AppSec EU 2017 Introducing The OWASP ModSecurity Core Rule Set 3 0 by Christian Folini

preview_player
Показать описание
The CRS is a set of generic attack detection rules for use with ModSecurity or compatible web application firewalls that saw a new major release in November 2016 (3.0 vs GR; CRS3). CRS is the 1st line of defense against web application attacks like those summarized in the OWASP Top Ten and all with a minimum of false alerts.

This talk demonstrates the installation of the rule set and introduces the most important groups of rules. It covers key concepts like anomaly scoring and thresholds, paranoia levels, stricter siblings and the sampling mode. The important handling of false positives is also covered as well as pre-defined lists of rule exclusions for popular web applications helping to avoid false positives.

-

Рекомендации по теме
Комментарии
Автор

Great talk! Thanks Christian and everyone contributing to the project. (Great questions in the end so thanks for those as well :D)

DickSvensson
Автор

thank you, very informative, very organised

nikosc
Автор

Anyone know how to config the owasp in complex wordpress woocommerce site here. Please give me the sample work config file to me please, i have already setup on my site, but it is always false positive error with permission deny on backend i use owasp version 3.2 apache 2.4.xx, php7. 4.xx, httpv2. it often says: You dont have the permission to access that page.

othaibounheng
Автор

Where or How can we set the paranoia levels?

bitstop
Автор

How to combine modsecurity with iptables? I mean, if modsecurity block request, i need to block this ip in iptables?

MyChannel-X
Автор

Does mod_security have any overlapping rules with AppSensor? Edit: I can now see from appsensor's documentation that they do.

nikosc