firewall-monitoring-uber.sh create mode 100644 monitoring/security/firewall-vpn-server.sh create mode 100644 monitoring/security/nginx/nginx-fixed.conf create mode 100644 monitoring/security/nginx/nginx-simple.conf rename monitoring/{ => security}/nginx/nginx.conf (52%) mode change 100644 => 100755 create mode 100644 monitoring/security/rebind-services-to-vpn.sh rename monitoring/{ => security}/wazuh/config/certs.yml (100%) mode change 100644 => 100755 rename monitoring/{ => security}/wazuh/config/wazuh_dashboard/opensearch_dashboards.yml (100%) mode change 100644 => 100755 create mode 100755 monitoring/security/wazuh/config/wazuh_indexer/internal_users.yml rename monitoring/{ => security}/wazuh/config/wazuh_indexer/wazuh.indexer.yml (100%) mode change 100644 => 100755 create mode 100755 monitoring/security/wazuh/config/wazuh_manager/decoders/modsecurity_decoder.xml rename monitoring/{ => security}/wazuh/config/wazuh_manager/init.sh (100%) mode change 100644 => 100755 create mode 100644 monitoring/security/wazuh/config/wazuh_manager/localfile_clamav.conf rename monitoring/{ => security}/wazuh/config/wazuh_manager/ossec.conf (56%) mode change 100644 => 100755 create mode 100644 monitoring/security/wazuh/config/wazuh_manager/rules/clamav_rules.xml create mode 100644 monitoring/security/wazuh/config/wazuh_manager/rules/local_active_response_rules.xml create mode 100755 monitoring/security/wazuh/config/wazuh_manager/rules/local_modsecurity_rules.xml create mode 100644 monitoring/security/wazuh/config/wazuh_manager/rules/local_sca_noise.xml rename monitoring/{ => security}/wazuh/config/wazuh_manager/rules/local_ssh_pam_noise.xml (85%) mode change 100644 => 100755 create mode 100644 monitoring/security/wazuh/config/wazuh_manager/rules/modsecurity_owasp_rules.xml create mode 100755 monitoring/security/wazuh/config/wazuh_manager/rules/modsecurity_rules.xml rename monitoring/{ => security}/wazuh/generate-certs.sh (100%) create mode 100755 monitoring/security/wireguard-admin-client.sh create mode 100644 monitoring/security/wireguard-client-setup.sh create mode 100644 monitoring/security/wireguard-server-setup.sh delete mode 100644 monitoring/wazuh/config/wazuh_manager/decoders/modsecurity_decoder.xml delete mode 100644 monitoring/wazuh/config/wazuh_manager/rules/local_modsecurity_rules.xml delete mode 100644 monitoring/wazuh/config/wazuh_manager/rules/modsecurity_rules.xml diff --git a/monitoring/s3/.env b/monitoring/s3/.env new file mode 100644 index 00000000..49a8ef53 --- /dev/null +++ b/monitoring/s3/.env @@ -0,0 +1,9 @@ +RUSTFS_ACCESS_KEY=iBacJPHUHSf6SMTnxrr +RUSTFS_SECRET_KEY=4jNzZhstv1WkwTwtvR4gHSbrx01m4sJl4LBBleeJ + +XAVIA_ADMIN_PASSWORD=2VYfheOweyMiP510GGfjNYmq3vJGJ +XAVIA_UPLOAD_KEY=dNW2tiNXRR6w1cLwlmCOyKFIKvoTz8xQMSyd +XAVIA_PRIVATE_KEY_BASE_64=MlRvcGlyNHpFRjhYOTlvUjMxbHFCVHRQdjYyelh4Wnc0MDM4TkZaVQ== +XAVIA_POSTGRES_USER=xavia +XAVIA_POSTGRES_PASSWORD=6DzLcsb5rgWukuGdrHtRBQ222f +XAVIA_POSTGRES_DB=releases_db diff --git a/monitoring/s3/docker-compose-s3.yml b/monitoring/s3/docker-compose-s3.yml new file mode 100644 index 00000000..a9fcb30a --- /dev/null +++ b/monitoring/s3/docker-compose-s3.yml @@ -0,0 +1,99 @@ +services: + nginx: + image: nginx:alpine + container_name: s3_nginx + restart: unless-stopped + ports: + - "80:80" + - "443:443" + volumes: + - ./nginx/nginx.conf:/etc/nginx/nginx.conf:ro + - ./nginx/certs:/etc/nginx/certs:ro + - nginx_logs:/var/log/nginx + depends_on: + - rustfs + - xavia + networks: + - s3_net + + rustfs_perm: + image: alpine:latest + container_name: rustfs_perm + volumes: + - /mnt/data:/data + command: chown -R 10001:10001 /data + + rustfs: + image: rustfs/rustfs:latest + depends_on: + rustfs_perm: + condition: service_completed_successfully + hostname: rustfs + container_name: rustfs + restart: unless-stopped + volumes: + - /mnt/data:/data + - /mnt/logs:/logs + environment: + - RUSTFS_ACCESS_KEY=${RUSTFS_ACCESS_KEY:-iBacJPHUHSf6SMTnxrr} + - RUSTFS_SECRET_KEY=${RUSTFS_SECRET_KEY:-4jNzZhstv1WkwTwtvR4gHSbrx01m4sJl4LBBleeJ} + - RUSTFS_SERVER_DOMAINS=rustfs.uber-stup.club + - RUSTFS_CONSOLE_ENABLE=true + - RUSTFS_ADDRESS=:9000 + - RUSTFS_CONSOLE_ADDRESS=:9001 + networks: + - s3_net + + xavia_db: + image: postgres:16-alpine + container_name: xavia_db + restart: unless-stopped + environment: + - POSTGRES_USER=${XAVIA_POSTGRES_USER:-xavia} + - POSTGRES_PASSWORD=${XAVIA_POSTGRES_PASSWORD} + - POSTGRES_DB=${XAVIA_POSTGRES_DB:-releases_db} + volumes: + - xavia_db_data:/var/lib/postgresql/data + networks: + - s3_net + + xavia: + image: xaviaio/xavia-ota:latest + container_name: xavia + restart: unless-stopped + environment: + - HOST=https://ota.uber-stup.club + - BLOB_STORAGE_TYPE=local + - DB_TYPE=postgres + - ADMIN_PASSWORD=${XAVIA_ADMIN_PASSWORD} + - UPLOAD_KEY=${XAVIA_UPLOAD_KEY} + - PRIVATE_KEY_BASE_64=${XAVIA_PRIVATE_KEY_BASE_64} + - POSTGRES_USER=${XAVIA_POSTGRES_USER:-xavia} + - POSTGRES_PASSWORD=${XAVIA_POSTGRES_PASSWORD} + - POSTGRES_DB=${XAVIA_POSTGRES_DB:-releases_db} + - POSTGRES_HOST=xavia_db + - POSTGRES_PORT=5432 + volumes: + - xavia_blobs:/app/blobs + depends_on: + - xavia_db + networks: + - s3_net + + dozzle-agent: + image: amir20/dozzle:latest + command: agent + volumes: + - /var/run/docker.sock:/var/run/docker.sock:ro + ports: + - "7007:7007" + restart: unless-stopped + +networks: + s3_net: + driver: bridge + +volumes: + nginx_logs: + xavia_db_data: + xavia_blobs: diff --git a/monitoring/s3/nginx/nginx.conf b/monitoring/s3/nginx/nginx.conf new file mode 100644 index 00000000..11f90cec --- /dev/null +++ b/monitoring/s3/nginx/nginx.conf @@ -0,0 +1,98 @@ +worker_processes auto; + +events { + worker_connections 1024; +} + +http { + resolver 127.0.0.11 valid=10s ipv6=off; + + # Redirect HTTP -> HTTPS + server { + listen 80; + server_name _; + return 301 https://$host$request_uri; + } + + # ── RustFS Console ────────────────────────────────────── + server { + listen 443 ssl; + server_name rustfs.uber-stup.club; + + ssl_certificate /etc/nginx/certs/fullchain.pem; + ssl_certificate_key /etc/nginx/certs/privkey.pem; + ssl_protocols TLSv1.2 TLSv1.3; + ssl_ciphers HIGH:!aNULL:!MD5; + + access_log /var/log/nginx/rustfs_access.log; + error_log /var/log/nginx/rustfs_error.log; + + location / { + set $upstream http://rustfs:9001; + proxy_pass $upstream; + proxy_http_version 1.1; + proxy_set_header Host $host; + proxy_set_header X-Real-IP $remote_addr; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Proto $scheme; + proxy_set_header Upgrade $http_upgrade; + proxy_set_header Connection "upgrade"; + proxy_read_timeout 300s; + client_max_body_size 500m; + } + } + + # ── RustFS S3 API ─────────────────────────────────────── + server { + listen 443 ssl; + server_name s3.uber-stup.club; + + ssl_certificate /etc/nginx/certs/fullchain.pem; + ssl_certificate_key /etc/nginx/certs/privkey.pem; + ssl_protocols TLSv1.2 TLSv1.3; + ssl_ciphers HIGH:!aNULL:!MD5; + + access_log /var/log/nginx/rustfs_s3_access.log; + error_log /var/log/nginx/rustfs_s3_error.log; + + location / { + set $upstream http://rustfs:9000; + proxy_pass $upstream; + proxy_http_version 1.1; + proxy_set_header Host $http_host; + proxy_set_header X-Real-IP $remote_addr; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Proto $scheme; + proxy_read_timeout 300s; + client_max_body_size 2g; + } + } + + # ── Xavia OTA ─────────────────────────────────────────── + server { + listen 443 ssl; + server_name ota.uber-stup.club; + + ssl_certificate /etc/nginx/certs/fullchain.pem; + ssl_certificate_key /etc/nginx/certs/privkey.pem; + ssl_protocols TLSv1.2 TLSv1.3; + ssl_ciphers HIGH:!aNULL:!MD5; + + access_log /var/log/nginx/xavia_access.log; + error_log /var/log/nginx/xavia_error.log; + + location / { + set $upstream http://xavia:3000; + proxy_pass $upstream; + proxy_http_version 1.1; + proxy_set_header Host $host; + proxy_set_header X-Real-IP $remote_addr; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Proto $scheme; + proxy_set_header Upgrade $http_upgrade; + proxy_set_header Connection "upgrade"; + proxy_read_timeout 300s; + client_max_body_size 500m; + } + } +} diff --git a/monitoring/.env b/monitoring/security/.env similarity index 100% rename from monitoring/.env rename to monitoring/security/.env diff --git a/monitoring/security/CLAMAV_INTEGRATION.md b/monitoring/security/CLAMAV_INTEGRATION.md new file mode 100644 index 00000000..223ff23e --- /dev/null +++ b/monitoring/security/CLAMAV_INTEGRATION.md @@ -0,0 +1,283 @@ +# ClamAV Integration with Wazuh + +Integration guide for deploying ClamAV antivirus with Wazuh monitoring stack. + +## Overview + +ClamAV scans files and containers for malware, while Wazuh collects and analyzes ClamAV logs for: +- Real-time malware detection alerts +- Ransomware detection +- Signature database update status +- Scan statistics and quarantine actions + +--- + +## Architecture + +``` +┌─────────────────────────────────────┐ +│ ClamAV Container (clamav) │ +│ • Scans Docker containers/files │ +│ • Generates logs: clamav.log │ +│ • Freshclam updates signatures │ +└──────────────┬──────────────────────┘ + │ (logs volume) + ↓ +┌─────────────────────────────────────┐ +│ Wazuh Manager (wazuh.manager) │ +│ • Collects ClamAV logs │ +│ • Parses with decoders │ +│ • Matches detection rules │ +│ • Sends alerts to indexer │ +└──────────────┬──────────────────────┘ + │ (syslog format) + ↓ +┌─────────────────────────────────────┐ +│ Wazuh Dashboard (UI) │ +│ • Display malware detections │ +│ • Show scan results │ +│ • Alert severity levels │ +└─────────────────────────────────────┘ +``` + +--- + +## Deployment + +### 1. Add ClamAV to docker-compose + +The following service has been added to `docker-compose-security.yml`: + +```yaml +clamav: + image: clamav/clamav:stable + container_name: clamav + restart: unless-stopped + environment: + - FRESHCLAM_CHECKS=24 + - CLAMD_SCAN_MAX_FILESIZE=100M + volumes: + - clamav_data:/var/lib/clamav # Signature database + - clamav_logs:/var/log/clamav # Log output + - /var/run/docker.sock:/var/run/docker.sock:ro + networks: + - monitoring_net +``` + +### 2. Deploy ClamAV + +```bash +cd /home/ubuntu/docker +docker compose -f docker-compose-security.yml up -d clamav + +# Verify deployment +docker ps | grep clamav +docker logs clamav +``` + +### 3. Wazuh Configuration + +#### Log Collection + +File: `wazuh/config/wazuh_manager/localfile_clamav.conf` + +Configures Wazuh to collect: +- `clamav.log` — Main scanner logs +- `freshclam.log` — Signature update logs +- `alert.log` — High-priority detections + +#### Detection Rules + +File: `wazuh/config/wazuh_manager/rules/clamav_rules.xml` + +Key rules (level/priority): + +| Rule ID | Level | Trigger | Example | +|---------|-------|---------|---------| +| 100501 | 15 | FOUND/Infected | Malware detected | +| 100502 | 12 | Trojan/PUA | Potentially unwanted app | +| 100503 | 15 | .Virus/Worm | Classic virus detection | +| 100504 | 15 | Ransomware | Ransomware families | +| 100505 | 3 | Update successful | Signature DB refreshed | +| 100506 | 10 | Update failed | Download/connection error | +| 100507 | 8 | Daemon error | ClamAV process error | +| 100515 | 16 | Multiple hits in 1h | Possible outbreak | + +--- + +## Log Format + +### ClamAV Log Example + +``` +Jun 10 14:35:22 clamav clamd[1234]: /var/data/suspect.exe: Trojan.Win32.Generic!c FOUND +Jun 10 14:35:25 clamav freshclam[5678]: ClamAV update completed. 1 databases updated. +Jun 10 14:36:01 clamav clamd[1234]: Scanning started +Jun 10 14:36:45 clamav clamd[1234]: Scanning finished. 