By Andrea Menin
Hi!
Last year I’ve started to develop a WAF (web application firewall) based on Nginx (openresty) + ModSecurity and Nodejs. Now the WAF is stable and it works like a charm :)
I would like to create a new branch of this project (waf.blue) and create a FREE service waf-in-cloud for small websites / blogs / etc … (not enterprise) called waf.red and hosted on digitalocean. The free WAF will include all ModSecurity rules + Custom Rules + Shared Reputation DB + 2 months of reports and logs + real time dashboard.
Someone would be interested in using this kind of service? I’ve created a repository on github to collect opinions and show screenshots and video of the WAF.
https://github.com/theMiddleBlue/waf.red
hope this can be useful, thanks!
-theMiddle
This textbox defaults to using Markdown to format your answer.
You can type !ref in this text area to quickly search our full set of tutorials, documentation & marketplace offerings and insert the link!
Did this come along? I can’t view the node1.waf.red website. Would love to have a WAF service.
Sorry to rejuvenate this thread, but waf.red is way too intrusive with its CNAME requirement, and Bugshield.io is gone. Wallarm looks nice, but the Nginx install gives an error. I followed the instructions on their website, and while executing yum install wallarm-node-nginx nginx-module-wallarm, I get this error:
Error: Package: ruby-proton-2.12.0-1.x86_64 (wallarm-node)
Requires: libproton212 = 2.12.0-1
Error: ruby-proton conflicts with nginx-module-wallarm-2.10.7-1.el7.x86_64
Error: Package: ruby-proton-2.12.0-1.x86_64 (wallarm-node)
Requires: libproton.so.2.12()(64bit)
You could try using --skip-broken to work around the problem
You could try running: rpm -Va --nofiles --nodigest
This is on CentOS 7.x. Any ideas?
Hi guys!
I’m working to the registration process on waf.red website, i think i’ll complete it soon :)
I’ve just configured a “demo user” for make you try the WAF Web GUI. I would love to know your opinions about it :) It is not a “production state” for now, it is a “pre-alfa”. You need to login to:
Console: https://node1.waf.red/
Username: demo@waf.red
Password: demo
Demo Website: http://scream48.com
The WAF protect a demo website (scream48.com) that you can use it for generate events on the demo account. For example, you’ll see a request by you IP Address if you do:
curl -v "http://scream48.com"
thank you! others news coming soon :)
-theMiddle
Get paid to write technical tutorials and select a tech-focused charity to receive a matching donation.
Full documentation for every DigitalOcean product.
The Wave has everything you need to know about building a business, from raising funding to marketing your product.
Stay up to date by signing up for DigitalOcean’s Infrastructure as a Newsletter.
New accounts only. By submitting your email you agree to our Privacy Policy
Scale up as you grow — whether you're running one virtual machine or ten thousand.
Sign up and get $200 in credit for your first 60 days with DigitalOcean.*
*This promotional offer applies to new accounts only.