Integrating Vulnerability Scanning and Web Application Firewalls
Subject: Integrating Vulnerability Scanning and Web Application Firewalls
Newsgroups: gmane.comp.apache.mod-security.user
Date: 2008-05-05 19:57:08 GMT
Just wanted to send out this FYI to the list – Breach Security and Whitehat Security jointly released this announcement today -
The short, short overview is this – the Whitehat Sentinel vulnerability scanning service will “automatically” create custom ModSecurity rules to block SQL Injection, XSS and Directory Traversal attacks in scanned web applications. ModSecurity users (both open source and commercial) can then simply insert these rules into their config and start blocking exploit attempts. For those of you who have been fighting the uphill battle of creating custom virtual patching rules with ModSecurity while simultaneously adding exceptions for false positives due to the generic nature of the Core Rule Set, then this integration announcement should be welcomed news J
As a reference, I urge anyone who might consider utilizing this integration to also read this previous Blog post on the topic of VA+WAF integration - http://jeremiahgrossman.blogspot.com/2008/03/va-waf-yes-it-really-works.html - specifically review the Comments/Response section for many differing viewpoints on the theory and implementation options.
Let me know if any of you have any specific questions.
Also, keep an eye out for an upcoming webcast on this topic as Jeremiah Grossman and I will be hosting.
--
Ryan C. Barnett
ModSecurity Community Manager
Breach Security: Director of Application Security
Web Application Security Consortium (WASC) Member
CIS Apache Benchmark Project Lead
SANS Instructor, GCIA, GCFA, GCIH, GSNA, GCUX, GSEC
Author: Preventing Web Attacks with Apache
------------------------------------------------------------------------- This SF.net email is sponsored by the 2008 JavaOne(SM) Conference Don't miss this year's exciting event. There's still time to save $100. Use priority code J8TL2D2. http://ad.doubleclick.net/clk;198757673;13503038;p?http://java.sun.com/javaone
_______________________________________________ mod-security-users mailing list mod-security-users <at> lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/mod-security-users
RSS Feed