Главная
Study mode:
on
1
Introduction
2
Christian Folini
3
Why use a Web Application Firewall
4
What is ModSecurity
5
Rules on Top
6
How does it work
7
Levels of paranoia
8
How does that look
9
Confirmed
10
Anomaly Scoring
11
Demo
12
Problem false positives
13
Summary
14
Questions
15
Custom Response
16
Rule Updates
17
How to manage this on enterprise level
18
Karraza
19
Dust
20
payload
21
antiautomation
22
plugins
Description:
Explore the fundamentals of web application security in this 44-minute webinar presented by Christian Folini at Nullcon. Delve into the OWASP ModSecurity Core Rule Set (CRS), a powerful open-source tool designed to protect web applications from a wide range of attacks. Learn about the concept of Web Application Firewalls (WAFs), the ModSecurity engine, and key CRS features such as paranoia levels, stricter siblings, and anomaly scoring. Witness a live demonstration of the ruleset's detection capabilities and gain insights into managing false positives, custom responses, and rule updates in enterprise environments. Benefit from Folini's extensive experience in high-security ModSecurity configuration, DDoS defense, and threat modeling as he bridges complex technical concepts with his unique background in medieval history.

Introduction to the OWASP ModSecurity Core Rule Set

nullcon
Add to list