YoVDO

Introduction to the OWASP ModSecurity Core Rule Set

Offered By: nullcon via YouTube

Tags

nullcon Courses Web Application Security Courses Web Application Firewalls Courses ModSecurity Courses

Course Description

Overview

Explore the fundamentals of web application security in this 44-minute webinar presented by Christian Folini at Nullcon. Delve into the OWASP ModSecurity Core Rule Set (CRS), a powerful open-source tool designed to protect web applications from a wide range of attacks. Learn about the concept of Web Application Firewalls (WAFs), the ModSecurity engine, and key CRS features such as paranoia levels, stricter siblings, and anomaly scoring. Witness a live demonstration of the ruleset's detection capabilities and gain insights into managing false positives, custom responses, and rule updates in enterprise environments. Benefit from Folini's extensive experience in high-security ModSecurity configuration, DDoS defense, and threat modeling as he bridges complex technical concepts with his unique background in medieval history.

Syllabus

Introduction
Christian Folini
Why use a Web Application Firewall
What is ModSecurity
Rules on Top
How does it work
Levels of paranoia
How does that look
Confirmed
Anomaly Scoring
Demo
Problem false positives
Summary
Questions
Custom Response
Rule Updates
How to manage this on enterprise level
Karraza
Dust
payload
antiautomation
plugins


Taught by

nullcon

Related Courses

AWS SimuLearn: Intelligent Application Protection
Amazon Web Services via AWS Skill Builder
CISO Security Controls: Enterprise Controls
Cybrary
Fortinet FortiWeb Cloud WAF-as-a-Service
Cybrary
Filtering and blocking web incursions with AWS WAF (Traditional Chinese)
Amazon Web Services via AWS Skill Builder
AWS Administration: Security Fundamentals
LinkedIn Learning