4 ms·
Show HN: BunkerWeb – the open-source and cloud-native WAF
- qmarchi 1y agoWhile neat, I feel like in the current age of "let's throw shitloads of packets and see how they like that", this solves _a problem_, but I feel that most of the security products solve it by anycasting IP ranges. Neat to see another use case for NGNIX though!
- jqpabc123 1y agoHow is this better than Caddy?
- bnkty 1y agoCaddy does not offer full application protection besides HTTPS and basic stuff.
- dontTREATonme 1y agoIs there a significant difference between this and nginx proxy manager?
- justusthane 1y agoThey're both reverse proxies built on nginx, but the whole point of BunkerWeb is that it's a WAF, which NPM is not, so that's a significant difference. In short, NPM doesn't do any of the stuff listed under Security Features here: https://docs.bunkerweb.io/latest/#security-features https://docs.bunkerweb.io/latest/#security-features
- jeauxlb 1y agoNPM will automate Let's Encrypt certificate generation but you're right about the other listed features.
- lta 1y agoI'm still strongly suspecting this whole WAF thing is mostly complete bullshit intended for projects doing security works mostly from spreadsheets. Could someone with a proper background in security confirm or invalidate my suspicion ?
- daeken 1y agoI mean ... You're not completely wrong, but you're not completely right either. For context: I've been working full-time in security for 15 years and on the fringes (reversing) for many more. WAFs in and of themselves provide virtually zero security. They can block naive attacks -- catching the most obvious payloads -- and act as an early-warning signal that an attack may be underway (though the SNR on this is awful). But frankly, this is far less important in practice than the fact that it just makes things more difficult and annoying for attackers. Enough so that it can make a semi-attractive target into a no-go. This is like defense-in-depth, but instead of layering protections in place so that the holes in the swiss cheese don't like up, you're making the cheese smell awful enough to ignore the juicy apple behind it. If you're a valuable enough target, they're gonna go for the apple regardless of how bad the cheese is. ... And this analogy may have gotten away from me.
- macNchz 1y agoIn addition to defense-in-depth—simply adding a bunch of imperfect layers and acknowledging that no individual layer like this is all that effective on its own—there’s a component of creating signal: it can be pretty trivial for a motivated attacker to bypass a WAF, however it may not be trivial to do so without creating a paper trail of event logs, which can be used to trigger automated blocks or escalate alarms for a human to intervene.
- mac-chaffee 1y agoI'd generally confirm that suspicion: https://www.macchaffee.com/blog/2023/wafs/ https://www.macchaffee.com/blog/2023/wafs/ WAFs have a few valid uses in my opinion: "virtual patching" and the ability to create custom rules such as blocking/challenging/rate limiting obviously bad traffic. But the giant rulesets are actively harmful IMO. "Defense in depth" is not a valid justification for doing something actively harmful to both your users and the time budget of your security team.
- noobcoder 1y agoIs the syntax same as nginx?
- bnkty 1y agoCustom nginx configs are supported (more info here : https://docs.bunkerweb.io/latest/advanced/#custom-configurations https://docs.bunkerweb.io/latest/advanced/#custom-configurat...) but BunkerWeb also includes its own list of settings.
- chrismorgan 1y agoYour site talks of BunkerWeb PRO, which is, by the sound of it, not open source. But I have no idea what is actually different about it: https://panel.bunkerweb.io/knowledgebase/105/What-is-BunkerWeb-PRO-.html https://panel.bunkerweb.io/knowledgebase/105/What-is-BunkerW... flatly doesn’t answer the question: “additional features and services responding to professional needs” is impressively vague.
- bnkty 1y agoFeatures with a crown icon are PRO, you will find full list of free and PRO features here : https://docs.bunkerweb.io/latest/features/ https://docs.bunkerweb.io/latest/features/
- chrismorgan 1y agoMight I suggest at the very least linking to that from https://panel.bunkerweb.io/knowledgebase/105/What-is-BunkerWeb-PRO-.html https://panel.bunkerweb.io/knowledgebase/105/What-is-BunkerW... and https://panel.bunkerweb.io/store/bunkerweb-pro https://panel.bunkerweb.io/store/bunkerweb-pro.
- sreekanth850 1y agoHow this compare against safeline?
- Carriethebest 1y agoSafeLine is much easier to config, more user friendly. BunkerWeb requires much more time for tuning.
- jnettome 1y agoI just love this project! BunkerWeb was a huge help when I was self-hosting my products with Docker Swarm. It offers tons of configuration options—especially useful for those needing a WAF and dealing with heavy bot traffic. Since moving to Kubernetes, I haven’t used or evaluated it there yet, but kudos to the team for continuing to update and improve the project. Keep up the great work!
- bnkty 1y agoThanks for the kind words! Kubernetes integration is really awesome, you can use BunkerWeb ingress controller or mix it with an existing ingress controller.
- seymon 1y agoWhat's the benefit of just using plain owasp modsecurity? It also exists as a docker container as an nginx reverse proxy with modsecurity extension. https://coreruleset.org/docs/6-development/6-6-useful_tools/#official-crs-maintained-docker-images https://coreruleset.org/docs/6-development/6-6-useful_tools/...
- bnkty 1y agoModSecurity doesn't offer antibot, bad behavior, certificate management, ... You can find the full list of features here : https://docs.bunkerweb.io/latest/features/ https://docs.bunkerweb.io/latest/features/
- SbEpUBz2 1y agoI can't unban myself from the demo :)
- AgentMatrixAI 1y agoWhat % of cloudflare's protection can this provide? I've been looking at bunkerweb + anubis as alternative to cloudflare tunnel (im actually not sure if this provides WAF)
- SkyPuncher 1y agoThis isn't really comparable to any of the SaaS based products. While this offers many of the same technical capabilities as Cloudflare, a lot of Cloudflare's value is in having high-level, aggregate insight into threats.
- stevenicr 1y agolooks very cool, I could use this. Given how much I have watched all sorts of automated things hammer websites on multiple servers, I believe everyone should use something like this. Had a hard time finding the premium version price, aka pro - saw $170 and thought to myself, I don't know. Then I saw it was a monthly fee. $1500 per year, and I'm not sure what 10 services even means, for me I'd probably need more, and I wouldn't spend 1500 on it if it was a one time lifetime. I get that I am not the target market. I just wish it was faster to find that out. Glad I didn't waste more time looking at the cool features.