2 files scanned, 0 threats found +``` + +### Wazuh Alert Example + +```json +{ + "timestamp": "2026-06-10T14:35:22.000Z", + "rule": { + "id": "100501", + "level": 15, + "description": "ClamAV: Malware detected" + }, + "data": { + "srcfile": "/var/data/suspect.exe", + "alert": "Trojan.Win32.Generic!c FOUND" + }, + "groups": ["malware", "clamav", "infection"] +} +``` + +--- + +## Operations + +### Check ClamAV Status + +```bash +# Container status +docker ps | grep clamav + +# View logs +docker logs clamav + +# Manual scan +docker exec clamav clamscan -r /var/data +``` + +### Update Signatures + +ClamAV automatically updates signatures (configured via `FRESHCLAM_CHECKS=24`). + +Manual update: +```bash +docker exec clamav freshclam +``` + +### View Wazuh Alerts + +1. Access Wazuh Dashboard: `https://10.0.0.2` +2. Go to: **Security Events** → **Search** +3. Filter by: + - `rule.id: 100501` — Malware detections + - `rule.id: 100504` — Ransomware alerts + - `rule.groups: malware` — All malware-related events + +### Query via API + +```bash +# Get recent malware detections +curl -k -H "Authorization: Bearer YOUR_TOKEN" \ + "https://monitoring-uber:55000/api/v0/search?q=rule.id:100501&pretty" + +# Get ClamAV scan statistics +curl -k -H "Authorization: Bearer YOUR_TOKEN" \ + "https://monitoring-uber:55000/api/v0/search?q=group:clamav&pretty" +``` + +--- + +## Tuning & Optimization + +### Scan Performance + +Adjust scan parameters in docker-compose environment: + +```yaml +environment: + - CLAMD_SCAN_MAX_FILESIZE=100M # Max file size to scan + - CLAMD_MAX_SCAN_SIZE=200M # Max total scan size + - CLAMD_SCAN_PE_PLUS=yes # Enhanced PE detection + - CLAMD_SCAN_ARCHIVE=yes # Scan inside archives + - CLAMD_MAX_FILES=10000 # Max files to scan +``` + +### Update Frequency + +Default: 24 checks per day (every hour) + +Change via: +```yaml +environment: + - FRESHCLAM_CHECKS=48 # 2-hourly updates +``` + +### Alert Severity + +Adjust rule levels in `clamav_rules.xml` based on your risk tolerance: +- Level 3-6: Info/Low +- Level 8-10: Medium +- Level 12-15: High +- Level 16+: Critical/Outbreak + +--- + +## Troubleshooting + +### ClamAV Not Scanning + +```bash +# Check daemon is running +docker exec clamav ps aux | grep clamd + +# Check signatures are loaded +docker exec clamav clamscan --version + +# Manually scan +docker exec clamav clamscan /var/data +``` + +### Signature Updates Failing + +```bash +# Check freshclam logs +docker logs clamav | grep freshclam + +# Manual update with verbose output +docker exec clamav freshclam -v + +# Check internet connectivity +docker exec clamav wget https://cvd.clamav.net +``` + +### Wazuh Not Receiving Logs + +```bash +# Check logs are being generated +docker exec clamav tail -f /var/log/clamav/clamav.log + +# Check Wazuh log collection +docker exec wazuh_manager tail -f /var/ossec/logs/ossec.log | grep clamav + +# Verify rules loaded +docker exec wazuh_manager cat /var/ossec/etc/rules/clamav_rules.xml | head -10 +``` + +--- + +## Files Modified/Created + +| File | Purpose | +|------|---------| +| `docker-compose-security.yml` | Added ClamAV service + volumes | +| `wazuh/config/wazuh_manager/localfile_clamav.conf` | Log collection config | +| `wazuh/config/wazuh_manager/rules/clamav_rules.xml` | Malware detection rules | +| `CLAMAV_INTEGRATION.md` | This documentation | + +--- + +## Next Steps + +1. Deploy: `docker compose up -d clamav` +2. Wait for initial database download (5-10 minutes) +3. Monitor logs: `docker logs -f clamav` +4. Check Wazuh dashboard for alerts +5. Configure scan schedules/locations as needed +6. Set up active response (optional) for automatic quarantine + diff --git a/monitoring/security/FIREWALL_RULES.md b/monitoring/security/FIREWALL_RULES.md new file mode 100644 index 00000000..750657ae --- /dev/null +++ b/monitoring/security/FIREWALL_RULES.md @@ -0,0 +1,165 @@ +# Firewall Configuration Rules + +Updated: 2026-06-10 + +## Overview + +Firewall rules for monitoring stack with Wazuh, Dozzle, Beszel, and VPN infrastructure. + +--- + +## monitoring-uber (185.103.167.138) + +### Inbound Rules (INPUT) + +| Port | Protocol | Source | Purpose | Status | +|------|----------|--------|---------|--------| +| 22 | TCP | Admin IPs | SSH administration | ALLOW | +| 22 | TCP | 185.103.166.119 (prod) | SSH — BLOCKED | **DROP** | +| 22 | TCP | 185.103.166.112 (pre-prod) | SSH — BLOCKED | **DROP** | +| 22 | TCP | 80.96.58.164 (s3) | SSH — BLOCKED | **DROP** | +| 1514 | TCP | 185.103.166.119 | Wazuh agents (prod) | ALLOW | +| 1514 | TCP | 185.103.166.112 | Wazuh agents (pre-prod) | ALLOW | +| 51820 | UDP | Any | WireGuard VPN | ALLOW | +| 443 | TCP | 10.0.0.0/24 | Wazuh Dashboard (VPN) | ALLOW | +| 8080 | TCP | 10.0.0.0/24 | Dozzle logs (VPN) | ALLOW | +| 8090 | TCP | 10.0.0.0/24 | Beszel monitoring (VPN) | ALLOW | +| 9000-9001 | TCP | 10.0.0.0/24 | S3/RustFS (VPN) | ALLOW | + +### Outbound Rules (OUTPUT) +- **Default:** ACCEPT (all traffic allowed) +- Allows DNS, updates, internet access + +### Forward Rules (FORWARD) +- **Default:** DROP (no transit traffic) + +### Persistence +- Rules saved to `/etc/iptables/rules.v4` +- Auto-loaded on boot via `iptables-persistent` + +--- + +## vpn-uber (45.150.111.158) + +### Inbound Rules (INPUT) + +| Port | Protocol | Source | Purpose | Status | +|------|----------|--------|---------|--------| +| 22 | TCP | Any | SSH administration | ALLOW | +| 51820 | UDP | Any | WireGuard VPN | ALLOW | +| 10001 | TCP | 10.0.0.0/24 | Beszel agent (from VPN only) | ALLOW | + +### Outbound Rules (OUTPUT) +- **Default:** ACCEPT (all traffic allowed) + +### Forward Rules (FORWARD) +- **Default:** ACCEPT +- Enables routing: wg0 ↔ eth0 (VPN ↔ Internet) +- ESTABLISHED/RELATED always allowed + +### Network Features +- NAT masquerade: `eth0` (POSTROUTING) +- IP forwarding: enabled (`net.ipv4.ip_forward=1`) +- Allows VPN clients to reach internet through VPN server + +### Persistence +- Rules saved to `/etc/iptables/rules.v4` +- IP forwarding saved to `/etc/sysctl.conf` + +--- + +## Security Hardening + +### Principle: Least Privilege +1. **SSH restrictions**: Production servers (prod, pre-prod, s3) **cannot** SSH into monitoring-uber + - Prevents lateral movement if a prod server is compromised + - Admins must SSH directly to monitoring-uber or via VPN + +2. **Service isolation**: All user-facing services (Wazuh, Dozzle, Beszel) accessible **only via VPN** + - Not exposed to public internet + - Network: 10.0.0.0/24 (private VPN) + +3. **Port whitelist**: Only required ports open + - Wazuh agent ingest: 1514/tcp (prod/pre-prod only) + - VPN: 51820/udp (all) + - SSH: 22/tcp (admin access, blocked from prod servers) + - Monitoring agents: 10001/tcp (VPN only) + +### Attack Surface Reduction +- Production agents cannot access monitoring infrastructure +- Monitoring dashboard only accessible via VPN +- No exposed dashboards or logs to public internet +- SSH brute-force: limited by rate (ESTABLISHED/RELATED state tracking) + +--- + +## Updating Rules + +### monitoring-uber +```bash +ssh root@185.103.167.138 +./firewall-monitoring-uber.sh +``` + +### vpn-uber +```bash +ssh root@45.150.111.158 +./firewall-vpn-server.sh +``` + +### Verify Rules Applied +```bash +# Check current rules +iptables -L INPUT -n +iptables -L FORWARD -n + +# Check saved rules +cat /etc/iptables/rules.v4 +``` + +### Restore Rules on Boot +Rules are automatically restored via `/etc/iptables/rules.v4` if `iptables-persistent` is installed: +```bash +apt-get install iptables-persistent +``` + +--- + +## Beszel Agent Configuration + +Beszel agents installed on all infrastructure servers: + +| Server | Type | Port | Access | +|--------|------|------|--------| +| prod-uber | Docker | 10001 | Public IP (185.103.166.119:10001) | +| pre-prod-uber | Docker | 10001 | Public IP (185.103.166.112:10001) | +| s3-uber | Docker | 10001 | Public IP (80.96.58.164:10001) | +| vpn-uber | Binarie (systemd) | 10001 | VPN IP (10.0.0.1:10001) | + +**Note:** vpn-uber agent is accessible **only from VPN** due to firewall rules. + +--- + +## Troubleshooting + +### Service not reachable +```bash +# Check if service is listening +ss -tlnp | grep + +# Check firewall allows traffic +iptables -L INPUT -n | grep + +# Test connectivity +nc -zv +``` + +### SSH access denied from prod +- Expected behavior (security hardening) +- Use admin SSH keys or SSH via VPN instead + +### Beszel agent shows offline +- Check agent is listening: `ss -tlnp | grep 10001` +- Check firewall allows Beszel dashboard to reach agent +- Verify network routing between monitoring-uber and agent server + diff --git a/monitoring/security/OWASP_MODSECURITY_RULES.md b/monitoring/security/OWASP_MODSECURITY_RULES.md new file mode 100644 index 00000000..a649a8aa --- /dev/null +++ b/monitoring/security/OWASP_MODSECURITY_RULES.md @@ -0,0 +1,246 @@ +# OWASP Top 10 ModSecurity Rules — Wazuh Active Response + +## Vue d'ensemble + +Ce système détecte et répond aux attaques OWASP Top 10 via ModSecurity + Wazuh. + +**Deux couches de détection :** + +| Type | Trigger | Règle | Level | AR | +|------|---------|-------|-------|-----| +| **Bloqué (403)** | HTTP 403 | 100220-100281 | 12-15 | Fermer 4h-24h | +| **Remontée (Warning)** | Anomaly scoring | 100320-100381 | 6-11 | Fermer 30min-6h | + +--- + +## Correspondances CRS ModSecurity + +``` +941xxx — XSS (Cross-Site Scripting) +942xxx — SQL Injection, LDAP Injection, etc. +943xxx — XXE (XML External Entity) +930xxx — Path Traversal, RFI, RCE, LFI +932xxx — Remote Command Execution +933xxx — PHP Injection +934xxx — Java Injection +950xxx — Exploit attempts +951xxx — Regex DoS, Scanner detection +952xxx — Restricted File Access +953xxx — Insecure File Upload +954xxx — Proxy abuse, Scanner detection +955xxx — HTTP Response Splitting, Header Injection +970xxx — SSRF (Server-Side Request Forgery) +971xxx — SSRF (alternative patterns) +``` + +--- + +## Règles par OWASP Category + +### OWASP #1 : Broken Access Control + +**Détecte :** Path Traversal, File Inclusion, Unauthorized Access + +| Rule ID | Type | Patterns | Level | Description | +|---------|------|----------|-------|-------------| +| 100250 | Bloqué | 930xx (path\|traversal\|lfi) | 12 | LFI/Path Traversal bloquée | +| 100251 | Bloqué | 930xx (rfi\|remote\|include) | 13 | RFI bloquée | +| 100252 | Bloqué | 952xx | 11 | File Access bloquée | +| 100293 | Bloqué | Freq(100250)×4/180s | 12 | Path Traversal brute-force | +| 100350 | Remontée | 930xx (path\|traversal\|lfi) | 8 | LFI attempt (warning) | +| 100351 | Remontée | 930xx (rfi\|remote\|include) | 9 | RFI attempt (warning) | +| 100352 | Remontée | 952xx | 8 | File Access attempt (warning) | + +**Active Response :** +- Bloqué : `firewall-drop 6h` +- Brute-force : `firewall-drop 24h` +- Remontée : `firewall-drop 2h-4h` + +--- + +### OWASP #3 : Injection + +**Détecte :** SQLi, LDAP, Command Injection, PHP/Java Injection + +| Rule ID | Type | Patterns | Level | Description | +|---------|------|----------|-------|-------------| +| 100220 | Bloqué | 942xx | 13 | SQL Injection bloquée | +| 100221 | Bloqué | 942xx (LDAP pattern) | 12 | LDAP Injection bloquée | +| 100222 | Bloqué | 932xx | 14 | Command Injection bloquée | +| 100223 | Bloqué | 933xx | 13 | PHP Injection bloquée | +| 100224 | Bloqué | 934xx | 13 | Java Injection bloquée | +| 100290 | Bloqué | Freq(100220)×3/60s | 14 | SQLi brute-force | +| 100292 | Bloqué | Freq(100222)×2/60s | 15 | Command Injection CRITICAL | +| 100320 | Remontée | 942xx | 9 | SQLi attempt (warning) | +| 100321 | Remontée | 932xx | 10 | Command Injection attempt | +| 100322 | Remontée | 942xx (LDAP) | 9 | LDAP Injection attempt | +| 100323 | Remontée | 933xx\|934xx | 9 | PHP/Java Injection attempt | +| 100394 | Remontée | Freq(100320)×5/300s | 10 | SQLi anomaly scoring | +| 100396 | Remontée | Freq(100321)×2/60s | 12 | Command Injection CRITICAL | + +**Active Response :** +- SQLi Bloquée : `firewall-drop 6h` +- SQLi Brute-force : `firewall-drop 24h + host-deny permanent` +- Command Injection : `firewall-drop 24h + host-deny` +- Command Injection CRITICAL : `firewall-drop permanent + host-deny permanent` +- SQLi Remontée : `firewall-drop 2h` +- SQLi Anomaly : `firewall-drop 4h` +- Command Injection Remontée : `firewall-drop 4h` + +--- + +### OWASP #6 : Vulnerable & Outdated Components + +**Détecte :** RCE, Exploit attempts, known vulnerabilities + +| Rule ID | Type | Patterns | Level | Description | +|---------|------|----------|-------|-------------| +| 100230 | Bloqué | 930xx\|950xx | 14 | RCE/Exploit bloquée | +| 100330 | Remontée | 930xx\|950xx | 11 | RCE/Exploit attempt (warning) | + +**Active Response :** +- Bloqué : `firewall-drop 24h` +- Remontée : `firewall-drop 6h` + +--- + +### OWASP #7 : Authentication & Session Management + +**Détecte :** XSS, Header Injection, Session hijacking attempts + +| Rule ID | Type | Patterns | Level | Description | +|---------|------|----------|-------|-------------| +| 100240 | Bloqué | 941xx | 12 | XSS bloquée | +| 100241 | Bloqué | 955xx | 12 | Header Injection bloquée | +| 100291 | Bloqué | Freq(100240)×5/120s | 13 | XSS anomaly scoring | +| 100340 | Remontée | 941xx | 8 | XSS attempt (warning) | +| 100341 | Remontée | 955xx | 8 | Header Injection attempt | +| 100395 | Remontée | Freq(100340)×8/300s | 10 | XSS anomaly scoring | + +**Active Response :** +- XSS Bloquée : `firewall-drop 4h` +- XSS Anomaly : `firewall-drop 6h` +- Header Injection : `firewall-drop 6h` +- XSS Remontée : `firewall-drop 1h` +- Header Remontée : `firewall-drop 2h` + +--- + +### OWASP #8 : Software & Data Integrity Failures + +**Détecte :** XXE, Deserialization attacks + +| Rule ID | Type | Patterns | Level | Description | +|---------|------|----------|-------|-------------| +| 100260 | Bloqué | 943xx | 13 | XXE bloquée | +| 100360 | Remontée | 943xx | 9 | XXE attempt (warning) | + +**Active Response :** +- Bloqué : `firewall-drop 12h` +- Remontée : `firewall-drop 4h` + +--- + +### OWASP #9 : Logging & Monitoring Failures + +**Détecte :** Web scanners, bot activity, reconnaissance + +| Rule ID | Type | Patterns | Level | Description | +|---------|------|----------|-------|-------------| +| 100270 | Bloqué | 951xx\|954xx | 10 | Scanner detection (bloquée) | +| 100370 | Remontée | 951xx\|954xx | 6 | Scanner detection (warning) | + +**Active Response :** +- Bloqué : `firewall-drop 2h` +- Remontée : `firewall-drop 30min` + +--- + +### Autres : SSRF & File Upload + +| Rule ID | Type | Patterns | Level | Description | +|---------|------|----------|-------|-------------| +| 100280 | Bloqué | 970xx\|971xx | 13 | SSRF bloquée | +| 100281 | Bloqué | 953xx | 12 | File Upload bloquée | +| 100380 | Remontée | 970xx\|971xx | 9 | SSRF attempt | +| 100381 | Remontée | 953xx | 8 | File Upload attempt | + +**Active Response :** +- SSRF Bloquée : `firewall-drop 12h` +- File Upload Bloquée : `firewall-drop 6h` +- SSRF Remontée : `firewall-drop 4h` +- File Upload Remontée : `firewall-drop 2h` + +--- + +## Timeline des Active Responses + +### Bloquées (HTTP 403) + +| Durée | Règles | Motif | +|-------|--------|-------| +| Permanent | 100292 | Command Injection CRITICAL (2+ tentatives / 60s) | +| 24h | 100290 | SQLi brute-force (3+ / 60s) | +| 24h | 100230 | RCE/Exploit | +| 12h | 100251, 100260, 100280 | RFI, XXE, SSRF | +| 6h | 100220, 100221, 100250, 100252, 100281, 100330 | SQLi, LDAP, Path Traversal, File Access, Upload, RCE | +| 4h | 100240 | XSS | +| 2h | 100270 | Scanner | + +### Remontées (Anomaly Scoring) + +| Durée | Règles | Motif | +|-------|--------|-------| +| Permanent | 100396 | Command Injection (2+ / 60s) | +| 6h | 100395, 100330, 100351 | XSS anomaly, RCE, RFI | +| 4h | 100394, 100321, 100323, 100360, 100380 | SQLi anomaly, Cmd Inj, PHP/Java, XXE, SSRF | +| 2h | 100320, 100322, 100341, 100350, 100352, 100381 | SQLi, LDAP, Header Inj, Path Traversal, File Access, Upload | +| 30min | 100370 | Scanner | + +--- + +## Files + +- **`modsecurity_owasp_rules.xml`** — Définition des règles (100220-100396) +- **`ossec.conf`** — Active-response configs (firewall-drop, durées) +- **`firewall-monitoring-uber.sh`** — iptables pour autoriser trafic ModSec + +--- + +## Monitoring + +**Dashboard Wazuh :** + +1. **Alerts → Security Events → OWASP** +2. **Visualization:** + - Blocking rate (HTTP 403) + - Anomaly scoring trends + - Top attackers (srcip) + - Attack distribution by category + +**Logs:** + +```bash +# On monitoring-uber +tail -f /var/ossec/logs/alerts/alerts.json | grep -i "owasp\|100[23][0-9][0-9]" +``` + +--- + +## Tuning + +Les seuils de fréquence peuvent être ajustés : + +- **SQLi anomaly:** `frequency="5" timeframe="300"` → Réduire pour être plus agressif +- **XSS anomaly:** `frequency="8" timeframe="300"` → Augmenter pour réduire false positives +- **Command Injection:** `frequency="2" timeframe="60"` → Critique, ne pas modifier + +--- + +## Notes + +- **First-match semantics:** Wazuh évalue les règles par ID croissant → les règles bloquées (100220+) ont priorité sur les remontées (100320+) +- **Field matching:** Les patterns utilisent `` pour matcher les CRS rule IDs dans les logs ModSecurity +- **SCA suppressed:** Les alertes SCA (CIS benchmark) sont à level 0 (voir `local_sca_noise.xml`) +- **Persistence:** Tous les AR sont sauvegardés dans `iptables-save` → survient les reboots + diff --git a/monitoring/security/VPN_DEPLOYMENT_SUMMARY.md b/monitoring/security/VPN_DEPLOYMENT_SUMMARY.md new file mode 100644 index 00000000..b43ac34b --- /dev/null +++ b/monitoring/security/VPN_DEPLOYMENT_SUMMARY.md @@ -0,0 +1,258 @@ +# VPN Deployment Summary + +## Infrastructure + +| Role | Hostname | IP Public | IP VPN | Status | +|------|----------|-----------|--------|--------| +| **VPN Server** | vpn-uber | 45.150.111.158 | 10.0.0.1/24 | ✓ Active | +| **Monitoring** | monitoring-uber | 185.103.167.138 | 10.0.0.2/24 | ✓ Connected | +| **Admins** | (clients) | — | 10.0.0.3+ | Ready | + +--- + +## Server Credentials + +### VPN Server (vpn-uber) + +- **IP Public:** 45.150.111.158 +- **Port:** 51820/udp +- **Server Private Key:** (secured at `/etc/wireguard/privatekey`) +- **Server Public Key:** `VQa6g1foaXhJgYWbwyJ9R/EAmmXg0nOnhPhbIIPLlmg=` +- **Network:** 10.0.0.0/24 +- **Interface IP:** 10.0.0.1 + +**SSH Access:** +```bash +ssh root@45.150.111.158 +# Password: yqZ98EJL1h3ISlfT6l (from host.ini) +``` + +### Monitoring Server (monitoring-uber) + +- **IP Public:** 185.103.167.138 +- **VPN IP:** 10.0.0.2/24 +- **Status:** Connected to VPN ✓ +- **Firewall:** Configured (iptables) +- **Interface:** wg0 UP + +**SSH Access:** +```bash +ssh root@185.103.167.138 +# Password: rL9lY6YkcDQmfRuZ3Z (from host.ini) +``` + +--- + +## VPN Configuration + +### Firewall Rules + +**VPN Server (vpn-uber):** +``` +INPUT: + ✓ 22/tcp (SSH) + ✓ 51820/udp (WireGuard) + ✗ Everything else → REJECT + +OUTPUT: + ✓ All + +FORWARD: + ✓ wg0 interface (VPN traffic) + ✓ NAT masquerade (10.0.0.0/24 → Internet) +``` + +**Monitoring Server (monitoring-uber):** +``` +INPUT: + ✓ 1514/tcp FROM 185.103.166.119 (Prod agents) + ✓ 1514/tcp FROM 185.103.166.112 (Pre-prod agents) + ✓ 51820/udp (VPN) + ✓ 443/tcp FROM 10.0.0.0/24 (Wazuh Dashboard) + ✓ 8080/tcp FROM 10.0.0.0/24 (Dozzle) + ✓ 9090/tcp FROM 10.0.0.0/24 (Beszel) + ✓ 9000-9001/tcp FROM 10.0.0.0/24 (S3/RustFS) + ✗ Everything else → DROP + +OUTPUT: + ✓ All (Internet) +``` + +### WireGuard Routing + +``` +VPN Server (10.0.0.1) + ↓ +Monitoring (10.0.0.2) — Connected ✓ + ↓ +Admin Clients (10.0.0.3+) — Ready to connect +``` + +**Current Peers:** +``` +peer: 4WLn2BR9ZGhM195mIvLbZR7tP/mb7ks4+mZ5ppZ21xw= (monitoring-uber) + allowed ips: 10.0.0.2/32 + status: Connected ✓ (45ms latency, 0% loss) +``` + +--- + +## Services Accessible via VPN + +Once connected to VPN from admin client: + +| Service | URL | Port | Status | +|---------|-----|------|--------| +| **Wazuh Dashboard** | https://10.0.0.2 | 443 | ✓ (VPN only) | +| **Dozzle** | http://10.0.0.2:8080 | 8080 | ✓ (VPN only) | +| **Beszel** | http://10.0.0.2:9090 | 9090 | ✓ (VPN only) | +| **S3/RustFS Console** | http://10.0.0.2:9001 | 9001 | ✓ (VPN only) | +| **S3/RustFS API** | http://10.0.0.2:9000 | 9000 | ✓ (VPN only) | + +**Mode:** VPN + Internet normal (no kill switch) +- Admins can access services via VPN +- Admins keep normal Internet access +- If VPN drops → automatic fallback to Internet + +--- + +## Next Steps for Admins + +### 1. Generate Client Configs + +```bash +./wireguard-admin-client.sh admin1 45.150.111.158 "VQa6g1foaXhJgYWbwyJ9R/EAmmXg0nOnhPhbIIPLlmg=" +``` + +Creates: `admin1.conf` + +### 2. Add Client to VPN Server + +SSH to VPN server: +```bash +ssh root@45.150.111.158 +``` + +Then: +```bash +# Get client's public key from admin1.conf (PrivateKey → PublicKey) +wg set wg0 peer allowed-ips 10.0.0.3/32 +wg show +``` + +### 3. Admin Setup + +- Install WireGuard app (wireguard.com/install) +- Import admin1.conf +- Connect to VPN +- Test access to services + +--- + +## Testing + +### From Monitoring Server + +```bash +# Test VPN connection +ping 10.0.0.1 +# Response: 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=45.0 ms + +# Check VPN status +ip addr show wg0 +ip route show | grep wg0 + +# VPN traffic +tcpdump -i wg0 +``` + +### From VPN Server + +```bash +# Monitor active connections +wg show + +# Check interface +ip addr show wg0 + +# Verify firewall rules +iptables -L +iptables -L -t nat +``` + +--- + +## Troubleshooting + +### Monitoring not connecting to VPN + +```bash +# Check WireGuard daemon +ssh root@185.103.167.138 +systemctl status wg-quick@wg0 +journalctl -u wg-quick@wg0 -n 20 + +# Restart +systemctl restart wg-quick@wg0 +``` + +### VPN Server not accepting peers + +```bash +# On VPN server, verify WireGuard is running +wg show + +# Check if peer was added correctly +wg show wg0 + +# If not showing, re-add: +wg set wg0 peer allowed-ips 10.0.0.X/32 +``` + +### Admin client can't connect + +- Verify VPN server is listening: `netstat -ulnp | grep 51820` +- Verify firewall allows 51820/udp: `ufw status` or `iptables -L` +- Check client config has correct server IP and pubkey +- Try reconnecting after 2-3 seconds + +--- + +## Files & Scripts Used + +- `firewall-vpn-server.sh` — VPN server firewall (iptables) +- `wireguard-server-setup.sh` — WireGuard server install + config +- `firewall-monitoring-uber.sh` — Monitoring firewall (iptables) +- `wireguard-client-setup.sh` — WireGuard client install +- `wireguard-admin-client.sh` — Generate admin client configs +- `VPN_SETUP.md` — Full setup guide (phases 1-7) + +--- + +## Persistence + +All configurations survive reboot: + +- **Firewall:** `/etc/iptables/rules.v4` (loaded via iptables-restore) +- **WireGuard:** Enabled at boot via `systemctl enable wg-quick@wg0` +- **Routes:** Persistent in wg0 config + +--- + +## Security Notes + +- Firewall rules block unauthorized access +- WireGuard handshake: 45ms latency (acceptable) +- No kill switch enabled (VPN + Internet normal) +- Services (Wazuh, Dozzle, Beszel, S3) accessible ONLY via VPN +- Agents (prod/pre-prod) still have direct access to Wazuh manager (1514/tcp) + +--- + +## Status + +✓ VPN Server deployed on vpn-uber (45.150.111.158) +✓ Monitoring-uber connected to VPN (10.0.0.2) +✓ Firewall configured on both servers +✓ VPN connection tested (45ms, 0% loss) +✓ Ready for admin client setup diff --git a/monitoring/security/VPN_SETUP.md b/monitoring/security/VPN_SETUP.md new file mode 100644 index 00000000..46e11073 --- /dev/null +++ b/monitoring/security/VPN_SETUP.md @@ -0,0 +1,255 @@ +# VPN Setup for Monitoring Stack + +## Architecture + +``` +Internet (public) + ├─ [Prod/Pre-prod] (accessible) + │ └─→(1514/tcp)→ monitoring-uber (port ouvert) + │ + ├─ [VPN Server] (nouveau VPS, 1 CPU 2GB RAM) + │ └─ WireGuard 0.0.0.0:51820/udp + │ + └─ [monitoring-uber] (185.103.167.138) + ├─ Client VPN (10.0.0.2) + └─ Services: Wazuh, Dozzle, Beszel, S3 (VPN only) + +VPN Network: 10.0.0.0/24 +├─ VPN Server: 10.0.0.1 +├─ monitoring-uber: 10.0.0.2 +└─ Admins: 10.0.0.3+ +``` + +## Configuration + +**Mode:** VPN + Internet normal (pas de kill switch) +- Admins connectés au VPN → accès à services VPN (10.0.0.0/24) +- Admins gardent aussi accès à Internet normal (pas de restriction) +- Si VPN tombe → retrouvent Internet automatiquement + +--- + +## Implementation Steps + +### Phase 1: VPN Server Setup (nouveau VPS) + +```bash +# 1. Login to VPS +ssh root@ + +# 2. Run firewall setup +chmod +x /path/to/firewall-vpn-server.sh +./firewall-vpn-server.sh + +# 3. Setup WireGuard server +chmod +x /path/to/wireguard-server-setup.sh +./wireguard-server-setup.sh + +# Output will show: +# - Server Public Key (note this) +# - Example: aBcDeFgHiJkLmNoPqRsTuVwXyZ1234567890AbCdE= +``` + +Save the **Server Public Key** — you'll need it for clients. + +### Phase 2: monitoring-uber VPN Client + +```bash +# 1. Login to monitoring-uber +ssh root@185.103.167.138 + +# 2. Run firewall setup +chmod +x /path/to/firewall-monitoring-uber.sh +./firewall-monitoring-uber.sh + +# 3. Setup WireGuard client +# Syntax: wireguard-client-setup.sh +chmod +x /path/to/wireguard-client-setup.sh +./wireguard-client-setup.sh "" + +# Example: +# ./wireguard-client-setup.sh 123.45.67.89 "aBcDeFgHiJkLmNoPqRsTuVwXyZ1234567890AbCdE=" + +# Output will show: +# - Client Public Key (note this) +# - Example: XyZ9876543210AbCdEfGhIjKlMnOpQrStUvWxYz= +``` + +### Phase 3: Add monitoring-uber to VPN Server + +```bash +# Back on VPS, add monitoring-uber as a peer +ssh root@ + +# Use the Client Public Key from Phase 2 +wg set wg0 peer allowed-ips 10.0.0.2/32 + +# Verify +wg show + +# Example output: +# interface: wg0 +# public key: aBcDeFgHiJkLmNoPqRsTuVwXyZ1234567890AbCdE= +# private key: (hidden) +# listening port: 51820 +# +# peer: XyZ9876543210AbCdEfGhIjKlMnOpQrStUvWxYz= +# endpoint: :xxxxx +# allowed ips: 10.0.0.2/32 +# latest handshake: X seconds ago +# transfer: X B received, X B sent +``` + +### Phase 4: Verify VPN Connection + +```bash +# On monitoring-uber +ping 10.0.0.1 + +# Should respond +# PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. +# 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=XX.X ms + +# Check interface +ip addr show wg0 +``` + +### Phase 5: Rebind Services to VPN IP + +```bash +# On monitoring-uber +chmod +x /path/to/rebind-services-to-vpn.sh +./rebind-services-to-vpn.sh + +# This will update