Open Source Web Entry Firewall presented at OWASP Appsec 2010

by Ivan Butler (Security Compass),

Tags: Security Web Firewall


Summary : What makes the difference between a web application firewall and a web entry server? Learn in this talk more about web entry servers, architecture, pre-authentication, shared memory based session store, session hiding and service level access control.

The talk will start from a clean apache web server that will then be turned into a reverse proxy, from where mod_security enables the web app firewall capabilities. In the next step, the audience will learn and see how to turn this WAF into a Pre-Auth engine with url based access controls and session hiding features.

At the end of the talk, we have setup a fully operational, secure and open source web entry server in front of Facebook.