You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
#. On the Main tab, click **Security -> Overview -> OWASP Compliance**. This opens the OWASP Dashboard. Highlight your new policy ``juice_shop_waf``. You will see that your score is 0/10 for securing against the OWASP top 10. Though you will see partial % scores for some.
16
+
.. image:: ../images/list.png
16
17
17
-
#. Click on the expand arrow next to **A1 Injection**. This will display the attack signature types and required protections you need to secure yourself against this risk.
18
+
#. Click on the expand arrow next to **A3 Injection**. This will display the attack signature types and required protections you need to secure yourself against this risk.
18
19
19
-
.. image:: ../images/a1initialreview.png
20
+
.. image:: ../images/A3list.png
21
+
22
+
#. Notice that each signature type shows the number of signatures in **Staging/Enforced/Total**. Just because signatures are enabled, it does not mean they are enforced. Now let's enforce some signatures.
20
23
21
24
#. On that same screen in the OWASP Dashboard, hover your pointer over **SQL-Injection** and select the **checkmark**. Also hover over **Server Side Code Injection** and select the **checkmark**. These checkmarks apply the protections to the policy. Notice your potential A1 Injection protection % increased.
22
25
23
26
.. Note:: In the dashboard, if you see the checkmark available, it will enforce any protections required to be compliant for that vector.
24
27
25
-
.. image:: ../images/a1addsignatures.png
28
+
.. image:: ../images/A3checked.png
26
29
27
30
#. Press the blue **Review & Update** button below. On the pop up window press the blue **Save & Apply Policy** button.
28
31
@@ -31,18 +34,20 @@ Discover and learn to operate the Dashboard
31
34
#. Now for the sake of expediting the policy blocking malicious traffic, we will turn off signature staging. This will simulate a user waiting out the default 7 days of staging your attack signatures.
32
35
33
36
- Go to **Security -> Application Security -> Policy Building -> Learning and Blocking Settings**
37
+
- Make sure you select the **juice_shop_waf** policy at the top.
38
+
.. image:: ../images/pol_build.png
34
39
- Expand **Attack Signatures**
35
40
- Uncheck the box next to **Enable Signature Staging**
36
-
- Press **Save** at the bottom of that screen
41
+
- Press **Save** at the bottom or the top right of that screen.
37
42
- Press **Apply Policy** button at the top right corner of your screen
38
43
39
44
.. Note:: For those of you looking for the attack signature list, you may have now noticed the location of attack signatures has changed in the most recent release.
40
45
41
-
.. image:: ../images/disablestaging.png
46
+
.. image:: ../images/disablestagingv2.png
42
47
43
48
#. Go back to your OWASP Dashboard **Security -> Overview -> OWASP Compliance**. Select your policy ``juice_shop_waf``.. You can now see a lot more OWASP protections now.
44
49
45
-
.. image:: ../images/dbwithblocking.png
50
+
.. image:: ../images/list_dis_stage.png
46
51
47
52
.. Note:: When we disabled the staging, we represented a user waiting out the enforcement readiness period. We basically just time traveled to the future!! https://youtu.be/8qrriKcwvlY
0 commit comments