docker-compose-security.yml: +# - Wazuh Dashboard: 0.0.0.0:443 → 10.0.0.2:443 +# - Dozzle: 0.0.0.0:8080 → 10.0.0.2:8080 +# - Beszel: 0.0.0.0:9090 → 10.0.0.2:9090 +# - S3/RustFS: 0.0.0.0:9000/9001 → 10.0.0.2:9000/9001 +# - Wazuh Manager: stays on 0.0.0.0:1514 (for agents) + +# Restart services +cd /home/ubuntu/docker +docker compose -f docker-compose-security.yml down +docker compose -f docker-compose-security.yml up -d + +# Verify +docker ps +``` + +### Phase 6: Create Admin VPN Clients + +```bash +# Generate config for each admin +chmod +x /path/to/wireguard-admin-client.sh + +# Syntax: wireguard-admin-client.sh +./wireguard-admin-client.sh admin1 123.45.67.89 "aBcDeFgHiJkLmNoPqRsTuVwXyZ1234567890AbCdE=" +./wireguard-admin-client.sh admin2 123.45.67.89 "aBcDeFgHiJkLmNoPqRsTuVwXyZ1234567890AbCdE=" + +# Output: admin1.conf, admin2.conf + +# For each admin, add to VPN server: +ssh root@ +wg set wg0 peer allowed-ips 10.0.0.3/32 +wg set wg0 peer allowed-ips 10.0.0.4/32 + +# Verify +wg show +``` + +### Phase 7: Admin Connection + +Each admin: + +1. Download WireGuard app: https://www.wireguard.com/install/ +2. Import config file (admin1.conf, admin2.conf, etc.) +3. Connect to VPN +4. Access services: + - **Wazuh Dashboard**: https://10.0.0.2 + - **Dozzle**: http://10.0.0.2:8080 + - **Beszel**: http://10.0.0.2:9090 + - **S3/RustFS Console**: http://10.0.0.2:9001 + +## Firewall Rules Summary + +### VPS VPN Server + +| Protocol | Port | Source | Action | +|----------|------|--------|--------| +| UDP | 51820 | Any | ACCEPT (WireGuard) | +| TCP | 22 | Any | ACCEPT (SSH) | +| ICMP | echo-request | Any | ACCEPT | +| Any | Any | Any | REJECT | + +NAT masquerade enabled for VPN → Internet routing. + +### monitoring-uber (185.103.167.138) + +| Protocol | Port | Source | Action | +|----------|------|--------|--------| +| TCP | 1514 | 185.103.166.119 | ACCEPT (Prod Wazuh Agent) | +| TCP | 1514 | 185.103.166.112 | ACCEPT (Pre-prod Wazuh Agent) | +| UDP | 51820 | Any | ACCEPT (VPN) | +| TCP | 443 | 10.0.0.0/24 | ACCEPT (Wazuh Dashboard — VPN) | +| TCP | 8080 | 10.0.0.0/24 | ACCEPT (Dozzle — VPN) | +| TCP | 9090 | 10.0.0.0/24 | ACCEPT (Beszel — VPN) | +| TCP | 9000-9001 | 10.0.0.0/24 | ACCEPT (S3 — VPN) | +| TCP | 22 | Any | ACCEPT (SSH) | +| Any | Any | Any | DROP (Deny all) | + +## Troubleshooting + +### VPN connection not establishing + +```bash +# On monitoring-uber +systemctl status wg-quick@wg0 +journalctl -u wg-quick@wg0 -n 20 + +# Restart +systemctl restart wg-quick@wg0 +``` + +### Can't access services over VPN + +```bash +# On monitoring-uber, check bindings +netstat -tlnp | grep -E "(443|8080|9090|9000)" + +# Should show 10.0.0.2 (not 0.0.0.0) +``` + +### Wazuh agents can't connect + +Make sure firewall allows 1514/tcp from prod/pre-prod: + +```bash +# On monitoring-uber +iptables -L INPUT -v | grep 1514 +``` + +Should show rules for prod (185.103.166.119) and pre-prod (185.103.166.112). + +## Persistence & Boot + +All rules are saved with: +- `iptables-save` → `/etc/iptables/rules.v4` +- WireGuard: `systemctl enable wg-quick@wg0` + +Both survive reboots. + +## Next Steps + +- [ ] Deploy VPS VPN Server +- [ ] Run firewall + WireGuard setup on VPS +- [ ] Get Server Public Key +- [ ] Deploy firewall + WireGuard client on monitoring-uber +- [ ] Add monitoring-uber peer on VPS +- [ ] Verify VPN connection (ping 10.0.0.1) +- [ ] Rebind services to VPN IP +- [ ] Restart docker containers +- [ ] Generate admin client configs +- [ ] Add admin peers on VPS +- [ ] Test admin VPN connection +- [ ] Test service access (Wazuh, Dozzle, Beszel, S3) diff --git a/monitoring/security/admin1.conf b/monitoring/security/admin1.conf new file mode 100644 index 00000000..aa8490a2 --- /dev/null +++ b/monitoring/security/admin1.conf @@ -0,0 +1,10 @@ +[Interface] +Address = 10.0.0.3/32 +PrivateKey = ePPTC7QXatWQd9qZWmAqlgd+IskVQ9/7rvwsfUtosEs= +DNS = 8.8.8.8 + +[Peer] +PublicKey = VQa6g1foaXhJgYWbwyJ9R/EAmmXg0nOnhPhbIIPLlmg= +AllowedIPs = 10.0.0.0/24 +Endpoint = 45.150.111.158:51820 +PersistentKeepalive = 25 diff --git a/monitoring/docker-compose.yml b/monitoring/security/docker-compose-security.yml old mode 100644 new mode 100755 similarity index 61% rename from monitoring/docker-compose.yml rename to monitoring/security/docker-compose-security.yml index c7b968da..3190984f --- a/monitoring/docker-compose.yml +++ b/monitoring/security/docker-compose-security.yml @@ -1,5 +1,4 @@ services: - # ─── Dozzle ─────────────────────────────────────────────── dozzle: image: amir20/dozzle:latest container_name: dozzle @@ -10,11 +9,10 @@ services: environment: DOZZLE_AUTH_PROVIDER: simple DOZZLE_AUTH_TTL: 48h - DOZZLE_REMOTE_AGENT: "5.181.0.112:7007|demo-uber|VPS,185.234.9.102:7007|mln-uber|VPS" + DOZZLE_REMOTE_AGENT: "185.103.166.112:7007|pre-prod-uber|VPS,185.103.166.119:7007|prod-uber|VPS" networks: - monitoring_net - # ─── Nginx ──────────────────────────────────────────────── nginx: image: nginx:alpine container_name: monitoring_nginx @@ -29,10 +27,35 @@ services: depends_on: - dozzle - wazuh.dashboard + - beszel + networks: + - monitoring_net + + # ─── ClamAV Antivirus ──────────────────────────────────── + clamav: + image: clamav/clamav:stable + container_name: clamav + restart: unless-stopped + environment: + - FRESHCLAM_CHECKS=24 + - CLAMD_SCAN_MAX_FILESIZE=100M + volumes: + - clamav_data:/var/lib/clamav + - clamav_logs:/var/log/clamav + - /var/run/docker.sock:/var/run/docker.sock:ro + networks: + - monitoring_net + + # ─── Beszel Hub ─────────────────────────────────────────── + beszel: + image: henrygd/beszel:latest + container_name: beszel + restart: unless-stopped + volumes: + - beszel_data:/beszel_data networks: - monitoring_net - # ─── Wazuh Manager ──────────────────────────────────────── wazuh.manager: image: wazuh/wazuh-manager:4.14.5 hostname: wazuh.manager @@ -131,99 +154,11 @@ services: - wazuh.manager networks: - monitoring_net - rustfs_perm: - image: alpine:latest - container_name: rustfs_perm - volumes: - - /mnt/data:/data - command: chown -R 1000:1000 /data - rustfs: - image: rustfs/rustfs:latest - depends_on: - rustfs_perm: - condition: service_completed_successfully - hostname: rustfs - container_name: rustfs - restart: unless-stopped - volumes: - - /mnt/data:/data - environment: - - RUSTFS_ACCESS_KEY=${RUSTFS_ACCESS_KEY:-rustfsadmin} - - RUSTFS_SECRET_KEY=${RUSTFS_SECRET_KEY:-rustfsadmin} - - RUSTFS_SERVER_DOMAINS=rustfs.uber-stup.club - - RUSTFS_CONSOLE_ENABLE=true - - RUSTFS_ADDRESS=:9000 - - RUSTFS_CONSOLE_ADDRESS=:9001 - networks: - - monitoring_net - - # ─── Xavia OTA — PostgreSQL ─────────────────────────────── - xavia_db: - image: postgres:16-alpine - container_name: xavia_db - restart: unless-stopped - environment: - - POSTGRES_USER=${XAVIA_POSTGRES_USER:-xavia} - - POSTGRES_PASSWORD=${XAVIA_POSTGRES_PASSWORD} - - POSTGRES_DB=${XAVIA_POSTGRES_DB:-releases_db} - volumes: - - xavia_db_data:/var/lib/postgresql/data - networks: - - monitoring_net - - # ─── Xavia OTA ──────────────────────────────────────────── - xavia: - image: xaviaio/xavia-ota:latest - container_name: xavia - restart: unless-stopped - environment: - - HOST=https://ota.uber-stup.club - - BLOB_STORAGE_TYPE=local - - DB_TYPE=postgres - - ADMIN_PASSWORD=${XAVIA_ADMIN_PASSWORD} - - UPLOAD_KEY=${XAVIA_UPLOAD_KEY} - - PRIVATE_KEY_BASE_64=${XAVIA_PRIVATE_KEY_BASE_64} - - POSTGRES_USER=${XAVIA_POSTGRES_USER:-xavia} - - POSTGRES_PASSWORD=${XAVIA_POSTGRES_PASSWORD} - - POSTGRES_DB=${XAVIA_POSTGRES_DB:-releases_db} - - POSTGRES_HOST=xavia_db - - POSTGRES_PORT=5432 - volumes: - - xavia_blobs:/app/blobs - depends_on: - - xavia_db - networks: - - monitoring_net - # ─── Gitea ──────────────────────────────────────────────── - gitea: - image: gitea/gitea:latest - container_name: gitea - restart: unless-stopped - environment: - - USER_UID=1000 - - USER_GID=1000 - - GITEA__database__DB_TYPE=sqlite3 - - GITEA__server__DOMAIN=${GITEA_DOMAIN:-gitea.uber-stup.club} - - GITEA__server__ROOT_URL=https://${GITEA_DOMAIN:-gitea.uber-stup.club} - - GITEA__server__HTTP_PORT=3000 - - GITEA__service__DISABLE_REGISTRATION=${GITEA_DISABLE_REGISTRATION:-true} - - GITEA__service__REQUIRE_SIGNIN_VIEW=true - - GITEA__security__SECRET_KEY=${GITEA_SECRET_KEY} - - GITEA__security__INTERNAL_TOKEN=${GITEA_INTERNAL_TOKEN} - volumes: - - gitea_data:/data - networks: - - monitoring_net - networks: monitoring_net: driver: bridge volumes: - # Xavia - xavia_db_data: - xavia_blobs: - # Wazuh wazuh_api_configuration: wazuh_etc: wazuh_logs: @@ -237,5 +172,6 @@ volumes: filebeat_var: wazuh_indexer_data: nginx_logs: - # Gitea - gitea_data: + beszel_data: + clamav_data: + clamav_logs: diff --git a/monitoring/dozzle/users.yml b/monitoring/security/dozzle/users.yml old mode 100644 new mode 100755 similarity index 55% rename from monitoring/dozzle/users.yml rename to monitoring/security/dozzle/users.yml index e27627b4..7dfe9194 --- a/monitoring/dozzle/users.yml +++ b/monitoring/security/dozzle/users.yml @@ -2,5 +2,5 @@ users: admin: name: Admin email: admin@uber-stup.club - password: $2a$11$/JnHCr3JYFZxuoY5COpjM.2MMJUYyKsFmgu/5qphIrbDLVz1qTCOC + password: $2b$11$AOUC5QG2l8Ee0gUKIyZGKuHdL0iuvDa3C0bVAl2Gyt6Axx7.E/hHm roles: download diff --git a/monitoring/security/firewall-monitoring-uber.sh b/monitoring/security/firewall-monitoring-uber.sh new file mode 100644 index 00000000..6b4a1b24 --- /dev/null +++ b/monitoring/security/firewall-monitoring-uber.sh @@ -0,0 +1,106 @@ +#!/bin/bash +# ═══════════════════════════════════════════════════════════════════ +# Firewall monitoring-uber (185.103.167.138) +# ───────────────────────────────────────────────────────────────── +# INBOUND: +# • 1514/tcp FROM prod (185.103.166.119) — agents Wazuh +# • 1514/tcp FROM pre-prod (185.103.166.112) — agents Wazuh +# • 51820/udp — VPN WireGuard +# • 10.0.0.0/24 (VPN admins) → 443, 8080, 8090, 9000, 9001 +# • SSH: BLOCKED from prod/pre-prod/s3 (security hardening) +# ───────────────────────────────────────────────────────────────── +# OUTBOUND: +# • Tout (0.0.0.0/0) — Internet, updates, DNS +# • VPN vers VPS +# ═══════════════════════════════════════════════════════════════════ + +set -e + +echo "[*] Configurant firewall monitoring-uber..." + +# Flush des règles existantes +iptables -F +iptables -X +iptables -t nat -F +iptables -t nat -X +iptables -t mangle -F +iptables -t mangle -X + +# Politique par défaut +iptables -P INPUT DROP +iptables -P FORWARD DROP +iptables -P OUTPUT ACCEPT + +# ─── INPUT ──────────────────────────────────────────────────────── +# Loopback (services internes) +iptables -A INPUT -i lo -j ACCEPT + +# Established/Related +iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT + +# SSH (administration locale, bloquer depuis prod/pre-prod/s3) +iptables -A INPUT -p tcp --dport 22 -s 185.103.166.119 -j DROP # prod +iptables -A INPUT -p tcp --dport 22 -s 185.103.166.112 -j DROP # pre-prod +iptables -A INPUT -p tcp --dport 22 -s 80.96.58.164 -j DROP # s3 +iptables -A INPUT -p tcp --dport 22 -j ACCEPT # allow from other sources + +# ─── Agents Wazuh (prod + pre-prod) ──────────────────────────── +# Prod: 185.103.166.119 +iptables -A INPUT -p tcp --dport 1514 -s 185.103.166.119 -j ACCEPT + +# Pre-prod: 185.103.166.112 +iptables -A INPUT -p tcp --dport 1514 -s 185.103.166.112 -j ACCEPT + +# ─── VPN (WireGuard) ────────────────────────────────────────── +iptables -A INPUT -p udp --dport 51820 -j ACCEPT + +# ─── Services (accessibles via VPN seulement) ───────────────── +# Admins via VPN: 10.0.0.0/24 + +# Wazuh Dashboard (443/https) +iptables -A INPUT -p tcp --dport 443 -s 10.0.0.0/24 -j ACCEPT + +# Dozzle (8080/http) +iptables -A INPUT -p tcp --dport 8080 -s 10.0.0.0/24 -j ACCEPT + +# Beszel (8090/http) +iptables -A INPUT -p tcp --dport 8090 -s 10.0.0.0/24 -j ACCEPT + +# S3/RustFS (9000/9001) +iptables -A INPUT -p tcp --dport 9000 -s 10.0.0.0/24 -j ACCEPT +iptables -A INPUT -p tcp --dport 9001 -s 10.0.0.0/24 -j ACCEPT + +# ─── ICMP ───────────────────────────────────────────────────── +iptables -A INPUT -p icmp --icmp-type echo-request -j ACCEPT +iptables -A INPUT -p icmp --icmp-type destination-unreachable -j ACCEPT +iptables -A INPUT -p icmp --icmp-type time-exceeded -j ACCEPT + +# Reject le reste +iptables -A INPUT -j REJECT --reject-with icmp-host-prohibited + +# ─── FORWARD ────────────────────────────────────────────────── +# Blocker forward par défaut (services locaux, pas de transit) +iptables -A FORWARD -j REJECT --reject-with icmp-host-prohibited + +# ─── Sauvegarder ────────────────────────────────────────────── +mkdir -p /etc/iptables +iptables-save > /etc/iptables/rules.v4 + +echo "[✓] Firewall monitoring-uber configuré" +echo "" +echo "Règles appliquées (ALLOW) :" +echo " • SSH 22/tcp — from admin IPs only (BLOCKED from prod/pre-prod/s3)" +echo " • Wazuh 1514/tcp FROM prod (185.103.166.119) — agents Wazuh" +echo " • Wazuh 1514/tcp FROM pre-prod (185.103.166.112) — agents Wazuh" +echo " • VPN 51820/udp — WireGuard" +echo " • Wazuh Dashboard 443/tcp FROM 10.0.0.0/24 (VPN)" +echo " • Dozzle 8080/tcp FROM 10.0.0.0/24 (VPN)" +echo " • Beszel 8090/tcp FROM 10.0.0.0/24 (VPN)" +echo " • S3/RustFS 9000-9001/tcp FROM 10.0.0.0/24 (VPN)" +echo " • OUTPUT (Internet/DNS)" +echo "" +echo "Règles appliquées (DENY) :" +echo " • SSH 22/tcp FROM prod (185.103.166.119) — BLOCKED" +echo " • SSH 22/tcp FROM pre-prod (185.103.166.112) — BLOCKED" +echo " • SSH 22/tcp FROM s3 (80.96.58.164) — BLOCKED" +echo " • All other INPUT/FORWARD — default DROP" diff --git a/monitoring/security/firewall-vpn-server.sh b/monitoring/security/firewall-vpn-server.sh new file mode 100644 index 00000000..b580b657 --- /dev/null +++ b/monitoring/security/firewall-vpn-server.sh @@ -0,0 +1,80 @@ +#!