EPISODE · Oct 17, 2017 · 22 MIN
Tin Zaw -- ModSecurity and #AppSec
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
A web application firewall can buy time during a vulnerability crisis, but only if somebody understands and maintains its rules. Tin Zaw explains ModSecurity and the Core Rule Set, starting with where a WAF sits between users and an application. He distinguishes the rule engine from the rules themselves, describes embedded and proxy deployments, and explains how detection, blocking, and logging serve different purposes. The conversation uses the Apache Struts vulnerabilities as an example of virtual patching while a team prepares a software update. Chris and Robert also ask about writing signatures, sharing rules, tuning false positives, and the risks of adding another component to the stack. Tin closes with practical starting points for learning and contributing to open-source application protection.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Tin Zaw:→ Tin Zaw on LinkedInMentioned in this episode:→ ModSecurity→ OWASP Core Rule Set→ Apache StrutsFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 ModSecurity and application security with Tin Zaw01:11 Tin’s security origin story02:33 Contributing to OWASP projects03:59 What a web application firewall does04:42 Embedded and proxy WAF deployments06:32 The ModSecurity engine and Core Rule Set08:27 Using and extending security rules09:31 Detection, blocking, logging, and virtual patching11:19 Responding to an Apache Struts vulnerability13:18 Writing signatures from vulnerability information14:40 Sharing rules with the community15:36 Tuning false positives and maintaining the WAF17:37 Why choose an open-source WAF?18:30 Managing the WAF’s own attack surface19:59 Getting started and finding resources
Embed this episode
What this episode covers
A web application firewall can buy time during a vulnerability crisis, but only if somebody understands and maintains its rules. Tin Zaw explains ModSecurity and the Core Rule Set, starting with where a WAF sits between users and an application. He distinguishes the rule engine from the rules themselves, describes embedded and proxy deployments, and explains how detection, blocking, and logging serve different purposes. The conversation uses the Apache Struts vulnerabilities as an example of ...
Ready to play
Tin Zaw -- ModSecurity and #AppSec
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.