Wafris

62 posts

Wafris banner
Wafris

Wafris

@wafrisorg

Wafris is the open-source Web Application Firewall that works with your web framework to protect your sites from dark traffic, intrusions, and attacks.

Your Web Framework Katılım Ekim 2022
3 Takip Edilen239 Takipçiler
Wafris retweetledi
Ryan Castillo
Ryan Castillo@rmcastil·
Looking for someone to pair on Caddy and Golang for our v2 Wafris client. Got any recommendations? Would be paid of course.
English
0
3
0
465
Wafris retweetledi
Ryan Castillo
Ryan Castillo@rmcastil·
The @wafrisorg and honeybadgerapp teams will be hosting an online workshop tomorrow at 1PM EDT. Come learn about monitoring and security practices from Ben and Mike. I'll be hosting, so send me any questions/topics you want us to cover. (🔗 in the replies)
Ryan Castillo tweet media
English
1
2
2
1.1K
Wafris retweetledi
@honeybadger.io
@honeybadger.io@honeybadgerapp·
Save the date! 📅 One week from today, we're hosting an online workshop with our friends from @wafrisorg called "Error 'N Incidents." This is a great opportunity to learn some monitoring best practices from our co-founder, Ben Curtis (@stympy). (🔗 in replies)
@honeybadger.io tweet media
English
1
3
6
1.1K
Wafris retweetledi
Michael Buckbee
Michael Buckbee@mbuckbee·
I'm hosting a free online workshop, "The Art of Web Defense," this Thursday at 11 a.m. ET. This is _wholly_ focused on practical security considerations and is built around the real-world attacks that I've helped stop. Please signup: crowdcast.io/c/pwsw?utm_cam…
English
0
4
8
777
Wafris
Wafris@wafrisorg·
❓ Closing Question: What's the most interesting or unusual attack you've seen in your logs? We're trying to highlight more from the community. Thanks!
English
0
0
1
228
Wafris
Wafris@wafrisorg·
🌟 Contributor of the Week: We're recognizing Mathias Hansen from @Geocodio for his swift work on a Wafris client in PHP. See his work at github.com/mathias-hansen
English
2
0
1
429
Wafris
Wafris@wafrisorg·
🚀 This week's Update: We've heard your feedback. More automation features are on the way in Wafris. Stay tuned. 🤖
English
1
1
2
1.6K
Wafris
Wafris@wafrisorg·
This week in Wafris: massive memory improvements, a guide to helping developers level up their security expertise, updates clients, and how to tell if Googlebot is lying to you. Check it out at: wafris.org/blog/update-ma…
Wafris tweet mediaWafris tweet mediaWafris tweet media
English
0
4
9
3.1K
Wafris retweetledi
Jess Brown
Jess Brown@bjessbrown·
Guess what happens if you process an external api request in a sidekiq job and the api hangs and doesn't return a result? Your sidekiq job will VERY patiently wait and wait and if you have more of these jobs, eventually your queue will be full of hung jobs. You'd think...
English
5
2
17
6.1K
Wafris
Wafris@wafrisorg·
Seems like a good time to announce publicly that we're going to have our Laravel client out very soon (we're still looking for some more beta testers) and are working on a Pulse card for it.
Taylor Otwell@taylorotwell

Introducing Laravel Pulse. 💓 Pulse delivers at-a-glance insights into your production application's performance and usage. Track down slow jobs and endpoints, find your most active users, and more. Next week on GitHub. A gift from Laravel to you. pulse.laravel.com

English
0
0
2
787
Wafris
Wafris@wafrisorg·
It’s essential to recognize that bots going directly for the jugular aren’t playing around but exhibiting direct hostile intent. Here, the second screenshot shows where a single bot (proxied through the US, UK, and Latvia) is ripping through 27 exploits in 3 seconds. 3/3
English
0
0
1
119
Wafris
Wafris@wafrisorg·
- Determining if a particular asset management software is installed - Exfiltrating data by UNION command if the injection works These will fail if you’re using Rails, Spring, Express, or some other framework. 2/3
English
1
0
1
138
Wafris
Wafris@wafrisorg·
➡ “Dumb” requests by bots in your logs are, in actuality, hyper-efficient. Most are both a probe and an exploit rolled into one. Here’s an example of (screenshot) of individual requests that: - Extract the version from Transact SQL 1/3
Wafris tweet mediaWafris tweet media
English
1
0
0
227
Wafris
Wafris@wafrisorg·
⏱️ 96 requests in less than a minute, intentionally slowing down to avoid rate limiting. 🛠️ Towards the end, it started providing custom path names based on the site name.
English
0
0
1
98
Wafris
Wafris@wafrisorg·
🤖 Bots are learning too quickly. They now scrape for domains, names, and emails to enhance their probing abilities. Here's a screenshot (from our dashboard) of a 🇨🇳 Chinese bot (based on path requests) making proxied requests through a 🇹🇷 Turkish IP. 1/2
Wafris tweet media
English
1
0
1
460