3 ms·
I like AWS direction towards security. But... Who needs WAF with basic, static rules in 2015 when applications are deployed several times a day? Mod_security i
by awkgeek 11y ago
I like AWS direction towards security. But...
Who needs WAF with basic, static rules in 2015 when applications are deployed several times a day? Mod_security in a cloud? Well. Be ready to get a dedicated person to support it to avoid false positives. And I guess it's still easy to by-pass.
Give a try to Wallarm, NAXSI, Signal Sciences.
- hkr_mag 11y agoNone of solutions you've mentioned works in the cloud! But yep. If you're looking for WAF for NGINX, these are good options. BTW, mod_security is now compatible with NGINX too.