Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
hkr_mag
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
1.
▲
Machine Learning On-Line Hackathon: Detect Malicious Intent
(lab.wallarm.com)
4 points
by
hkr_mag
8y ago
|
0 comments
2.
▲
App Security Company Wallarm (YC S16) Locks Down $8M Series A
(eweek.com)
9 points
by
hkr_mag
8y ago
|
0 comments
3.
▲
by
hkr_mag
8y ago
For those who is new to the world of SSRF vulnerabilities, check the SSRF Bible (full disclaimer: I'm with Wallarm): https://docs.google.com/document/d/1v1TkWZtrhzRLy0bYXBcdLUed...
4.
▲
by
hkr_mag
8y ago
This is a list of what you can do for application security with Nginx (mostly with open source tools): https://github.com/wallarm/awesome-nginx-security My talk from Nginx conference: https://www.nginx.com&#
5.
▲
by
hkr_mag
9y ago
Awesome job, guys! We have several team members (mostly sales) using Polymail as a default email client.
6.
▲
Neural Architecture Search with Reinforcement Learning Using TensorFlow
(lab.wallarm.com)
2 points
by
hkr_mag
9y ago
|
0 comments
7.
▲
HOWTO: Prevent your secrets being exposed in code repositories
(lab.wallarm.com)
2 points
by
hkr_mag
9y ago
|
0 comments
8.
▲
What to Consider Before Investing in ICO
(forbes.com)
1 points
by
hkr_mag
9y ago
|
0 comments
9.
▲
by
hkr_mag
9y ago
One of the most promising companies among the whole S16 batch. Congatz!
10.
▲
10 tips how to secure apps and APIs with NGINX
(nginx.com)
2 points
by
hkr_mag
9y ago
|
0 comments
11.
▲
Announcing NGINX Plus Certified Modules
(nginx.com)
2 points
by
hkr_mag
9y ago
|
0 comments
12.
▲
Security startup Wallarm raises $2.3M after going through Y Combinator
(techcrunch.com)
1 points
by
hkr_mag
10y ago
|
0 comments
13.
▲
by
hkr_mag
10y ago
+1. Success factor, API.ai, Evernote — three logos from my memory
14.
▲
Millions of vBulletin forum software is affected by a severe SSRF vulnerability
(legalhackers.com)
2 points
by
hkr_mag
10y ago
|
0 comments
15.
▲
by
hkr_mag
10y ago
The main idea about Wallarm is to get inner knowledge of how the application works and how users use it. Based on this data, we craft dynamic rules for every single applications or API. The simplest example is what data transmitted in diffe
16.
▲
by
hkr_mag
10y ago
Thanks!
17.
▲
by
hkr_mag
10y ago
Thanks Jason! Will be at DEFCON this year? It'll be great to meet there.
18.
▲
by
hkr_mag
10y ago
Hackerone and Bugcrowd do a great job. And we recommmend to run bug-bounty programs all the time. But companies which run fast and deploy code everyday with CI/CD (or several times a day) it's almost impossible not to introduce ne
19.
▲
by
hkr_mag
10y ago
Thanks for feedback! 1. Customers analyze traffic with locally installed NGINX-based instances (there is not DNS take-over). They send applications/traffic statistics to Wallarm Cloud so we can run machine-learning stuff. We had a lot
20.
▲
by
hkr_mag
10y ago
Hey there. Stepan, co-founder of Wallarm, here. Feel free to ask any questions.
21.
▲
by
hkr_mag
10y ago
It's because all the security guys (as we're) troll a lot and always skeptical (reasonably!) about blackboxes
22.
▲
by
hkr_mag
10y ago
It absolutely has. The vulnerability was detected with a vulnerability scanner built in Wallarm. As for detection of attacks, in many cases, it's much easier to identify the attacker when he runs several requests than to stop only one
23.
▲
by
hkr_mag
10y ago
Pity you get it in this way. Exploit for WebSphere is just an example of a complicated case with Base64 inside XML where Wallarm can detect malicious request other WAF usually fails. And, no one asked to pay anything until getting proper re
24.
▲
by
hkr_mag
10y ago
Cool. Let's catch up for a coffee than
25.
▲
by
hkr_mag
10y ago
Signal Sciences launched a bit after us. The main difference is in the result: - Guys are helping to detect anomalies and attacks, and I believe they're doing this better than regular WAF does. - Wallarm helps to discover exploitable s
26.
▲
by
hkr_mag
10y ago
What we have already published to open-source is libdetection ( https://github.com/wallarm/libdetection ), a library implementing a completely new way to detect attacks. This approach allows us to implement attack detect
27.
▲
by
hkr_mag
10y ago
# Why it's different 1. Vulnerability and data breach detection. Regular WAF just detects attacks. Thousands of attacks. And what to do with this knowledge? In a case of a traditional security solution, it's never clear — if an at
28.
▲
by
hkr_mag
10y ago
4. Another great example is detecting exploitation of Java Unserialize vulnerabilities ( https://foxglovesecurity.com/2015/11/06/what-do-weblogic-web... ). WebSphere takes payload in Base64 inside the XML. To p
29.
▲
by
hkr_mag
10y ago
BTW, here is the link to Ivan's presentation about WAF evasion techniques — http://www.slideshare.net/d0znpp/lie-tomephd2013 . Lots of them are still valid for old-fashioned security vendors
30.
▲
by
hkr_mag
10y ago
Thanks! Asked mates to figure it out.
More ›