/bin/bash +# ═══════════════════════════════════════════════════════════════════ +# Firewall VPS VPN Server (WireGuard) — vpn-uber (45.150.111.158) +# Allow: WireGuard (51820/udp), SSH (22/tcp), Beszel agent (10001/tcp from VPN) +# Reject: tout le reste +# NAT: masquerade pour routage VPN +# ═══════════════════════════════════════════════════════════════════ + +set -e + +echo "[*] Configurant firewall VPS VPN Server..." + +# Flush des règles existantes +iptables -F +iptables -X +iptables -t nat -F +iptables -t nat -X +iptables -t mangle -F +iptables -t mangle -X + +# Politique par défaut +iptables -P INPUT DROP +iptables -P FORWARD ACCEPT +iptables -P OUTPUT ACCEPT + +# ─── INPUT ──────────────────────────────────────────────────────── +# Loopback +iptables -A INPUT -i lo -j ACCEPT + +# Established/Related +iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT + +# SSH (administration) +iptables -A INPUT -p tcp --dport 22 -j ACCEPT + +# WireGuard +iptables -A INPUT -p udp --dport 51820 -j ACCEPT + +# Beszel Agent (10001/tcp) — accessible depuis VPN uniquement +iptables -A INPUT -p tcp --dport 10001 -s 10.0.0.0/24 -j ACCEPT + +# ICMP (ping, MTU discovery) +iptables -A INPUT -p icmp --icmp-type echo-request -j ACCEPT +iptables -A INPUT -p icmp --icmp-type destination-unreachable -j ACCEPT +iptables -A INPUT -p icmp --icmp-type time-exceeded -j ACCEPT + +# Reject le reste +iptables -A INPUT -j REJECT --reject-with icmp-host-prohibited + +# ─── FORWARD ────────────────────────────────────────────────────── +# VPN ↔ Internet +iptables -A FORWARD -i wg0 -j ACCEPT +iptables -A FORWARD -o wg0 -j ACCEPT +iptables -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT + +# ─── NAT ────────────────────────────────────────────────────────── +# Masquerade pour routage VPN +iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE + +# ─── Sauvegarder ────────────────────────────────────────────────── +mkdir -p /etc/iptables +iptables-save > /etc/iptables/rules.v4 + +# ─── IP Forwarding ──────────────────────────────────────────────── +sysctl -w net.ipv4.ip_forward=1 +grep -q "net.ipv4.ip_forward" /etc/sysctl.conf || echo "net.ipv4.ip_forward=1" >> /etc/sysctl.conf + +echo "[✓] Firewall VPS VPN Server configuré" +echo "" +echo "Règles appliquées (ALLOW) :" +echo " • SSH 22/tcp — administration" +echo " • WireGuard 51820/udp — VPN peers" +echo " • Beszel Agent 10001/tcp FROM 10.0.0.0/24 — monitoring dashboard" +echo " • ICMP (ping, MTU discovery)" +echo "" +echo "Configuration :" +echo " • FORWARD ACCEPT (VPN ↔ Internet routing)" +echo " • NAT masquerade activé (eth0)" +echo " • IP forwarding activé (net.ipv4.ip_forward=1)" +echo " • Default INPUT policy: DROP" diff --git a/monitoring/security/nginx/nginx-fixed.conf b/monitoring/security/nginx/nginx-fixed.conf new file mode 100644 index 00000000..db0cc6c3 --- /dev/null +++ b/monitoring/security/nginx/nginx-fixed.conf @@ -0,0 +1,74 @@ +worker_processes auto; + +events { + worker_connections 1024; +} + +http { + # Main HTTPS server + server { + listen 0.0.0.0:80 default_server; + listen [::]:80 default_server; + + return 301 https://$host$request_uri; + } + + server { + listen 0.0.0.0:443 ssl default_server; + listen [::]:443 ssl default_server; + + ssl_certificate /etc/nginx/certs/fullchain.pem; + ssl_certificate_key /etc/nginx/certs/privkey.pem; + ssl_protocols TLSv1.2 TLSv1.3; + ssl_ciphers HIGH:!aNULL:!MD5; + + # Wazuh (root) + location / { + proxy_pass https://wazuh.dashboard:5601/; + proxy_ssl_verify off; + proxy_http_version 1.1; + proxy_set_header Host wazuh.dashboard:5601; + proxy_set_header X-Real-IP $remote_addr; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Proto $scheme; + proxy_set_header Upgrade $http_upgrade; + proxy_set_header Connection "upgrade"; + proxy_read_timeout 300s; + proxy_hide_header Content-Security-Policy; + } + + # Dozzle + location /dozzle { + proxy_pass http://dozzle:8080; + proxy_http_version 1.1; + proxy_buffering off; + proxy_cache off; + proxy_set_header Host $host; + proxy_set_header X-Real-IP $remote_addr; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Proto $scheme; + proxy_redirect ~^http://dozzle:8080/(.*)$ /dozzle/$1; + proxy_redirect ~^/$/ /dozzle/; + proxy_read_timeout 3600s; + } + + # Beszel + location /beszel { + proxy_pass http://beszel:8090; + proxy_http_version 1.1; + proxy_set_header Upgrade $http_upgrade; + proxy_set_header Connection "upgrade"; + proxy_set_header Host $host; + proxy_set_header X-Real-IP $remote_addr; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Proto $scheme; + proxy_redirect ~^http://beszel:8090/(.*)$ /beszel/$1; + proxy_redirect ~^/$/ /beszel/; + sub_filter 'href="/' 'href="/beszel/'; + sub_filter 'src="/' 'src="/beszel/'; + sub_filter 'url(/' 'url(/beszel/'; + sub_filter_once off; + proxy_read_timeout 3600s; + } + } +} diff --git a/monitoring/security/nginx/nginx-simple.conf b/monitoring/security/nginx/nginx-simple.conf new file mode 100644 index 00000000..032e7534 --- /dev/null +++ b/monitoring/security/nginx/nginx-simple.conf @@ -0,0 +1,83 @@ +worker_processes auto; + +events { + worker_connections 1024; +} + +http { + resolver 127.0.0.11 valid=10s ipv6=off; + + upstream wazuh_backend { + server wazuh.dashboard:5601; + } + + upstream dozzle_backend { + server dozzle:8080; + } + + upstream beszel_backend { + server beszel:8090; + } + + # Redirect HTTP to HTTPS + server { + listen 80; + return 301 https://$host$request_uri; + } + + # Main HTTPS server + server { + listen 443 ssl default_server; + listen [::]:443 ssl default_server; + + ssl_certificate /etc/nginx/certs/fullchain.pem; + ssl_certificate_key /etc/nginx/certs/privkey.pem; + ssl_protocols TLSv1.2 TLSv1.3; + ssl_ciphers HIGH:!aNULL:!MD5; + + # Root redirects to /wazuh + location = / { + return 301 https://$host/wazuh; + } + + # Wazuh + location /wazuh/ { + proxy_pass https://wazuh_backend/; + proxy_ssl_verify off; + proxy_http_version 1.1; + proxy_set_header Host $host; + proxy_set_header X-Real-IP $remote_addr; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Proto $scheme; + proxy_set_header Upgrade $http_upgrade; + proxy_set_header Connection "upgrade"; + proxy_read_timeout 300s; + } + + # Dozzle + location /dozzle/ { + proxy_pass http://dozzle_backend/; + proxy_http_version 1.1; + proxy_buffering off; + proxy_cache off; + proxy_set_header Host $host; + proxy_set_header X-Real-IP $remote_addr; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Proto $scheme; + proxy_read_timeout 3600s; + } + + # Beszel + location /beszel/ { + proxy_pass http://beszel_backend/; + proxy_http_version 1.1; + proxy_set_header Upgrade $http_upgrade; + proxy_set_header Connection "upgrade"; + proxy_set_header Host $host; + proxy_set_header X-Real-IP $remote_addr; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Proto $scheme; + proxy_read_timeout 3600s; + } + } +} diff --git a/monitoring/nginx/nginx.conf b/monitoring/security/nginx/nginx.conf old mode 100644 new mode 100755 similarity index 52% rename from monitoring/nginx/nginx.conf rename to monitoring/security/nginx/nginx.conf index 0fb39eb0..cdfe0cdd --- a/monitoring/nginx/nginx.conf +++ b/monitoring/security/nginx/nginx.conf @@ -5,6 +5,8 @@ events { } http { + resolver 127.0.0.11 valid=10s ipv6=off; + # Redirect HTTP -> HTTPS server { listen 80; @@ -12,10 +14,70 @@ http { return 301 https://$host$request_uri; } + # ── Default server (by IP + path) ──────────────────────── + server { + listen 443 ssl default_server; + server_name _; + + ssl_certificate /etc/nginx/certs/fullchain.pem; + ssl_certificate_key /etc/nginx/certs/privkey.pem; + ssl_protocols TLSv1.2 TLSv1.3; + ssl_ciphers HIGH:!aNULL:!MD5; + + # Root → Wazuh Dashboard + location = / { + return 301 https://$host/wazuh; + } + + # /wazuh → Wazuh Dashboard + location /wazuh/ { + set $upstream https://wazuh.dashboard:5601; + proxy_pass $upstream; + proxy_ssl_verify off; + proxy_http_version 1.1; + proxy_set_header Host $host; + proxy_set_header X-Real-IP $remote_addr; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Proto $scheme; + proxy_set_header Upgrade $http_upgrade; + proxy_set_header Connection "upgrade"; + proxy_read_timeout 300s; + proxy_hide_header Content-Security-Policy; + } + + # /dozzle → Dozzle + location /dozzle/ { + set $upstream http://dozzle:8080; + proxy_pass $upstream; + proxy_http_version 1.1; + proxy_buffering off; + proxy_cache off; + proxy_set_header Host $host; + proxy_set_header X-Real-IP $remote_addr; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Proto $scheme; + proxy_read_timeout 3600s; + } + + # /beszel → Beszel + location /beszel/ { + set $upstream http://beszel:8090; + proxy_pass $upstream; + proxy_http_version 1.1; + proxy_set_header Upgrade $http_upgrade; + proxy_set_header Connection "upgrade"; + proxy_set_header Host $host; + proxy_set_header X-Real-IP $remote_addr; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Proto $scheme; + proxy_read_timeout 3600s; + } + } + # ── Dozzle ────────────────────────────────────────────── server { listen 443 ssl; - server_name dozzle.uber-stup.club; + server_name dozzle.demo-uber.xyz; ssl_certificate /etc/nginx/certs/fullchain.pem; ssl_certificate_key /etc/nginx/certs/privkey.pem; @@ -26,7 +88,8 @@ http { error_log /var/log/nginx/dozzle_error.log; location / { - proxy_pass http://dozzle:8080; + set $upstream http://dozzle:8080; + proxy_pass $upstream; proxy_http_version 1.1; proxy_set_header Connection ""; proxy_buffering off; @@ -39,113 +102,10 @@ http { } } - # ── RustFS Console ────────────────────────────────────── - server { - listen 443 ssl; - server_name rustfs.uber-stup.club; - - ssl_certificate /etc/nginx/certs/fullchain.pem; - ssl_certificate_key /etc/nginx/certs/privkey.pem; - ssl_protocols TLSv1.2 TLSv1.3; - ssl_ciphers HIGH:!aNULL:!MD5; - - access_log /var/log/nginx/rustfs_access.log; - error_log /var/log/nginx/rustfs_error.log; - - # Console web (port 9001) - location / { - proxy_pass http://rustfs:9001; - proxy_http_version 1.1; - proxy_set_header Host $host; - proxy_set_header X-Real-IP $remote_addr; - proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; - proxy_set_header X-Forwarded-Proto $scheme; - proxy_set_header Upgrade $http_upgrade; - proxy_set_header Connection "upgrade"; - proxy_read_timeout 300s; - client_max_body_size 500m; - } - } - - # ── RustFS S3 API ─────────────────────────────────────── - server { - listen 443 ssl; - server_name s3.uber-stup.club; - - ssl_certificate /etc/nginx/certs/fullchain.pem; - ssl_certificate_key /etc/nginx/certs/privkey.pem; - ssl_protocols TLSv1.2 TLSv1.3; - ssl_ciphers HIGH:!aNULL:!MD5; - - access_log /var/log/nginx/rustfs_s3_access.log; - error_log /var/log/nginx/rustfs_s3_error.log; - - location / { - proxy_pass http://rustfs:9000; - proxy_http_version 1.1; - proxy_set_header Host $http_host; - proxy_set_header X-Real-IP $remote_addr; - proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; - proxy_set_header X-Forwarded-Proto $scheme; - proxy_read_timeout 300s; - client_max_body_size 2g; - } - } - - # ── Xavia OTA ─────────────────────────────────────────── - server { - listen 443 ssl; - server_name ota.uber-stup.club; - - ssl_certificate /etc/nginx/certs/fullchain.pem; - ssl_certificate_key /etc/nginx/certs/privkey.pem; - ssl_protocols TLSv1.2 TLSv1.3; - ssl_ciphers HIGH:!aNULL:!MD5; - - access_log /var/log/nginx/xavia_access.log; - error_log /var/log/nginx/xavia_error.log; - - location / { - proxy_pass http://xavia:3000; - proxy_http_version 1.1; - proxy_set_header Host $host; - proxy_set_header X-Real-IP $remote_addr; - proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; - proxy_set_header X-Forwarded-Proto $scheme; - proxy_read_timeout 300s; - client_max_body_size 500m; - } - } - - # ── Gitea ─────────────────────────────────────────────── - server { - listen 443 ssl; - server_name gitea.uber-stup.club; - - ssl_certificate /etc/nginx/certs/fullchain.pem; - ssl_certificate_key /etc/nginx/certs/privkey.pem; - ssl_protocols TLSv1.2 TLSv1.3; - ssl_ciphers HIGH:!aNULL:!MD5; - - access_log /var/log/nginx/gitea_access.log; - error_log /var/log/nginx/gitea_error.log; - - location / { - proxy_pass http://gitea:3000; - proxy_http_version 1.1; - proxy_set_header Host $host; - proxy_set_header X-Real-IP $remote_addr; - proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; - proxy_set_header X-Forwarded-Proto $scheme; - proxy_read_timeout 300s; - client_max_body_size 100m; - } - } - # ── Wazuh Dashboard ───────────────────────────────────── server { listen 443 ssl; - server_name wazuh.uber-stup.club; + server_name wazuh.demo-uber.xyz; ssl_certificate /etc/nginx/certs/fullchain.pem; ssl_certificate_key /etc/nginx/certs/privkey.pem; @@ -156,7 +116,8 @@ http { error_log /var/log/nginx/wazuh_error.log; location / { - proxy_pass https://wazuh.dashboard:5601; + set $upstream https://wazuh.dashboard:5601; + proxy_pass $upstream; proxy_ssl_verify off; @@ -177,4 +138,31 @@ http { proxy_hide_header X-XSS-Protection; } } + + # ── Beszel ────────────────────────────────────────────── + server { + listen 443 ssl; + server_name beszel.demo-uber.xyz; + + ssl_certificate /etc/nginx/certs/fullchain.pem; + ssl_certificate_key /etc/nginx/certs/privkey.pem; + ssl_protocols TLSv1.2 TLSv1.3; + ssl_ciphers HIGH:!aNULL:!MD5; + + access_log /var/log/nginx/beszel_access.log; + error_log /var/log/nginx/beszel_error.log; + + location / { + set $upstream http://beszel:8090; + proxy_pass $upstream; + proxy_http_version 1.1; + proxy_set_header Upgrade $http_upgrade; + proxy_set_header Connection "upgrade"; + proxy_set_header Host $host; + proxy_set_header X-Real-IP $remote_addr; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Proto $scheme; + proxy_read_timeout 3600s; + } + } } diff --git a/monitoring/security/rebind-services-to-vpn.sh b/monitoring/security/rebind-services-to-vpn.sh new file mode 100644 index 00000000..f8e886ea --- /dev/null +++ b/monitoring/security/rebind-services-to-vpn.sh @@ -0,0 +1,61 @@ +#!/bin/bash +# ═══════════════════════════════════════════════════════════════════ +# Rebind services to private VPN IP (10.0.0.2) +# Services: Wazuh Dashboard, Dozzle, Beszel, S3/RustFS +# +# IMPORTANT: +# - Wazuh Manager stays on 0.0.0.0:1514 (agents need access) +# - Other services bind to 10.0.0.2 (VPN only) +# ═══════════════════════════════════════════════════════════════════ + +set -e + +VPN_IP="10.0.0.2" +COMPOSE_FILE="/home/ubuntu/docker/docker-compose-security.yml" + +if [ ! -f "$COMPOSE_FILE" ]; then + echo "[!] File not found: $COMPOSE_FILE" + exit 1 +fi + +echo "[*] Rebinding services to VPN IP ($VPN_IP)..." +echo " Config: $COMPOSE_FILE" + +# ─── Wazuh Dashboard (443) ──────────────────────────────────── +echo "[*] Updating Wazuh Dashboard (443)..." +sed -i 's|0\.0\.0\.0:443:|'"$VPN_IP"':443:|g' "$COMPOSE_FILE" + +# ─── Dozzle (8080) ──────────────────────────────────────────── +echo "[*] Updating Dozzle (8080)..." +sed -i 's|0\.0\.0\.0:8080:|'"$VPN_IP"':8080:|g' "$COMPOSE_FILE" + +# ─── Beszel (9090) ──────────────────────────────────────────── +echo "[*] Updating Beszel (9090)..." +sed -i 's|0\.0\.0\.0:9090:|'"$VPN_IP"':9090:|g' "$COMPOSE_FILE" + +# ─── RustFS / S3 (9000, 9001) ───────────────────────────────── +echo "[*] Updating RustFS/S3 (9000, 9001)..." +sed -i 's|0\.0\.0\.0:9000:|'"$VPN_IP"':9000:|g' "$COMPOSE_FILE" +sed -i 's|0\.0\.0\.0:9001:|'"$VPN_IP"':9001:|g' "$COMPOSE_FILE" + +# ─── Keep Wazuh Manager on 0.0.0.0:1514 ─────────────────────── +# (agents need public access) + +echo "" +echo "[✓] Services rebound to $VPN_IP" +echo "" +echo "Verify changes:" +grep -n "ports:" -A 2 "$COMPOSE_FILE" | grep -E "(443|8080|9090|9000|9001|1514)" || true + +echo "" +echo "Services now listening on:" +echo " • 0.0.0.0:1514 — Wazuh Manager (agents)" +echo " • $VPN_IP:443 — Wazuh Dashboard (VPN only)" +echo " • $VPN_IP:8080 — Dozzle (VPN only)" +echo " • $VPN_IP:9090 — Beszel (VPN only)" +echo " • $VPN_IP:9000/9001 — RustFS (VPN only)" +echo "" +echo "Next: Restart services" +echo " cd /home/ubuntu/docker" +echo " docker compose -f docker-compose-security.yml down" +echo " docker compose -f docker-compose-security.yml up -d" diff --git a/monitoring/wazuh/config/certs.yml b/monitoring/security/wazuh/config/certs.yml old mode 100644 new mode 100755 similarity index 100% rename from monitoring/wazuh/config/certs.yml rename to monitoring/security/wazuh/config/certs.yml diff --git a/monitoring/wazuh/config/wazuh_dashboard/opensearch_dashboards.yml b/monitoring/security/wazuh/config/wazuh_dashboard/opensearch_dashboards.yml old mode 100644 new mode 100755 similarity index 100% rename from monitoring/wazuh/config/wazuh_dashboard/opensearch_dashboards.yml rename to monitoring/security/wazuh/config/wazuh_dashboard/opensearch_dashboards.yml diff --git a/monitoring/security/wazuh/config/wazuh_indexer/internal_users.yml b/monitoring/security/wazuh/config/wazuh_indexer/internal_users.yml new file mode 100755 index 00000000..bd530c0f --- /dev/null +++ b/monitoring/security/wazuh/config/wazuh_indexer/internal_users.yml @@ -0,0 +1,45 @@ +--- +_meta: + type: "internalusers" + config_version: 2 + +admin: + hash: "$2b$12$lNbkFg7B3IN.BXwZHjztteTDd3hTIvT/kTJhRFqfUY/228Bw45POO" + reserved: true + backend_roles: + - "admin" + description: "Admin user" + +kibanaserver: + hash: "$2b$12$czi/zi7uht/K5.vcCvsXueFi6ot7GFwFfVBax7rCaNqBq1jhTOZ7u" + reserved: true + description: "Kibanaserver user" + +kibanaro: + hash: "$2b$12$lNbkFg7B3IN.BXwZHjztteTDd3hTIvT/kTJhRFqfUY/228Bw45POO" + reserved: false + backend_roles: + - "kibanauser" + - "readall" + description: "Kibana read-only user" + +logstash: + hash: "$2b$12$lNbkFg7B3IN.BXwZHjztteTDd3hTIvT/kTJhRFqfUY/228Bw45POO" + reserved: false + backend_roles: + - "logstash" + description: "Logstash user" + +readall: + hash: "$2b$12$lNbkFg7B3IN.BXwZHjztteTDd3hTIvT/kTJhRFqfUY/228Bw45POO" + reserved: false + backend_roles: + - "readall" + description: "Readall user" + +snapshotrestore: + hash: "$2b$12$lNbkFg7B3IN.BXwZHjztteTDd3hTIvT/kTJhRFqfUY/228Bw45POO" + reserved: false + backend_roles: + - "snapshotrestore" + description: "Snapshotrestore user" diff --git a/monitoring/wazuh/config/wazuh_indexer/wazuh.indexer.yml b/monitoring/security/wazuh/config/wazuh_indexer/wazuh.indexer.yml old mode 100644 new mode 100755 similarity index 100% rename from monitoring/wazuh/config/wazuh_indexer/wazuh.indexer.yml rename to monitoring/security/wazuh/config/wazuh_indexer/wazuh.indexer.yml diff --git a/monitoring/security/wazuh/config/wazuh_manager/decoders/modsecurity_decoder.xml b/monitoring/security/wazuh/config/wazuh_manager/decoders/modsecurity_decoder.xml new file mode 100755 index 00000000..b796f1e4 --- /dev/null +++ b/monitoring/security/wazuh/config/wazuh_manager/decoders/modsecurity_decoder.xml @@ -0,0 +1,4 @@ + + + UNUSED_MODSEC_PLACEHOLDER_NEVER_MATCHES + diff --git a/monitoring/wazuh/config/wazuh_manager/init.sh b/monitoring/security/wazuh/config/wazuh_manager/init.sh old mode 100644 new mode 100755 similarity index 100% rename from monitoring/wazuh/config/wazuh_manager/init.sh rename to monitoring/security/wazuh/config/wazuh_manager/init.sh diff --git a/monitoring/security/wazuh/config/wazuh_manager/localfile_clamav.conf b/monitoring/security/wazuh/config/wazuh_manager/localfile_clamav.conf new file mode 100644 index 00000000..88dc0476 --- /dev/null +++ b/monitoring/security/wazuh/config/wazuh_manager/localfile_clamav.conf @@ -0,0 +1,23 @@ + + + + + + syslog + /var/log/clamav/clamav.log + log + + + + + syslog + /var/log/clamav/freshclam.log + log + + + + + syslog + /var/log/clamav/alert.log + log + diff --git a/monitoring/wazuh/config/wazuh_manager/ossec.conf b/monitoring/security/wazuh/config/wazuh_manager/ossec.conf old mode 100644 new mode 100755 similarity index 56% rename from monitoring/wazuh/config/wazuh_manager/ossec.conf rename to monitoring/security/wazuh/config/wazuh_manager/ossec.conf index 881aea68..11c09c9f --- a/monitoring/wazuh/config/wazuh_manager/ossec.conf +++ b/monitoring/security/wazuh/config/wazuh_manager/ossec.conf @@ -317,6 +317,338 @@ 86400 + + + firewall-drop + local + 100300 + 3600 + + + + + firewall-drop + local + 100301 + 86400 + + + + + disable-account + local + 100310 + 7200 + + + + firewall-drop + local + 100310 + 21600 + + + + + + + firewall-drop + local + 100220 + 21600 + + + + + firewall-drop + local + 100290 + 86400 + + + + host-deny + local + 100290 + 0 + + + + + firewall-drop + local + 100221 + 21600 + + + + + firewall-drop + local + 100222 + 86400 + + + + host-deny + local + 100222 + 0 + + + + + firewall-drop + local + 100292 + 0 + + + + host-deny + local + 100292 + 0 + + + + + firewall-drop + local + 100223,100224 + 43200 + + + + + firewall-drop + local + 100230 + 86400 + + + + + firewall-drop + local + 100240 + 14400 + + + + + firewall-drop + local + 100291 + 86400 + + + + + firewall-drop + local + 100241 + 21600 + + + + + firewall-drop + local + 100250 + 21600 + + + + + firewall-drop + local + 100293 + 86400 + + + + + firewall-drop + local + 100251 + 43200 + + + + + firewall-drop + local + 100252 + 21600 + + + + + firewall-drop + local + 100260 + 43200 + + + + + firewall-drop + local + 100270 + 7200 + + + + + firewall-drop + local + 100280 + 43200 + + + + + firewall-drop + local + 100281 + 21600 + + + + + + + firewall-drop + local + 100320 + 7200 + + + + + firewall-drop + local + 100394 + 14400 + + + + + firewall-drop + local + 100321 + 14400 + + + + + firewall-drop + local + 100396 + 0 + + + + + firewall-drop + local + 100322,100323 + 7200 + + + + + firewall-drop + local + 100330 + 21600 + + + + + firewall-drop + local + 100340 + 3600 + + + + + firewall-drop + local + 100395 + 21600 + + + + + firewall-drop + local + 100341 + 7200 + + + + + firewall-drop + local + 100350 + 7200 + + + + + firewall-drop + local + 100351 + 14400 + + + + + firewall-drop + local + 100352 + 7200 + + + + + firewall-drop + local + 100360 + 14400 + + + + + firewall-drop + local + 100370 + 1800 + + + + + firewall-drop + local + 100380 + 14400 + + + + + firewall-drop + local + 100381 + 7200 + + no host-deny @@ -396,6 +728,302 @@ 21600 + + + firewall-drop + all + 100300 + 3600 + + + + + firewall-drop + all + 100301 + 86400 + + + + + + + firewall-drop + all + 100220 + 21600 + + + + + firewall-drop + all + 100290 + 86400 + + + + + firewall-drop + all + 100221 + 21600 + + + + + firewall-drop + all + 100222 + 86400 + + + + + firewall-drop + all + 100292 + 0 + + + + + firewall-drop + all + 100223,100224 + 43200 + + + + + firewall-drop + all + 100230 + 86400 + + + + + firewall-drop + all + 100240 + 14400 + + + + + firewall-drop + all + 100291 + 86400 + + + + + firewall-drop + all + 100241 + 21600 + + + + + firewall-drop + all + 100250 + 21600 + + + + + firewall-drop + all + 100293 + 86400 + + + + + firewall-drop + all + 100251 + 43200 + + + + + firewall-drop + all + 100252 + 21600 + + + + + firewall-drop + all + 100260 + 43200 + + + + + firewall-drop + all + 100270 + 7200 + + + + + firewall-drop + all + 100280 + 43200 + + + + + firewall-drop + all + 100281 + 21600 + + + + + + + firewall-drop + all + 100320 + 7200 + + + + + firewall-drop + all + 100394 + 14400 + + + + + firewall-drop + all + 100321 + 14400 + + + + + firewall-drop + all + 100396 + 0 + + + + + firewall-drop + all + 100322,100323 + 7200 + + + + + firewall-drop + all + 100330 + 21600 + + + + + firewall-drop + all + 100340 + 3600 + + + + + firewall-drop + all + 100395 + 21600 + + + + + firewall-drop + all + 100341 + 7200 + + + + + firewall-drop + all + 100350 + 7200 + + + + + firewall-drop + all + 100351 + 14400 + + + + + firewall-drop + all + 100352 + 7200 + + + + + firewall-drop + all + 100360 + 14400 + + + + + firewall-drop + all + 100370 + 1800 + + + + + firewall-drop + all + 100380 + 14400 + + + + + firewall-drop + all + 100381 + 7200 + + diff --git a/monitoring/security/wazuh/config/wazuh_manager/rules/clamav_rules.xml b/monitoring/security/wazuh/config/wazuh_manager/rules/clamav_rules.xml new file mode 100644 index 00000000..c03025a5 --- /dev/null +++ b/monitoring/security/wazuh/config/wazuh_manager/rules/clamav_rules.xml @@ -0,0 +1,143 @@ + + + + syslog + clam + ClamAV message grouping + + + + + 100500 + FOUND|Infected|detected + ClamAV: Malware detected - $(var malware_name) + malware,clamav,infection + + + + + 100500 + Trojan|PUA|unwanted|grayware + ClamAV: Potentially Unwanted Application detected + malware,clamav,pua + + + + + 100500 + \.Virus\.