OPNSense - Web Application Firewall (WAF) configuration using NAXSI

OPNSense - Web Application Firewall (WAF) configuration using NAXSI

LS111 Cyber Security Education

1 год назад

24,615 Просмотров

Ссылки и html тэги не поддерживаются


Комментарии:

@jacksoncremean1664
@jacksoncremean1664 - 21.10.2022 07:16

I thought NAXSI was a whitelist based WAF, why would you need to download rules if it just blocks every request by default?

Ответить
@gurulee73
@gurulee73 - 30.11.2023 14:47

What does the NAT Port Forward rule look like? Currently my webapp requires a NAT port forward rule with redirect IP and then that auto-creates a WAN interface rule to allow ingress to internal IP of webapp server.
Specifically, what would I change on my NAT Port Forward rule for the Redirect IP when incorporating the nginx WAF protections. I changed the destination to 'this firewall', but for the redirect IP I do not have a 'this firewall' value and I'd like to verify if this should be the internal IP of the webapp or the WAN int IP address for nginx to pickup?

Ответить
@enderst81
@enderst81 - 29.11.2023 22:35

Works great except the server behind the waf is only logging the waf IP and not the actual IPs.

Ответить
@miamarquez4074
@miamarquez4074 - 03.10.2023 01:31

HI friend, I found your channel and I am fascinated, but I have a problem, I am doing a test laboratory like yours. I downloaded the DVWA ISO from VulnDB, connected it to my Vmware via DMZ, performed the same steps as you did in the video, but NAXSI does not detect attempted SQLi attacks. What could be wrong? Could you make a video explaining how to configure DVWA to integrate it with NAXSI.

Ответить
@user-kh1qr3fh5u
@user-kh1qr3fh5u - 21.08.2023 23:45

i have a question

Ответить
@Aq.37
@Aq.37 - 04.07.2023 22:11

How do I install DVWA on the Nginx server?

Ответить
@uwuwaifu101
@uwuwaifu101 - 01.05.2023 22:39

Thank you!

Ответить
@hna3981
@hna3981 - 05.01.2023 12:32

How you did that from the same machine I didn't get the point, I tried this but set the opnsense in one VM and then I ran another VM as an attacker and I stuck here, I opened the vulnerable web by the first VM ip address which I wrote in the upstream server, I enabled the rules but still it didn't prevent the attack like this!

Ответить
@DigiDoc101
@DigiDoc101 - 16.11.2022 20:29

Very interesting. Since you're running this on 80/443 ports, how would you use this alongside internal reverse proxy to serve public domains?

Ответить
@theressasaliba3239
@theressasaliba3239 - 29.10.2022 00:42

𝙥𝙧𝙤𝙢𝙤𝙨𝙢

Ответить
@frescom06
@frescom06 - 16.10.2022 09:43

Usefull demo: will test it quite soon. Thx for sharing your knowledge ;)

Ответить
@Felix-ve9hs
@Felix-ve9hs - 15.10.2022 18:55

Now I understand what a WAF is and how it works :)

Ответить
@JasonsLabVideos
@JasonsLabVideos - 15.10.2022 01:06

First, and watching this 100% ..

Ответить