全球主机交流论坛

 找回密码
 注册

QQ登录

只需一步,快速开始

IP归属甄别会员请立即修改密码
查看: 1304|回复: 1
打印 上一主题 下一主题

请教Cloudflare的WAF防火墙Package: OWASP ModSecurity Core Rule Set作用

[复制链接]
跳转到指定楼层
1#
发表于 2015-10-17 23:16:01 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
What is OWASP?

This package consists of rulesets derived from the OWASP ModSecurity Core Rule Set. These provide an easily pluggable set of generic attack detection rules that provide a base level of protection for any web application.

The OWASP rules operate in scoring threshold mode: each match against a rule increases the threat score of that request. Once a request exceeds a configurable sensitivity threshold (off, low, or high), the action is taken. This action can be simulate (create a log entry but do not block the request), challenge (present the user with an in-browser challenge page, and log), or block (reject the request and log).

Individual rule groups within the OWASP package can be enabled or disabled in "rule details", after which rules can be managed at the individual rule level through the advanced option.
2#
发表于 2015-10-17 23:34:49 | 只看该作者
比较直白的翻译——web漏洞防御。
您需要登录后才可以回帖 登录 | 注册

本版积分规则

Archiver|手机版|小黑屋|全球主机交流论坛

GMT+8, 2025-10-2 06:35 , Processed in 0.063622 second(s), 12 queries , Gzip On, MemCache On.

Powered by Discuz! X3.4

© 2001-2023 Discuz! Team.

快速回复 返回顶部 返回列表