|\.Win\.|\.Linux\.|\.Worm\.|\.Backdoor + ClamAV: Virus detected - High severity + malware,clamav,virus + + + + + 100500 + Ransomware|Encrypted|Cryptolocker|BadRabbit|WannaCry + ClamAV: Ransomware detected + malware,clamav,ransomware + + + + + 100500 + freshclam + ClamAV update completed successfully|updated + ClamAV: Signature database updated successfully + clamav,updates + + + + + 100500 + freshclam + ERROR|Failed|error downloading|connection failed|timeout + ClamAV: Signature update failed + clamav,updates,error + + + + + 100500 + clamd + ERROR|error|CRITICAL + ClamAV: Daemon error + clamav,error + + + + + 100500 + Scanning started|initializing scanner + ClamAV: Scanning started + clamav,scanning + + + + + 100500 + Scanning finished|scan completed + ClamAV: Scanning completed + clamav,scanning + + + + + 100500 + corrupted|corrupt file|damaged|unreadable + ClamAV: Corrupted file detected + clamav,corruption + + + + + 100500 + quarantine|moved|removed|deleted|archived + ClamAV: File quarantined/removed + clamav,quarantine,action + + + + + 100500 + infects|infected files|detected + ClamAV: Scan statistics + clamav,statistics + + + + + 100500 + Permission denied|access denied|unable to scan + ClamAV: Permission denied when scanning file + clamav,access + + + + + 100500 + database error|bad database|corrupt database|outdated database + ClamAV: Database problem detected + clamav,database,error + + + + + 100501 + 33600 + + ClamAV: Multiple malware detections in short time - possible outbreak + malware,clamav,outbreak + + + + + 100501 + 100504 + + 300 + ClamAV: Ransomware and virus detected together - critical threat + malware,clamav,ransomware,critical + + + diff --git a/monitoring/security/wazuh/config/wazuh_manager/rules/local_active_response_rules.xml b/monitoring/security/wazuh/config/wazuh_manager/rules/local_active_response_rules.xml new file mode 100644 index 00000000..ea942f32 --- /dev/null +++ b/monitoring/security/wazuh/config/wazuh_manager/rules/local_active_response_rules.xml @@ -0,0 +1,45 @@ + + + + + + + + 5716 + + SSH: brute-force — 3 mots de passe faux en 60s depuis $(srcip) + authentication_failures,ssh_brute, + + + + + 5710 + + SSH: scan de comptes — 3 users inexistants en 60s depuis $(srcip) + authentication_failures,ssh_scan, + + + + + + + + + + 5401 + + Sudo: 3 échecs d'auth en 5 min — tentative d'escalade de privilèges + authentication_failures,sudo_brute, + + + diff --git a/monitoring/security/wazuh/config/wazuh_manager/rules/local_modsecurity_rules.xml b/monitoring/security/wazuh/config/wazuh_manager/rules/local_modsecurity_rules.xml new file mode 100755 index 00000000..706803a5 --- /dev/null +++ b/monitoring/security/wazuh/config/wazuh_manager/rules/local_modsecurity_rules.xml @@ -0,0 +1,39 @@ + + + + + + + json + modsec_audit.log + \.+ + ModSecurity: WAF event capturé + web,modsecurity, + + + + + 100100 + ^403$ + ModSecurity: accès bloqué (403) — $(transaction.client_ip) → $(transaction.request.uri) + web,modsecurity,attack,blocked, + + + + + 100100 + ModSecurity: règle WAF déclenchée (non bloqué) — $(transaction.client_ip) + web,modsecurity,attack, + + + + + 100102 + ModSecurity: blocages répétés — possible scan ou attaque soutenue + web,modsecurity,attack,blocked, + + + diff --git a/monitoring/security/wazuh/config/wazuh_manager/rules/local_sca_noise.xml b/monitoring/security/wazuh/config/wazuh_manager/rules/local_sca_noise.xml new file mode 100644 index 00000000..fa1c4085 --- /dev/null +++ b/monitoring/security/wazuh/config/wazuh_manager/rules/local_sca_noise.xml @@ -0,0 +1,113 @@ + + + + + + + 19000 + ^summary + no_full_log + SCA summary — supprimé (voir onglet SCA du dashboard). + + + + 19001 + ^8\d + no_full_log + SCA summary: score < 90% — supprimé. + + + + 19001 + ^7\d|^6\d|^5\d + no_full_log + SCA summary: score < 80% — supprimé. + + + + 19001 + ^4\d|^3\d + no_full_log + SCA summary: score < 50% — supprimé. + + + + 19001 + ^2\d|^1\d$|^\d$ + no_full_log + SCA summary: score < 30% — supprimé. + + + + + 19006 + ^failed + no_full_log + SCA check failed — supprimé. + + + + 19006 + ^passed + no_full_log + SCA check passed — supprimé. + + + + 19006 + ^not applicable + no_full_log + SCA check not applicable — supprimé. + + + + + 19008 + ^failed + no_full_log + SCA: failed → passed — supprimé. + + + + 19007 + ^passed + no_full_log + SCA: passed → failed — supprimé. + + + + 19009 + ^passed + no_full_log + SCA: passed → not applicable — supprimé. + + + + 19009 + ^failed + no_full_log + SCA: failed → not applicable — supprimé. + + + + 19007 + ^not applicable + no_full_log + SCA: not applicable → failed — supprimé. + + + + 19008 + ^not applicable + no_full_log + SCA: not applicable → passed — supprimé. + + + diff --git a/monitoring/wazuh/config/wazuh_manager/rules/local_ssh_pam_noise.xml b/monitoring/security/wazuh/config/wazuh_manager/rules/local_ssh_pam_noise.xml old mode 100644 new mode 100755 similarity index 85% rename from monitoring/wazuh/config/wazuh_manager/rules/local_ssh_pam_noise.xml rename to monitoring/security/wazuh/config/wazuh_manager/rules/local_ssh_pam_noise.xml index 018c2579..cd719a7a --- a/monitoring/wazuh/config/wazuh_manager/rules/local_ssh_pam_noise.xml +++ b/monitoring/security/wazuh/config/wazuh_manager/rules/local_ssh_pam_noise.xml @@ -107,28 +107,27 @@ + IMPORTANT: PLACEHOLDER_NEVER_MATCHES au lieu de . + pour éviter que ces rules catch-all bloquent l'évaluation des rules avec + un ID plus élevé (first-match semantics dans Wazuh). --> - . - Suricata: malicious domain — non applicable (pas d'agent Suricata). + WAZUH_PLACEHOLDER_SURICATA_NEVER_MATCHES + Suricata: malicious domain — overwrite placeholder (non applicable). - . - Suricata: malicious domain DNS — non applicable. + WAZUH_PLACEHOLDER_SURICATA_DNS_NEVER_MATCHES + Suricata: malicious domain DNS — overwrite placeholder (non applicable). - . - Windows: failed logon malicious IP — non applicable (pas d'agent Windows). + WAZUH_PLACEHOLDER_WINDOWS_FAILED_NEVER_MATCHES + Windows: failed logon malicious IP — overwrite placeholder (non applicable). - . - Windows: successful logon malicious IP — non applicable. + WAZUH_PLACEHOLDER_WINDOWS_SUCCESS_NEVER_MATCHES + Windows: successful logon malicious IP — overwrite placeholder (non applicable). diff --git a/monitoring/security/wazuh/config/wazuh_manager/rules/modsecurity_owasp_rules.xml b/monitoring/security/wazuh/config/wazuh_manager/rules/modsecurity_owasp_rules.xml new file mode 100644 index 00000000..0b69068e --- /dev/null +++ b/monitoring/security/wazuh/config/wazuh_manager/rules/modsecurity_owasp_rules.xml @@ -0,0 +1,352 @@ + + + + + + + + + + + 100102 + 942[0-9] + OWASP#3 SQL Injection bloquée — $(transaction.client_ip) → $(transaction.request.uri) + owasp_injection,sql_injection, + + + + + 100102 + 942[0-9].*LDAP\|ldap_filter + OWASP#3 LDAP Injection bloquée — $(transaction.client_ip) → $(transaction.request.uri) + owasp_injection,ldap_injection, + + + + + 100102 + 932[0-9] + OWASP#3 Remote Command Injection bloquée — $(transaction.client_ip) → $(transaction.request.uri) + owasp_injection,command_injection,rce, + + + + + 100102 + 933[0-9] + OWASP#3 PHP Injection bloquée — $(transaction.client_ip) → $(transaction.request.uri) + owasp_injection,php_injection, + + + + + 100102 + 934[0-9] + OWASP#3 Java Injection bloquée — $(transaction.client_ip) → $(transaction.request.uri) + owasp_injection,java_injection, + + + + + + + 100102 + 930[0-9]\|950[0-9] + OWASP#6 RCE / Exploit attempt bloquée — $(transaction.client_ip) → $(transaction.request.uri) + owasp_vulnerable_components,rce,exploit, + + + + + + + 100102 + 941[0-9] + OWASP#7 XSS attack bloquée — $(transaction.client_ip) → $(transaction.request.uri) + owasp_auth,xss,session_theft, + + + + + 100102 + 955[0-9] + OWASP#7 HTTP Header Injection bloquée — $(transaction.client_ip) → $(transaction.request.uri) + owasp_auth,header_injection, + + + + + + + 100102 + 930[0-9].*\(path\|traversal\|lfi\) + OWASP#1 Path Traversal / LFI bloquée — $(transaction.client_ip) → $(transaction.request.uri) + owasp_access_control,lfi,path_traversal, + + + + + 100102 + 930[0-9].*\(rfi\|remote\|include\) + OWASP#1 Remote File Inclusion bloquée — $(transaction.client_ip) → $(transaction.request.uri) + owasp_access_control,rfi, + + + + + 100102 + 952[0-9] + OWASP#1 Unauthorized File Access bloquée — $(transaction.client_ip) → $(transaction.request.uri) + owasp_access_control,file_access, + + + + + + + 100102 + 943[0-9] + OWASP#8 XML External Entity (XXE) bloquée — $(transaction.client_ip) → $(transaction.request.uri) + owasp_data_integrity,xxe, + + + + + + + 100102 + 951[0-9]\|954[0-9] + OWASP#9 Web Scanner / Bot detected — $(transaction.client_ip) + owasp_monitoring,scanner_detection, + + + + + + + 100102 + 970[0-9]\|971[0-9] + OWASP Server-Side Request Forgery (SSRF) bloquée — $(transaction.client_ip) → $(transaction.request.uri) + owasp_misc,ssrf, + + + + + 100102 + 953[0-9] + OWASP Insecure File Upload bloquée — $(transaction.client_ip) → $(transaction.request.uri) + owasp_misc,file_upload, + + + + + + + 100220 + OWASP#3 SQL Injection brute-force — $(transaction.client_ip) tentatives répétées + owasp_injection,sql_injection,brute_force, + + + + + 100240 + OWASP#7 XSS attack pattern — $(transaction.client_ip) attaque soutenue + owasp_auth,xss, + + + + + 100222 + OWASP#3 Command Injection attempts — $(transaction.client_ip) CRITICAL + owasp_injection,command_injection,critical, + + + + + 100250 + OWASP#1 Path Traversal brute-force — $(transaction.client_ip) + owasp_access_control,lfi,brute_force, + + + + + + + 100100 + 942[0-9] + OWASP#3 SQL Injection attempt (anomaly scoring) — $(transaction.client_ip) → $(transaction.request.uri) + owasp_injection,sql_injection,warning, + + + + + 100100 + 932[0-9] + OWASP#3 Command Injection attempt — $(transaction.client_ip) → $(transaction.request.uri) + owasp_injection,command_injection,warning, + + + + + 100100 + 942[0-9].*LDAP\|ldap_filter + OWASP#3 LDAP Injection attempt — $(transaction.client_ip) → $(transaction.request.uri) + owasp_injection,ldap_injection,warning, + + + + + 100100 + 933[0-9]\|934[0-9] + OWASP#3 Code Injection attempt (PHP/Java) — $(transaction.client_ip) → $(transaction.request.uri) + owasp_injection,code_injection,warning, + + + + + 100100 + 930[0-9]\|950[0-9] + OWASP#6 RCE / Exploit attempt — $(transaction.client_ip) → $(transaction.request.uri) + owasp_vulnerable_components,rce,warning, + + + + + 100100 + 941[0-9] + OWASP#7 XSS attempt (anomaly scoring) — $(transaction.client_ip) → $(transaction.request.uri) + owasp_auth,xss,warning, + + + + + 100100 + 955[0-9] + OWASP#7 HTTP Header Injection attempt — $(transaction.client_ip) → $(transaction.request.uri) + owasp_auth,header_injection,warning, + + + + + 100100 + 930[0-9].*\(path\|traversal\|lfi\) + OWASP#1 Path Traversal attempt — $(transaction.client_ip) → $(transaction.request.uri) + owasp_access_control,lfi,warning, + + + + + 100100 + 930[0-9].