Tin Zaw -- ModSecurity and #AppSec episode artwork

EPISODE · Oct 17, 2017 · 22 MIN

Tin Zaw -- ModSecurity and #AppSec

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

A web application firewall can buy time during a vulnerability crisis, but only if somebody understands and maintains its rules. Tin Zaw explains ModSecurity and the Core Rule Set, starting with where a WAF sits between users and an application. He distinguishes the rule engine from the rules themselves, describes embedded and proxy deployments, and explains how detection, blocking, and logging serve different purposes. The conversation uses the Apache Struts vulnerabilities as an example of virtual patching while a team prepares a software update. Chris and Robert also ask about writing signatures, sharing rules, tuning false positives, and the risks of adding another component to the stack. Tin closes with practical starting points for learning and contributing to open-source application protection.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Tin Zaw:→ Tin Zaw on LinkedInMentioned in this episode:→ ModSecurity→ OWASP Core Rule Set→ Apache StrutsFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 ModSecurity and application security with Tin Zaw01:11 Tin’s security origin story02:33 Contributing to OWASP projects03:59 What a web application firewall does04:42 Embedded and proxy WAF deployments06:32 The ModSecurity engine and Core Rule Set08:27 Using and extending security rules09:31 Detection, blocking, logging, and virtual patching11:19 Responding to an Apache Struts vulnerability13:18 Writing signatures from vulnerability information14:40 Sharing rules with the community15:36 Tuning false positives and maintaining the WAF17:37 Why choose an open-source WAF?18:30 Managing the WAF’s own attack surface19:59 Getting started and finding resources

Episode metadata supplied by the publisher feed · Published Oct 17, 2017

Embed this episode

A web application firewall can buy time during a vulnerability crisis, but only if somebody understands and maintains its rules. Tin Zaw explains ModSecurity and the Core Rule Set, starting with where a WAF sits between users and an application. He distinguishes the rule engine from the rules themselves, describes embedded and proxy deployments, and explains how detection, blocking, and logging serve different purposes. The conversation uses the Apache Struts vulnerabilities as an example of ...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Tin Zaw -- ModSecurity and #AppSec

0:00 22:59

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 22 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on October 17, 2017.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!