Web Application Firewall (WAF)
Implementing and managing WAFs — from rule writing and OWASP Core Rule Set through deployment, tuning, and bypass prevention.
When to Use
- Protecting apps from SQL injection, XSS, and OWASP Top 10 attacks
- Implementing virtual patching for known vulnerabilities
- Filtering malicious traffic before it reaches app servers
- PCI DSS compliance (requirement 6.6)
WAF Solutions
WAF_SOLUTIONS = {
'modsecurity': 'Open-source WAF engine, OWASP CRS rules',
'cloudflare': 'Cloud WAF, managed rules, rate limiting, bot mgmt',
'aws_waf': 'AWS-managed, integrates with ALB/CloudFront',
}
RULES = [
{'id': '942100', 'desc': 'SQL Injection', 'pattern': r'(?i)\b(union|select|drop)\b.*\b(from|where)\b'},
{'id': '941100', 'desc': 'XSS', 'pattern': r'(?i)(<script|javascript:|onerror=)'},
{'id': '930100', 'desc': 'Path Traversal', 'pattern': r'\.\.\/|\.\.'},
]
Common Pitfalls
- False positives — blocking legitimate traffic; tune CRS paranoia level
- Blind blocking — deploy in detection mode first, block after tuning
- Bypass vectors — test with encoded payloads and alternative methods
- WAF as only defense — complements, doesn't replace secure coding
Verification Checklist
1---2name: waf-web-application-firewall3description: Use when implementing web application firewalls and rules.4license: MIT5---67# Web Application Firewall (WAF)89Implementing and managing WAFs — from rule writing and OWASP Core Rule Set through deployment, tuning, and bypass prevention.1011## When to Use1213- Protecting apps from SQL injection, XSS, and OWASP Top 10 attacks14- Implementing virtual patching for known vulnerabilities15- Filtering malicious traffic before it reaches app servers16- PCI DSS compliance (requirement 6.6)1718## WAF Solutions1920```python21WAF_SOLUTIONS = {22 'modsecurity': 'Open-source WAF engine, OWASP CRS rules',23 'cloudflare': 'Cloud WAF, managed rules, rate limiting, bot mgmt',24 'aws_waf': 'AWS-managed, integrates with ALB/CloudFront',25}2627RULES = [28 {'id': '942100', 'desc': 'SQL Injection', 'pattern': r'(?i)\b(union|select|drop)\b.*\b(from|where)\b'},29 {'id': '941100', 'desc': 'XSS', 'pattern': r'(?i)(<script|javascript:|onerror=)'},30 {'id': '930100', 'desc': 'Path Traversal', 'pattern': r'\.\.\/|\.\.'},31]32```3334## Common Pitfalls35361. **False positives** — blocking legitimate traffic; tune CRS paranoia level372. **Blind blocking** — deploy in detection mode first, block after tuning383. **Bypass vectors** — test with encoded payloads and alternative methods394. **WAF as only defense** — complements, doesn't replace secure coding4041## Verification Checklist4243- [ ] Detection mode first, tune before blocking44- [ ] OWASP CRS at appropriate paranoia level45- [ ] Custom rules for app-specific threats46- [ ] Rate limiting configured47- [ ] Logs integrated with SIEM