Posts

Showing posts with the label FTW

Ftw - Framework For Testing Wafs

Image
This projection was created past times researchers from ModSecurity together with Fastly to help render rigorous tests for WAF rules. It uses the OWASP Core Ruleset V3 every bit a baseline to exam rules on a WAF. Each dominion from the ruleset is loaded into a YAML file that issues HTTP requests that volition trigger these rules. Users tin verify the execution of the dominion later on the tests are issued to brand certain the expected reply is received from an attack. Goals / Use cases include: Find regressions inwards WAF deployments past times using continuous integration together with issuing repeatable attacks to a WAF Provide a testing framework for novel rules into ModSecurity, if a dominion is submitted it MUST accept corresponding positive & negative tests Evaluate WAFs against a common, agreeable baseline ruleset (OWASP) Test together with verify custom rules for WAFs that are non business office of the heart dominion set For our 1.0 loose announcement,...