open-appsec NGINX WAF Tutorial

preview_player
Показать описание

open-appsec is designed for simple setup and painless maintenance. Thanks to machine learning, there is no threat signature upkeep and exception handling, like common in many WAF solutions. It can be deployed as add-on to Kubernetes Ingress, NGINX, Envoy and API Gateways.

In this tutorial we will show how to protect Web applications & APIs in just a few minutes using a demo web application called Acme Audit that has multiple security vulnerabilities.

• You will learn how to Attack the application by performing a SQL Injection (a simple attack just for demo purpose).
• Deploy open-appsec for NGINX Ingress and protect it
• Attack the application again to see that the protection is effective
• Connect your deployment to the SaaS Web-Based Management

Рекомендации по теме
Комментарии
Автор

This is very interesting. I am attempting to distribute a version of Nginx-Proxy-Manager with this WAF instead of modsec.

baudneo
Автор

Thnks for the video but i want to install the package i have unsupported version nginx (my version is 1.18.0-6ubuntu 14.3)
Any help please?

mimiatech
Автор

nice video I was able to deploy openapp sec on a cluster on aws but I dont know how to view the gui following the documentation any help please I will appreciate @openappsec

Eunice-js
Автор

Well that was a creepy video. I think I would happily run this if it was a touch more obvious how to actually do things not just have it run scripts for me. I need to inject this stuff into some nginx containers I already run and just need to know the bits to put where.

ChamunksArkturus
Автор

Wow, a fully AI video, interesting choice. Perhaps tweak on your voice model a bit, it can't pronounce some of the key terms properly, and the intenation is weird. Also, the model of the girl is too still. Makes for a distracting experience.

randomexperiences
welcome to shbcf.ru