Christian Folini -Securing Access to Internet Voting with the OWASP ModSecurity Core Rule Set
Traditionally, the OWASP ModSecurity Core Rule Set, an OWASP flagship project, has been hard to use.
However, the release of CRS 3.0 in 2017 and the advancements made up to CRS 3.4 successfully removed most of the false positives in the default installation. This improved the user experience when running ModSecurity / CRS - the only general purpose open source web application firewall.
The presentation explains how to run CRS successfully in high security settings. This includes practical advice to tuning, working with the anomaly thresholds, the paranoia levels and complementary whitelisting rule sets. This talk is based on many years of experience gained by using CRS in various high security settings, including the one by Swiss Post for it's national online voting service.
Slides: https://drive.google.com/file/d/1Klua... (4.8MB)
Speaker info: https://www.romhack.io/speakers-2021....
Full live stream: • #RomHack2021 Full Conference
On this page of the site you can watch the video online #RomHack2021 with a duration of hours minute second in good quality, which was uploaded by the user Cyber Saiyan 27 September 2021, share the link with friends and acquaintances, this video has already been watched 292 times on youtube and it was liked by 11 viewers. Enjoy your viewing!