# Waf Web Application Firewall

> Use when implementing web application firewalls and rules.

- Skill: `loopyluci/waf-web-application-firewall` (Agent Skill)
- Install (CLI): `npx skillmds@latest add loopyluci/waf-web-application-firewall`
- Raw SKILL.md: https://api.skillmd.com/api/skills/loopyluci/waf-web-application-firewall/raw
- Safety review: pending (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Coding & Dev Tools
- License: MIT
- Author: LoopyLuci (https://skillmd.com/u/loopyluci)
- Updated: 2026-09-08
- Page: https://skillmd.com/skills/loopyluci/waf-web-application-firewall

---


# Web Application Firewall (WAF)

Implementing and managing WAFs — from rule writing and OWASP Core Rule Set through deployment, tuning, and bypass prevention.

## When to Use

- Protecting apps from SQL injection, XSS, and OWASP Top 10 attacks
- Implementing virtual patching for known vulnerabilities
- Filtering malicious traffic before it reaches app servers
- PCI DSS compliance (requirement 6.6)

## WAF Solutions

```python
WAF_SOLUTIONS = {
    'modsecurity': 'Open-source WAF engine, OWASP CRS rules',
    'cloudflare': 'Cloud WAF, managed rules, rate limiting, bot mgmt',
    'aws_waf': 'AWS-managed, integrates with ALB/CloudFront',
}

RULES = [
    {'id': '942100', 'desc': 'SQL Injection', 'pattern': r'(?i)\b(union|select|drop)\b.*\b(from|where)\b'},
    {'id': '941100', 'desc': 'XSS', 'pattern': r'(?i)(<script|javascript:|onerror=)'},
    {'id': '930100', 'desc': 'Path Traversal', 'pattern': r'\.\.\/|\.\.'},
]
```

## Common Pitfalls

1. **False positives** — blocking legitimate traffic; tune CRS paranoia level
2. **Blind blocking** — deploy in detection mode first, block after tuning
3. **Bypass vectors** — test with encoded payloads and alternative methods
4. **WAF as only defense** — complements, doesn't replace secure coding

## Verification Checklist

- [ ] Detection mode first, tune before blocking
- [ ] OWASP CRS at appropriate paranoia level
- [ ] Custom rules for app-specific threats
- [ ] Rate limiting configured
- [ ] Logs integrated with SIEM

