PDA

View Full Version : Website Firewall


chikuru
09-03-2015, 09:42 AM
Anyone using Website Application Firewall?
What are you using? Hows your experience?
What do you recommend?

Dave
09-03-2015, 12:06 PM
What kind of firewall are we talking about?
To prevent bots? To prevent website attacks such as SQL injection and such? To prevent (D)DoS attacks?

I don't use any because I have made my own very basic filtering function in PHP for vBulletin that should prevent any 0day attacks. (D)DoS attacks can not be prevented with a WAF. But besides that there's always some way to bypass a WAF because it simply checks the request sent to the server for certain patterns or strings.

Cloudflare and Incapsula are good examples of DNS providers who also provide WAF and DDoS protection.

chikuru
09-03-2015, 12:33 PM
Specifically sql injection, xss, and 0day attacks. Im currently using the free version of cloudflare

TheLastSuperman
09-03-2015, 04:39 PM
Incapsula is good, I've been stopped dead in my tracks by it and I wasn't even trying anything dirty, I swear!

Always a good idea to check with your host, some offer very solid advice on matters such as this including what they can offer/do as I bet its not their first ddos rodeo :cool:.

Dave
09-03-2015, 07:14 PM
Specifically sql injection, xss, and 0day attacks. Im currently using the free version of cloudflare

The free version does not provide any WAF though, you'll have to buy one of the packages of which the cheapest one is $20/month. I recommend either Cloudflare or Incapsula.

bremereric
09-07-2015, 05:43 PM
Not free, but I use a cloud proxy firewall from Sucuri. Had several hacks two weeks ago through the loophole in vb 4.1.3