Главная
Study mode:
on
1
Intro
2
What is FTW
3
Goals of FTW
4
How we do FTW
5
Real Rule
6
How we use FTW
7
Stop Go Message
8
Core Ruleset
9
Ruleset Tests
10
Commit Tests
11
PowerPoint Presentation
12
Christian
13
Fastly
14
Issues
15
Chaining
16
Bypass
17
Session Fixation
18
Tool Chain
19
Future Steps
20
Additional Resources
Description:
Explore a modern DevOps approach to security testing Web Application Firewalls (WAFs) in this conference talk from AppSecUSA 2017. Learn about the Framework for Testing WAFs (FTW) project, which provides an extendable framework for objectively reviewing WAF effectiveness. Discover how to design and implement tests using YAML format, leveraging the OWASP Core Ruleset Version 3 as a benchmark for web attacks and defenses. Gain insights into the architecture of the code, including the use of Py.test for testing and continuous integration strategies. Examine real-world use cases, including regression testing for the ModSecurity team and shipping WAF rules for customers on the edge. Understand the importance of applying security to the Software Development Life Cycle (SDLC) of WAF deployments and explore the journaling feature for comprehensive pentest reports.

WAFs FTW! A Modern DevOps Approach to Security Testing Your WAF

OWASP Foundation
Add to list
0:00 / 0:00