Latest Posts
StrongBox It
June 8, 2022
The Open Web Application Security Project (OWASP) is a non-profit organisation founded on the motive of improving software security. OWASP WAF which is the ModSecurity core ruleset is provided to help improve application security through a web application firewall.
The OWASP Foundation is the source for developers and technologists to safeguard the web through community-led open-source software projects, hundreds of local chapters globally, tens of thousands of members, and leading educational and training conferences.
The OWASP Top 10 is a book/reference document that summarises the top ten security concerns for web applications. The report is put together by a group of security specialists from across the world, and the data is gathered from a variety of sources before being analysed.
The Top 10 is described by OWASP as an "awareness document," and it is recommended that all organisations implement the report into their procedures to reduce security risks. One thing to keep in mind is that this is not a standard.
Organisations can customise the matrix to fit their own needs. Top10 is defined by OWASP, which collects data from a large number of people and organisations and then makes it available for us to comment on.
Based on the level of damage the vulnerabilities have caused, OWASP has derived a list of top 10 threats. Listed from A1 to A10, A1 being the most severe and A10 being the least.
A1:2021: Broken Access Control
A2:2021: Cryptographic failures (sensitive data exposure)
A3:2021: Injection
A4:2021: Insecure Design
A5:2021: Security Misconfiguration
A6:2021: Vulnerable and outdated components
A7:2021: Identification and Authentication Failures
A8:2021: Software and Data Integrity Failures
A9 2021: Security Logging and Monitoring Failures
A10:2021: Server-side request forgery
Insecure Design
ModSecurity, often known as Modsec, is a free web application firewall (WAF). Originally designed as a module for the Apache HTTP Server.
It has evolved to provide a variety of HTTP request and response filtering capabilities, as well as other security features, across a variety of platforms, including Apache HTTP Server,[1][2] Microsoft IIS, and Nginx. [3] It's open-source software licenced under the Apache 2.0 licence.
The platform includes a 'SecRules' rule configuration language for real-time monitoring, logging, and filtering of Hypertext Transfer Protocol conversations using user-defined rules.
The 1st Line of Defence Against Web Application Attacks is the OWASP ModSecurity Core Rule Set.
The OWASP ModSecurity Core Rule Set (CRS) is a collection of attack detection rules that may be used with ModSecurity or other compatible web application firewalls.
With a minimum of false warnings, the CRS tries to protect online applications from a wide range of assaults, including the OWASP Top Ten.
SQL Injection, Cross-Site Scripting, Local File Inclusion, and other typical attack categories are all protected by the CRS.
Latest Posts
Get the latest cybersecurity insights, threat intelligence, and security best practices delivered straight to your inbox.