mirror of
https://github.com/BagelHole/DevOps-Security-Agent-Skills.git
synced 2026-08-22 12:49:53 +02:00
.
This commit is contained in:
@@ -0,0 +1,79 @@
|
||||
---
|
||||
name: waf-setup
|
||||
description: Deploy and tune Web Application Firewalls. Configure rules for OWASP Top 10 protection. Use when protecting web applications from common attacks.
|
||||
license: MIT
|
||||
metadata:
|
||||
author: devops-skills
|
||||
version: "1.0"
|
||||
---
|
||||
|
||||
# WAF Setup
|
||||
|
||||
Protect web applications with Web Application Firewalls.
|
||||
|
||||
## AWS WAF
|
||||
|
||||
```bash
|
||||
# Create Web ACL
|
||||
aws wafv2 create-web-acl \
|
||||
--name my-waf \
|
||||
--scope REGIONAL \
|
||||
--default-action Allow={} \
|
||||
--rules file://rules.json
|
||||
|
||||
# Associate with ALB
|
||||
aws wafv2 associate-web-acl \
|
||||
--web-acl-arn arn:aws:wafv2:... \
|
||||
--resource-arn arn:aws:elasticloadbalancing:...
|
||||
```
|
||||
|
||||
## ModSecurity (nginx)
|
||||
|
||||
```nginx
|
||||
# nginx.conf
|
||||
load_module modules/ngx_http_modsecurity_module.so;
|
||||
|
||||
server {
|
||||
modsecurity on;
|
||||
modsecurity_rules_file /etc/nginx/modsec/main.conf;
|
||||
}
|
||||
```
|
||||
|
||||
```bash
|
||||
# Install OWASP CRS
|
||||
git clone https://github.com/coreruleset/coreruleset /etc/nginx/modsec/crs
|
||||
```
|
||||
|
||||
## Cloudflare WAF
|
||||
|
||||
```bash
|
||||
# Enable managed rules via API
|
||||
curl -X PUT "https://api.cloudflare.com/client/v4/zones/{zone}/firewall/waf/packages/{package}/rules/{rule}" \
|
||||
-H "Authorization: Bearer $TOKEN" \
|
||||
-d '{"mode":"block"}'
|
||||
```
|
||||
|
||||
## Common Rules
|
||||
|
||||
```yaml
|
||||
protections:
|
||||
- SQL Injection (SQLi)
|
||||
- Cross-Site Scripting (XSS)
|
||||
- Remote File Inclusion (RFI)
|
||||
- Local File Inclusion (LFI)
|
||||
- Command Injection
|
||||
- Cross-Site Request Forgery (CSRF)
|
||||
```
|
||||
|
||||
## Best Practices
|
||||
|
||||
- Start in detection mode
|
||||
- Tune for false positives
|
||||
- Monitor blocked requests
|
||||
- Regular rule updates
|
||||
- Custom rules for app-specific attacks
|
||||
|
||||
## Related Skills
|
||||
|
||||
- [dast-scanning](../../scanning/dast-scanning/) - Web security testing
|
||||
- [ssl-tls-management](../ssl-tls-management/) - HTTPS configuration
|
||||
@@ -0,0 +1,120 @@
|
||||
# WAF Rules Reference
|
||||
|
||||
## AWS WAF
|
||||
|
||||
### Managed Rules
|
||||
```hcl
|
||||
resource "aws_wafv2_web_acl" "main" {
|
||||
name = "myapp-waf"
|
||||
scope = "REGIONAL"
|
||||
|
||||
default_action {
|
||||
allow {}
|
||||
}
|
||||
|
||||
# AWS Managed Rules - Core
|
||||
rule {
|
||||
name = "AWSManagedRulesCommonRuleSet"
|
||||
priority = 1
|
||||
override_action { none {} }
|
||||
|
||||
statement {
|
||||
managed_rule_group_statement {
|
||||
vendor_name = "AWS"
|
||||
name = "AWSManagedRulesCommonRuleSet"
|
||||
}
|
||||
}
|
||||
visibility_config {
|
||||
cloudwatch_metrics_enabled = true
|
||||
metric_name = "CommonRuleSet"
|
||||
sampled_requests_enabled = true
|
||||
}
|
||||
}
|
||||
|
||||
# SQL Injection
|
||||
rule {
|
||||
name = "AWSManagedRulesSQLiRuleSet"
|
||||
priority = 2
|
||||
override_action { none {} }
|
||||
|
||||
statement {
|
||||
managed_rule_group_statement {
|
||||
vendor_name = "AWS"
|
||||
name = "AWSManagedRulesSQLiRuleSet"
|
||||
}
|
||||
}
|
||||
visibility_config {
|
||||
cloudwatch_metrics_enabled = true
|
||||
metric_name = "SQLiRuleSet"
|
||||
sampled_requests_enabled = true
|
||||
}
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
### Custom Rules
|
||||
```hcl
|
||||
# Rate limiting
|
||||
rule {
|
||||
name = "RateLimit"
|
||||
priority = 0
|
||||
action { block {} }
|
||||
|
||||
statement {
|
||||
rate_based_statement {
|
||||
limit = 2000
|
||||
aggregate_key_type = "IP"
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
# Geo blocking
|
||||
rule {
|
||||
name = "GeoBlock"
|
||||
priority = 3
|
||||
action { block {} }
|
||||
|
||||
statement {
|
||||
geo_match_statement {
|
||||
country_codes = ["CN", "RU"]
|
||||
}
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
## Cloudflare WAF
|
||||
|
||||
```hcl
|
||||
resource "cloudflare_ruleset" "waf" {
|
||||
zone_id = var.zone_id
|
||||
name = "WAF Rules"
|
||||
kind = "zone"
|
||||
phase = "http_request_firewall_managed"
|
||||
|
||||
rules {
|
||||
action = "execute"
|
||||
action_parameters {
|
||||
id = "efb7b8c949ac4650a09736fc376e9aee" # OWASP Core Ruleset
|
||||
}
|
||||
expression = "true"
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
## Common Attack Patterns
|
||||
|
||||
| Pattern | Description | Rule |
|
||||
|---------|-------------|------|
|
||||
| SQLi | SQL Injection | Block `' OR 1=1`, UNION |
|
||||
| XSS | Cross-Site Scripting | Block `<script>`, event handlers |
|
||||
| LFI | Local File Inclusion | Block `../`, `/etc/passwd` |
|
||||
| RCE | Remote Code Execution | Block shell commands |
|
||||
|
||||
## Best Practices
|
||||
|
||||
1. Start in monitoring mode
|
||||
2. Tune rules for false positives
|
||||
3. Use rate limiting
|
||||
4. Block known bad IPs
|
||||
5. Log all blocked requests
|
||||
6. Regular rule review
|
||||
Reference in New Issue
Block a user