*\(rfi\|remote\|include\) + OWASP#1 Remote File Inclusion attempt — $(transaction.client_ip) → $(transaction.request.uri) + owasp_access_control,rfi,warning, + + + + + 100100 + 952[0-9] + OWASP#1 Unauthorized File Access attempt — $(transaction.client_ip) → $(transaction.request.uri) + owasp_access_control,file_access,warning, + + + + + 100100 + 943[0-9] + OWASP#8 XML External Entity (XXE) attempt — $(transaction.client_ip) → $(transaction.request.uri) + owasp_data_integrity,xxe,warning, + + + + + 100100 + 951[0-9]\|954[0-9] + OWASP#9 Web Scanner / Bot detected — $(transaction.client_ip) + owasp_monitoring,scanner_detection,warning, + + + + + 100100 + 970[0-9]\|971[0-9] + OWASP Server-Side Request Forgery (SSRF) attempt — $(transaction.client_ip) → $(transaction.request.uri) + owasp_misc,ssrf,warning, + + + + + 100100 + 953[0-9] + OWASP Insecure File Upload attempt — $(transaction.client_ip) → $(transaction.request.uri) + owasp_misc,file_upload,warning, + + + + + + + 100320 + OWASP#3 SQL Injection anomaly scoring — $(transaction.client_ip) tentatives répétées + owasp_injection,sql_injection,anomaly, + + + + + 100340 + OWASP#7 XSS anomaly scoring — $(transaction.client_ip) attaque soutenue + owasp_auth,xss,anomaly, + + + + + 100321 + OWASP#3 Command Injection attempts — $(transaction.client_ip) CRITICAL + owasp_injection,command_injection,anomaly, + + + diff --git a/monitoring/security/wazuh/config/wazuh_manager/rules/modsecurity_rules.xml b/monitoring/security/wazuh/config/wazuh_manager/rules/modsecurity_rules.xml new file mode 100755 index 00000000..b22bca25 --- /dev/null +++ b/monitoring/security/wazuh/config/wazuh_manager/rules/modsecurity_rules.xml @@ -0,0 +1,44 @@ + + + + + + + 100102 + SQL Injection\|SQLi\|942[0-9] + ModSecurity: SQL Injection bloquée — $(transaction.client_ip) → $(transaction.request.uri) + modsecurity_sqli,sql_injection, + + + + + 100102 + XSS\|941[0-9] + ModSecurity: XSS bloqué — $(transaction.client_ip) → $(transaction.request.uri) + modsecurity_xss,xss, + + + + + 100102 + RCE\|930[0-9]\|932[0-9] + ModSecurity: tentative RCE bloquée — $(transaction.client_ip) → $(transaction.request.uri) + modsecurity_rce,rce, + + + + + 100102 + LFI\|930[0-9] + ModSecurity: LFI bloqué — $(transaction.client_ip) → $(transaction.request.uri) + modsecurity_lfi,lfi, + + + + + 100102 + ModSecurity: blocages répétés en 2 min — attaque soutenue + modsecurity_repeated, + + + diff --git a/monitoring/wazuh/generate-certs.sh b/monitoring/security/wazuh/generate-certs.sh similarity index 100% rename from monitoring/wazuh/generate-certs.sh rename to monitoring/security/wazuh/generate-certs.sh diff --git a/monitoring/security/wireguard-admin-client.sh b/monitoring/security/wireguard-admin-client.sh new file mode 100755 index 00000000..dddee41a --- /dev/null +++ b/monitoring/security/wireguard-admin-client.sh @@ -0,0 +1,68 @@ +#!/bin/bash +# ═══════════════════════════════════════════════════════════════════ +# Generate WireGuard client config for admin +# Usage: wireguard-admin-client.sh +# Output: admin_name.conf (ready for import in WireGuard app) +# ═══════════════════════════════════════════════════════════════════ + +set -e + +ADMIN_NAME="${1:-admin1}" +VPN_SERVER_IP="${2:-}" +VPN_SERVER_PUBKEY="${3:-}" + +if [ -z "$VPN_SERVER_IP" ] || [ -z "$VPN_SERVER_PUBKEY" ]; then + echo "Usage: $0 " + echo "" + echo "Example:" + echo " $0 admin1 123.45.67.89 'aBcDeFgHiJkLmNoPqRsTuVwXyZ1234567890AbCdE='" + exit 1 +fi + +echo "[*] Generating WireGuard config for admin: $ADMIN_NAME" + +# ─── Generate unique keys for this admin ─────────────────────── +ADMIN_PRIVATEKEY=$(wg genkey) +ADMIN_PUBKEY=$(echo "$ADMIN_PRIVATEKEY" | wg pubkey) + +# ─── Auto-assign IP from 10.0.0.3+ ───────────────────────────── +# Format: [admin_name].conf uses 10.0.0.3, 10.0.0.4, etc. +# You should track these manually or use a database +ADMIN_IP="10.0.0.3" # ← CHANGE THIS for each admin + +# ─── Create config file ──────────────────────────────────────── +cat > "${ADMIN_NAME}.conf" << EOF +[Interface] +Address = $ADMIN_IP/32 +PrivateKey = $ADMIN_PRIVATEKEY +DNS = 8.8.8.8 + +[Peer] +PublicKey = $VPN_SERVER_PUBKEY +AllowedIPs = 10.0.0.0/24 +Endpoint = $VPN_SERVER_IP:51820 +PersistentKeepalive = 25 +EOF + +echo "[✓] Config created: ${ADMIN_NAME}.conf" +echo "" +echo "Configuration:" +echo " Name: $ADMIN_NAME" +echo " IP: $ADMIN_IP" +echo " Public Key: $ADMIN_PUBKEY" +echo "" +echo "Steps to add to VPN server:" +echo " 1. Copy public key above" +echo " 2. SSH to VPN server" +echo " 3. wg set wg0 peer $ADMIN_PUBKEY allowed-ips $ADMIN_IP/32" +echo " 4. wg show" +echo "" +echo "To import on your device:" +echo " 1. Install WireGuard app (Windows/Mac/Linux/iPhone/Android)" +echo " 2. Import ${ADMIN_NAME}.conf" +echo " 3. Connect to VPN" +echo " 4. Access services:" +echo " • Wazuh: https://10.0.0.2" +echo " • Dozzle: http://10.0.0.2:8080" +echo " • Beszel: http://10.0.0.2:9090" +echo " • S3: http://10.0.0.2:9000" diff --git a/monitoring/security/wireguard-client-setup.sh b/monitoring/security/wireguard-client-setup.sh new file mode 100644 index 00000000..b5b52061 --- /dev/null +++ b/monitoring/security/wireguard-client-setup.sh @@ -0,0 +1,104 @@ +#!/bin/bash +# ═══════════════════════════════════════════════════════════════════ +# WireGuard Client Setup (monitoring-uber) +# Install WireGuard, generate client keys, auto-connect to VPN server +# Client IP: 10.0.0.2/24 +# ═══════════════════════════════════════════════════════════════════ + +set -e + +# ─── Parameters ──────────────────────────────────────────────────── +VPN_SERVER_IP="${1:-}" # IP publique du serveur VPN +VPN_SERVER_PUBKEY="${2:-}" # Clé publique du serveur VPN + +if [ -z "$VPN_SERVER_IP" ] || [ -z "$VPN_SERVER_PUBKEY" ]; then + echo "Usage: $0 " + echo "" + echo "Example:" + echo " $0 123.45.67.89 'aBcDeFgHiJkLmNoPqRsTuVwXyZ1234567890AbCdE='" + exit 1 +fi + +echo "[*] Setting up WireGuard Client on monitoring-uber..." +echo " Server IP: $VPN_SERVER_IP" +echo " Server Pubkey: $VPN_SERVER_PUBKEY" + +# ─── Install WireGuard ───────────────────────────────────────── +echo "[*] Installing WireGuard..." +apt-get update -qq +apt-get install -y wireguard wireguard-tools + +# ─── Create key directory ────────────────────────────────────── +mkdir -p /etc/wireguard +cd /etc/wireguard +umask 077 + +# ─── Generate client keys ────────────────────────────────────── +if [ ! -f client_privatekey ]; then + echo "[*] Generating client private key..." + wg genkey > client_privatekey + cat client_privatekey | wg pubkey > client_publickey + echo "[✓] Keys generated" + echo "" + echo "Client Public Key (for server):" + cat client_publickey + echo "" +else + echo "[!] Client keys already exist" +fi + +# ─── Create wg0 configuration ────────────────────────────────── +echo "[*] Creating WireGuard client configuration..." + +PRIVATE_KEY=$(cat client_privatekey) +CLIENT_PUBKEY=$(cat client_publickey) + +cat > wg0.conf << EOF +[Interface] +# monitoring-uber VPN IP +Address = 10.0.0.2/24 +ListenPort = 0 +PrivateKey = $PRIVATE_KEY + +[Peer] +# VPN Server +PublicKey = $VPN_SERVER_PUBKEY +AllowedIPs = 10.0.0.0/24 +Endpoint = $VPN_SERVER_IP:51820 +PersistentKeepalive = 25 +EOF + +chmod 600 wg0.conf + +echo "[✓] Configuration created at /etc/wireguard/wg0.conf" + +# ─── Enable at boot and start ────────────────────────────────── +echo "[*] Enabling WireGuard at boot..." +systemctl enable wg-quick@wg0 2>/dev/null || true +systemctl start wg-quick@wg0 + +sleep 2 + +# Vérifier connexion +if ip addr show wg0 &>/dev/null; then + echo "[✓] WireGuard interface up" + ip addr show wg0 +else + echo "[!] WireGuard interface not up, check logs:" + journalctl -u wg-quick@wg0 -n 10 +fi + +echo "" +echo "[✓] WireGuard Client configured" +echo "" +echo "Configuration Summary:" +echo " • Interface: wg0" +echo " • Client IP: 10.0.0.2/24" +echo " • Server: $VPN_SERVER_IP:51820" +echo " • Config: /etc/wireguard/wg0.conf" +echo "" +echo "IMPORTANT: Add this client public key to VPN server:" +echo " wg set wg0 peer $(cat client_publickey) allowed-ips 10.0.0.2/32" +echo "" +echo "Verify connection:" +echo " ping 10.0.0.1" diff --git a/monitoring/security/wireguard-server-setup.sh b/monitoring/security/wireguard-server-setup.sh new file mode 100644 index 00000000..88b18e10 --- /dev/null +++ b/monitoring/security/wireguard-server-setup.sh @@ -0,0 +1,89 @@ +#!/bin/bash +# ═══════════════════════════════════════════════════════════════════ +# WireGuard Server Setup (VPS VPN) +# Install WireGuard, generate server keys, configure interface +# Network: 10.0.0.0/24 +# Server IP: 10.0.0.1 +# Listen: 0.0.0.0:51820/udp +# ═══════════════════════════════════════════════════════════════════ + +set -e + +echo "[*] Setting up WireGuard Server..." + +# ─── Install WireGuard ───────────────────────────────────────── +echo "[*] Installing WireGuard..." +apt-get update -qq +apt-get install -y wireguard wireguard-tools + +# ─── Create key directory ────────────────────────────────────── +mkdir -p /etc/wireguard +cd /etc/wireguard +umask 077 + +# ─── Generate server keys ────────────────────────────────────── +if [ ! -f privatekey ]; then + echo "[*] Generating server private key..." + wg genkey > privatekey + cat privatekey | wg pubkey > publickey + echo "[✓] Keys generated" + echo "" + echo "Server Public Key:" + cat publickey + echo "" +else + echo "[!] Server keys already exist" +fi + +# ─── Create wg0 configuration ────────────────────────────────── +echo "[*] Creating WireGuard interface configuration..." + +cat > wg0.conf << 'EOF' +[Interface] +# Server IP dans le réseau VPN +Address = 10.0.0.1/24 +ListenPort = 51820 + +# Charger la clé privée +PrivateKey = PRIVATE_KEY_PLACEHOLDER + +# Accepter VPN traffic +PostUp = iptables -I FORWARD 1 -i %i -j ACCEPT; iptables -I FORWARD 1 -o %i -j ACCEPT; iptables -t nat -I POSTROUTING 1 -o eth0 -j MASQUERADE +PostDown = iptables -D FORWARD -i %i -j ACCEPT; iptables -D FORWARD -o %i -j ACCEPT; iptables -t nat -D POSTROUTING -o eth0 -j MASQUERADE + +# Peers: monitoring-uber, admins (ajouté après) +EOF + +# Remplacer placeholder par clé réelle +PRIVATE_KEY=$(cat privatekey) +sed -i "s|PRIVATE_KEY_PLACEHOLDER|$PRIVATE_KEY|" wg0.conf + +# ─── Enable WireGuard interface ──────────────────────────────── +echo "[*] Bringing up WireGuard interface..." +ip link add dev wg0 type wireguard +ip addr add 10.0.0.1/24 dev wg0 +ip link set wg0 up +wg set wg0 private-key <(cat privatekey) +wg set wg0 listen-port 51820 + +# ─── Enable at boot ─────────────────────────────────────────── +echo "[*] Enabling WireGuard at boot..." +systemctl enable wg-quick@wg0 2>/dev/null || true +systemctl start wg-quick@wg0 2>/dev/null || true + +echo "" +echo "[✓] WireGuard Server configured" +echo "" +echo "Configuration Summary:" +echo " • Interface: wg0" +echo " • Server IP: 10.0.0.1/24" +echo " • Listen: 0.0.0.0:51820/udp" +echo " • Config: /etc/wireguard/wg0.conf" +echo "" +echo "Server Public Key (for clients):" +cat publickey +echo "" +echo "Next steps:" +echo " 1. Create client configs with wg-quick or manually" +echo " 2. Add peers to wg0:" +echo " wg set wg0 peer allowed-ips 10.0.0.X/32" diff --git a/monitoring/wazuh/config/wazuh_manager/decoders/modsecurity_decoder.xml b/monitoring/wazuh/config/wazuh_manager/decoders/modsecurity_decoder.xml deleted file mode 100644 index 24768c91..00000000 --- a/monitoring/wazuh/config/wazuh_manager/decoders/modsecurity_decoder.xml +++ /dev/null @@ -1,35 +0,0 @@ - - - - - {"transaction":{ - - - - - docker-waf-modsec - "client_ip":"(\d+\.\d+\.\d+\.\d+)".+"uri":"([^"]+)".+"http_code":403.+"ruleId":"(\d+)" - srcip,url,id - - - - - docker-waf-modsec - "client_ip":"(\d+\.\d+\.\d+\.\d+)".+"uri":"([^"]+)".+"ruleId":"(\d+)" - srcip,url,id - - - - - docker-waf-modsec - "client_ip":"(\d+\.\d+\.\d+\.\d+)".+"uri":"([^"]+)" - srcip,url - diff --git a/monitoring/wazuh/config/wazuh_manager/rules/local_modsecurity_rules.xml b/monitoring/wazuh/config/wazuh_manager/rules/local_modsecurity_rules.xml deleted file mode 100644 index e8c99b6d..00000000 --- a/monitoring/wazuh/config/wazuh_manager/rules/local_modsecurity_rules.xml +++ /dev/null @@ -1,37 +0,0 @@ - - - - - - - docker-waf-modsec-pass - ModSecurity: trafic légitime (supprimé). - - - - - docker-waf-modsec-rule - ModSecurity: règle $(id) — $(srcip) → $(url) - web,modsecurity,attack, - - - - - docker-waf-modsec-blocked - ModSecurity: accès bloqué (403) — $(srcip) → $(url) [règle $(id)] - web,modsecurity,attack,blocked, - - - - - 100102 - - ModSecurity: blocages répétés depuis $(srcip) — scan ou attaque - web,modsecurity,attack,blocked, - - - diff --git a/monitoring/wazuh/config/wazuh_manager/rules/modsecurity_rules.xml b/monitoring/wazuh/config/wazuh_manager/rules/modsecurity_rules.xml deleted file mode 100644 index 058d1f52..00000000 --- a/monitoring/wazuh/config/wazuh_manager/rules/modsecurity_rules.xml +++ /dev/null @@ -1,94 +0,0 @@ - - - - - - - modsecurity-block - ModSecurity: requête bloquée ($(extra_data)) sur $(url) - modsecurity_block, - - - - - modsecurity-warning - ModSecurity: alerte $(extra_data) sur $(url) - modsecurity_warning, - - - - - - - 100200 - SQL Injection - ModSecurity: SQL Injection détecté depuis $(srcip) sur $(url) - modsecurity_sqli,sql_injection, - - - - - 100200 - XSS - ModSecurity: XSS détecté depuis $(srcip) sur $(url) - modsecurity_xss,xss, - - - - - 100200 - RCE - ModSecurity: tentative RCE depuis $(srcip) sur $(url) - modsecurity_rce,rce, - - - - - 100200 - LFI - ModSecurity: LFI détecté depuis $(srcip) sur $(url) - modsecurity_lfi,lfi, - - - - - 100200 - Critical anomaly score\|anomaly score - ModSecurity: score d'anomalie critique depuis $(srcip) - modsecurity_anomaly, - - - - - 100200 - IP is banned\|ip.banned - ModSecurity: IP bannie $(srcip) tente un accès - modsecurity_banned, - - - - - modsecurity-block - 429 - ModSecurity: rate-limit déclenché depuis $(srcip) - modsecurity_ratelimit, - - - - - - 100200 - - ModSecurity: $(srcip) bloqué 5 fois en 2 min — attaque soutenue - modsecurity_repeated, - - -