Extending WAFs at the Application Layer
Offered By: OWASP Foundation via YouTube
Course Description
Overview
Syllabus
Intro
Brief History of WAF's
Purpose of WAF's
Problems with WAF's
Bypassing WAF'S
Sanwaf: Application-Level Security Control
Purpose of Sanwaf
Bypass Example A cookie is being blocked by a WWF and is causing an issue, so
Sanwaf Does Not Replace WAF's
Sanitizing Data
How Sanwaf Works
Sanwaf Structure
Global Settings
Shield Settings
Regex Settings
Metadata Settings
Sanwaf Datatypes
Sanwaf: How it works
Sanwaf: How Strings Work
Sanwaf Datatype Performance
Example - Delimited Set of Numbers
Datatype Example: Delimited Set of Numbers (RegEx)
Datatype Example: Alphanumeric and Whitelisted
Datatype Example: Using a lava Class
Datatype Example: String & Regex
Implementing Sanwaf
Sample Implementation: Filter
Sample Implementation: Logging
Error Message Example
Rending Error to End User
Sample Application
Where to Git Sanwaf
Contact Information
Taught by
OWASP Foundation
Related Courses
Building Geospatial Apps on Postgres, PostGIS, & Citus at Large ScaleMicrosoft via YouTube Unlocking the Power of ML for Your JavaScript Applications with TensorFlow.js
TensorFlow via YouTube Managing the Reactive World with RxJava - Jake Wharton
ChariotSolutions via YouTube What's New in Grails 2.0
ChariotSolutions via YouTube Performance Analysis of Apache Spark and Presto in Cloud Environments
Databricks via YouTube