Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Tin Zaw -- ModSecurity and #AppSec

23 min17 oktober 2017

Om avsnittet

A web application firewall can buy time during a vulnerability crisis, but only if somebody understands and maintains its rules. Tin Zaw explains ModSecurity and the Core Rule Set, starting with where a WAF sits between users and an application. He distinguishes the rule engine from the rules themselves, describes embedded and proxy deployments, and explains how detection, blocking, and logging serve different purposes. The conversation uses the Apache Struts vulnerabilities as an example of virtual patching while a team prepares a software update. Chris and Robert also ask about writing signatures, sharing rules, tuning false positives, and the risks of adding another component to the stack. Tin closes with practical starting points for learning and contributing to open-source application protection.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Tin Zaw:
Tin Zaw on LinkedIn

Mentioned in this episode:
ModSecurity
OWASP Core Rule Set
Apache Struts

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 ModSecurity and application security with Tin Zaw
01:11 Tin’s security origin story
02:33 Contributing to OWASP projects
03:59 What a web application firewall does
04:42 Embedded and proxy WAF deployments
06:32 The ModSecurity engine and Core Rule Set
08:27 Using and extending security rules
09:31 Detection, blocking, logging, and virtual patching
11:19 Responding to an Apache Struts vulnerability
13:18 Writing signatures from vulnerability information
14:40 Sharing rules with the community
15:36 Tuning false positives and maintaining the WAF
17:37 Why choose an open-source WAF?
18:30 Managing the WAF’s own attack surface
19:59 Getting started and finding resources

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.