This commit is contained in:
Toby
2026-01-27 17:35:45 -05:00
commit 2639af6531
176 changed files with 27104 additions and 0 deletions
+79
View File
@@ -0,0 +1,79 @@
---
name: waf-setup
description: Deploy and tune Web Application Firewalls. Configure rules for OWASP Top 10 protection. Use when protecting web applications from common attacks.
license: MIT
metadata:
author: devops-skills
version: "1.0"
---
# WAF Setup
Protect web applications with Web Application Firewalls.
## AWS WAF
```bash
# Create Web ACL
aws wafv2 create-web-acl \
--name my-waf \
--scope REGIONAL \
--default-action Allow={} \
--rules file://rules.json
# Associate with ALB
aws wafv2 associate-web-acl \
--web-acl-arn arn:aws:wafv2:... \
--resource-arn arn:aws:elasticloadbalancing:...
```
## ModSecurity (nginx)
```nginx
# nginx.conf
load_module modules/ngx_http_modsecurity_module.so;
server {
modsecurity on;
modsecurity_rules_file /etc/nginx/modsec/main.conf;
}
```
```bash
# Install OWASP CRS
git clone https://github.com/coreruleset/coreruleset /etc/nginx/modsec/crs
```
## Cloudflare WAF
```bash
# Enable managed rules via API
curl -X PUT "https://api.cloudflare.com/client/v4/zones/{zone}/firewall/waf/packages/{package}/rules/{rule}" \
-H "Authorization: Bearer $TOKEN" \
-d '{"mode":"block"}'
```
## Common Rules
```yaml
protections:
- SQL Injection (SQLi)
- Cross-Site Scripting (XSS)
- Remote File Inclusion (RFI)
- Local File Inclusion (LFI)
- Command Injection
- Cross-Site Request Forgery (CSRF)
```
## Best Practices
- Start in detection mode
- Tune for false positives
- Monitor blocked requests
- Regular rule updates
- Custom rules for app-specific attacks
## Related Skills
- [dast-scanning](../../scanning/dast-scanning/) - Web security testing
- [ssl-tls-management](../ssl-tls-management/) - HTTPS configuration
@@ -0,0 +1,120 @@
# WAF Rules Reference
## AWS WAF
### Managed Rules
```hcl
resource "aws_wafv2_web_acl" "main" {
name = "myapp-waf"
scope = "REGIONAL"
default_action {
allow {}
}
# AWS Managed Rules - Core
rule {
name = "AWSManagedRulesCommonRuleSet"
priority = 1
override_action { none {} }
statement {
managed_rule_group_statement {
vendor_name = "AWS"
name = "AWSManagedRulesCommonRuleSet"
}
}
visibility_config {
cloudwatch_metrics_enabled = true
metric_name = "CommonRuleSet"
sampled_requests_enabled = true
}
}
# SQL Injection
rule {
name = "AWSManagedRulesSQLiRuleSet"
priority = 2
override_action { none {} }
statement {
managed_rule_group_statement {
vendor_name = "AWS"
name = "AWSManagedRulesSQLiRuleSet"
}
}
visibility_config {
cloudwatch_metrics_enabled = true
metric_name = "SQLiRuleSet"
sampled_requests_enabled = true
}
}
}
```
### Custom Rules
```hcl
# Rate limiting
rule {
name = "RateLimit"
priority = 0
action { block {} }
statement {
rate_based_statement {
limit = 2000
aggregate_key_type = "IP"
}
}
}
# Geo blocking
rule {
name = "GeoBlock"
priority = 3
action { block {} }
statement {
geo_match_statement {
country_codes = ["CN", "RU"]
}
}
}
```
## Cloudflare WAF
```hcl
resource "cloudflare_ruleset" "waf" {
zone_id = var.zone_id
name = "WAF Rules"
kind = "zone"
phase = "http_request_firewall_managed"
rules {
action = "execute"
action_parameters {
id = "efb7b8c949ac4650a09736fc376e9aee" # OWASP Core Ruleset
}
expression = "true"
}
}
```
## Common Attack Patterns
| Pattern | Description | Rule |
|---------|-------------|------|
| SQLi | SQL Injection | Block `' OR 1=1`, UNION |
| XSS | Cross-Site Scripting | Block `<script>`, event handlers |
| LFI | Local File Inclusion | Block `../`, `/etc/passwd` |
| RCE | Remote Code Execution | Block shell commands |
## Best Practices
1. Start in monitoring mode
2. Tune rules for false positives
3. Use rate limiting
4. Block known bad IPs
5. Log all blocked requests
6. Regular rule review