9 ms·
Care to elaborate?
by andyfleming 8y ago
Care to elaborate?
- tptacek 8y agoYou almost certainly don't want to set up a WAF. Don't use any of those scanners, all of which look almost exclusively for vulnerabilities you don't have. Do look into getting a Burp license for every developer on your team. By all means, harden Nginx. Don't pay SpiderLabs to do it for you.
- peterwwillis 8y agoA WAF will stop a lot of the stupid junk that a kid with a "how 2 hax0r" book can make work a disturbing amount of the time.
- tptacek 8y agoIf any of that stuff is actually working on your site, not having a WAF is the least of your problems. Don't waste time with this stuff.
- nxc18 8y agoI assume you are writing in an attempt to persuade. Your message is being lost/ignored as a result of your delivery. We want to understand your message, but you aren't giving enough background. I don't trust your message because there is no supporting background. If you're going to tell me to not do something, either: A) provide a compelling alternative (not doing $it is not a compelling alternative to $it in nearly all cases) B) explain in detail why you shouldn't do $it. Provide more details if asked. I want to believe what you are saying and be convinced by it, please help me. (Note: I'm not trying to be a dick, I've just known a lot of people who are perpetually ignored because of this communication style and take forever to learn that lesson because no one bothers to say anything)
- tptacek 8y agoIn this instance, I'm just interested in getting the right answer written down and moving on.
- pvg 8y agoI'm not trying to be a dick You are succeeding without trying. You're essentially complaining some free advice does not fit your exact expectations and specifications. Which is fine, lots of free advice doesn't. Trying to pass this complaint off as some kind of favour to the person giving you free advice, though, is... less than great.
- irundebian 8y agoNo, tptacek just doesn't give proper answers here because he thinks he can afford it with his status here. He could have just left links to further links/literature.
- pvg 8y agoThere's nothing 'improper' about the answers, you just don't like how they're presented. As I said, that's a totally fair objection. It's just that nobody owes you free advice in the precise format you find acceptable. That's usually a feature of paid advice.
- TeMPOraL 8y agoI think tptacek's implicit point is this: all the problems you're trying to address with the tools listed are the problems you shouldn't be having in the first place, so, to quote, "focus on removing attack surface, rather than continuously monitoring it".
- anothergoogler 8y ago> We want Please speak for yourself alone. tptacek's comments in the thread are quite clear.
- hueving 8y agotptacek is using an appeal to authority given his standing as a security expert on this forum. That's the only reason his comment containing no justification is being taken seriously.
- Alex3917 8y ago> If any of that stuff is actually working on your site, not having a WAF is the least of your problems. Is this advice assuming that it's devs who want the WAF, rather than ops or management? For devs clearly it's not what they should be focusing on. But saying something isn't worth doing because it shouldn't work is a terrible security principle.
- tptacek 8y agoI wrote a longer comment here, but decided it wasn't helping. So, I'm just going to go with: no, if you're really building an application and care about application security, no, you shouldn't waste time setting up a WAF tool designed to help 10,000 employee insurance companies make sure their Wordpress marketing site isn't exposing some vulnerability from 3 years ago. Not wasting time with dumb stuff like this isn't "terrible security"; every dumb thing you do exacts a cost from good things you could be doing instead.
- subcosmos 8y ago"Don't invest in a home security system because your windows should be completely shatterproof"
- balls187 8y agoMore like, "Don't invest in home security, because your most precious valuables are stored in a safety deposit box at a bank, and everything else is covered by home insurance."
- pennaMan 8y ago"Don't invest in a home security system before you make sure your house has a door"
- subcosmos 8y agoSomething tells me those taking objection to my comment are missing the point that I am criticizing the parent.... If your counterexample is just reinforcing the parents erroneous point that WAFs only protect against specific applications with known vulnerabilities, and that not all websites have "doors", then you are missing the point that many WAFs have detectors for fairly generic sql injection and path traversal techniques that could very well find problems with even custom application endpoints....
- sebcat 8y agoA WAF will also add an attack surface, just like anti-virus software before them. Company X, a content publisher, has a wordpress site with a bunch of plugins. They hear that the security record of such a setup is less than ideal. They buy a WAF solution to protect them. Company Y, also a content publisher in the same space, realizes that they don't need dynamically generated content. They don't need tons of JS. They start publishing static content and what little dynamic functionality they have is well-compartmentalized, with interactions to the outside world carefully audited. Company Y could also get a WAF, but why? It increases the attack surface, Company Y probably don't have the time/expertise to audit it, it is not clear what benefits it will have.
- sandGorgon 8y agoThis is brilliant. Thanks !
- _pdp_ 8y agoThere are good burp alternatives too :)
- tptacek 8y agoThere definitely are! Your stuff included! Burp is just the industry standard.
- sandGorgon 8y agoSo is it "fix whatever Burp points out" ? Is that a good first step ? Especially for api endpoints (versus websites)
- tptacek 8y agoYou'd ideally want a dev process where all your developers were capable of conducting integration test runs with Burp; you'd probably set up a checklist of authz tests, and set up some custom wordlists for Intruder for database, filesystem, and DOM injection vectors.
- sandGorgon 8y agoThanks. This was a superuseful suggestion. I can now Google a lot of stuff on my own.
- deleted 8y ago[deleted]
- peterwwillis 8y agoThe problem with throwing tools at the thing is you have no idea what it's doing or how it works or IF it works, and it becomes forgotten about. But it's better than nothing in the short term while you figure out how to secure your application. Slap ModSecurity in front of your app while you go over OWASP and managing cloud infrastructure securely.
- technion 8y agoIn addition to the points discussed.. If you follow the Geekflare link to modsecurity, and then follow the link there to a download page, there's this warning: >NOTE: Some instabilities in the Nginx add-on have been reported (see the Github issues page for details). Please use the "nginx_refactoring" branch where possible for the most up to date version and stay tuned for the ModSecurity version 4. That's not something I would suggest throwing in production, given that warning has been there for years. The post itself describes Shadow daemon as "probably defunct". Ironbee's last commit was two years ago and I get an nxdomain looking for their website. AWS WAF is both expensive and and extremely manual. You won't get anything out of it without a major labour investment. Nginx's built in WAF is only in the pro edition, and outside the price of many people. This whole discussion however depends on your customer. I have an agency I support where I have to provide a report on every single hack attempt. That means if my Rails application gets hit with said three year old Wordpress exploit, and the web server "404", I have to report on how we "blocked" it. And no, "not applicable" is not an answer. So we throw money at commercial products. And sometimes I recommend doing so. But like security can involve just being aware of your risks, this use of a WAF is about being aware of the real problem you're solving, which is a paper work based one.