bretlowery · @bretlowery
3 followers · 23 posts · Server infosec.exchange

Would like to know how anyone using is solving for the lack of proper visualization and analytics at scale. Anyone else have multiple sites with over 500M requests/day or WAF logs in the trillions/day? Splunk/SIEM is a pricey answer.

#awswaf

Last updated 2 years ago

bretlowery · @bretlowery
1 followers · 7 posts · Server infosec.exchange

is missing quite a few longer-tail user agents in the list of valid browser user agents behind its SignalNonBrowserUserAgent rule. Recommend you change this from the OOTB BLOCK setting to CAPTCHA or COUNT for now, and extensively review your logs for FPs and report them to AWS as found.

#awswaf #AWSWAFBotControl

Last updated 2 years ago

Xavier Ashe :donor: · @Xavier
581 followers · 589 posts · Server infosec.exchange

From @securityaffairs: Experts devised a technique to web application firewalls () of several vendors.

"The researchers verifies that the bypass attack technique also worked against firewalls from other vendors, including , , Imperva, and Networks."



securityaffairs.co/wordpress/1

#bypass #waf #cloudflare #f5 #paloalto #awswaf #infosec #wafbypass

Last updated 2 years ago

vPierre · @vPierre
18 followers · 477 posts · Server mas.to

RT @Crowd_Security@twitter.com

🎉 We've released the CrowdSec AWS WAF bouncer to protect your web applications! 🥳
✔️ The bouncer syncs the decisions made by CrowdSec to one or multiple Web ACL
✔️ Supports ban and captcha decisions on IP or countries

Learn more 👉 crowdsec.net/blog/protect-your

🐦🔗: twitter.com/Crowd_Security/sta

#awswaf

Last updated 3 years ago