Главная
Study mode:
on
1
Intro
2
Brief History of WAF's
3
Purpose of WAF's
4
Problems with WAF's
5
Bypassing WAF'S
6
Sanwaf: Application-Level Security Control
7
Purpose of Sanwaf
8
Bypass Example A cookie is being blocked by a WWF and is causing an issue, so
9
Sanwaf Does Not Replace WAF's
10
Sanitizing Data
11
How Sanwaf Works
12
Sanwaf Structure
13
Global Settings
14
Shield Settings
15
Regex Settings
16
Metadata Settings
17
Sanwaf Datatypes
18
Sanwaf: How it works
19
Sanwaf: How Strings Work
20
Sanwaf Datatype Performance
21
Example - Delimited Set of Numbers
22
Datatype Example: Delimited Set of Numbers (RegEx)
23
Datatype Example: Alphanumeric and Whitelisted
24
Datatype Example: Using a lava Class
25
Datatype Example: String & Regex
26
Implementing Sanwaf
27
Sample Implementation: Filter
28
Sample Implementation: Logging
29
Error Message Example
30
Rending Error to End User
31
Sample Application
32
Where to Git Sanwaf
33
Contact Information
Description:
Explore the evolution, purpose, and limitations of Web Application Firewalls (WAFs) in this 38-minute OWASP Foundation conference talk. Learn about WAF bypassing techniques and discover Sanwaf, an application-level security control. Dive into Sanwaf's structure, functionality, and implementation, including global settings, shield settings, regex settings, and metadata settings. Examine various datatype examples and performance considerations. Gain insights on sanitizing data, implementing filters and logging, and handling error messages. Access a sample application and learn where to find Sanwaf for implementation in your own projects.

Extending WAFs at the Application Layer

OWASP Foundation
Add to list