Skip to content

Commit 99a24ff

Browse files
committed
module2lab1_2
1 parent eedbf82 commit 99a24ff

File tree

12 files changed

+14
-343
lines changed

12 files changed

+14
-343
lines changed

docs/waf2025/images/A3checked.png

91.1 KB
Loading

docs/waf2025/images/A3list.png

95.2 KB
Loading
213 KB
Loading

docs/waf2025/images/list.png

59.2 KB
Loading
67.9 KB
Loading

docs/waf2025/images/pol_build.png

65 KB
Loading

docs/waf2025/module2/lab1.rst

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -64,6 +64,8 @@ Create security policy using the Guided Configuration
6464

6565
.. image:: ../images/ready_to_deploy.png
6666

67+
#. Click Finish on the next screen.
68+
6769
#. After the policy is created, we will want to apply a logging profile to our new security policy.
6870

6971
- Go to **Securirty -> Overview -> Summary**, and the policy you just created should be listed.

docs/waf2025/module2/lab2.rst

Lines changed: 11 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -13,16 +13,19 @@ Discover and learn to operate the Dashboard
1313
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
1414

1515
#. On the Main tab, click **Security -> Overview -> OWASP Compliance**. This opens the OWASP Dashboard. Highlight your new policy ``juice_shop_waf``. You will see that your score is 0/10 for securing against the OWASP top 10. Though you will see partial % scores for some.
16+
.. image:: ../images/list.png
1617

17-
#. Click on the expand arrow next to **A1 Injection**. This will display the attack signature types and required protections you need to secure yourself against this risk.
18+
#. Click on the expand arrow next to **A3 Injection**. This will display the attack signature types and required protections you need to secure yourself against this risk.
1819

19-
.. image:: ../images/a1initialreview.png
20+
.. image:: ../images/A3list.png
21+
22+
#. Notice that each signature type shows the number of signatures in **Staging/Enforced/Total**. Just because signatures are enabled, it does not mean they are enforced. Now let's enforce some signatures.
2023

2124
#. On that same screen in the OWASP Dashboard, hover your pointer over **SQL-Injection** and select the **checkmark**. Also hover over **Server Side Code Injection** and select the **checkmark**. These checkmarks apply the protections to the policy. Notice your potential A1 Injection protection % increased.
2225

2326
.. Note:: In the dashboard, if you see the checkmark available, it will enforce any protections required to be compliant for that vector.
2427

25-
.. image:: ../images/a1addsignatures.png
28+
.. image:: ../images/A3checked.png
2629

2730
#. Press the blue **Review & Update** button below. On the pop up window press the blue **Save & Apply Policy** button.
2831

@@ -31,18 +34,20 @@ Discover and learn to operate the Dashboard
3134
#. Now for the sake of expediting the policy blocking malicious traffic, we will turn off signature staging. This will simulate a user waiting out the default 7 days of staging your attack signatures.
3235

3336
- Go to **Security -> Application Security -> Policy Building -> Learning and Blocking Settings**
37+
- Make sure you select the **juice_shop_waf** policy at the top.
38+
.. image:: ../images/pol_build.png
3439
- Expand **Attack Signatures**
3540
- Uncheck the box next to **Enable Signature Staging**
36-
- Press **Save** at the bottom of that screen
41+
- Press **Save** at the bottom or the top right of that screen.
3742
- Press **Apply Policy** button at the top right corner of your screen
3843

3944
.. Note:: For those of you looking for the attack signature list, you may have now noticed the location of attack signatures has changed in the most recent release.
4045

41-
.. image:: ../images/disablestaging.png
46+
.. image:: ../images/disablestagingv2.png
4247

4348
#. Go back to your OWASP Dashboard **Security -> Overview -> OWASP Compliance**. Select your policy ``juice_shop_waf``.. You can now see a lot more OWASP protections now.
4449

45-
.. image:: ../images/dbwithblocking.png
50+
.. image:: ../images/list_dis_stage.png
4651

4752
.. Note:: When we disabled the staging, we represented a user waiting out the enforcement readiness period. We basically just time traveled to the future!! https://youtu.be/8qrriKcwvlY
4853

docs/waf2025/module4/lab2.rst

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ Execute an attack via a python script
55
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
66

77

8-
#. Open Terminal on the LInux jump host
8+
#. Open Terminal on the Linux jump host
99

1010
#. cd /graphql
1111

docs/waf2025/module5/lab1.rst

Lines changed: 0 additions & 115 deletions
This file was deleted.

0 commit comments

Comments
 (0)