store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Wed Jun 19, 2013 11:18 am

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 2 posts ] 
Author Message
 Post subject: WAF Challenge Page + Honey Pot
Unread postPosted: Sat Aug 27, 2011 3:31 pm 
Offline
Forum User
Forum User

Joined: Sat Jul 21, 2007 7:31 pm
Posts: 28
Instead of sending users a 403 forbidden could you send them a challenge page with CAPTCHA? That's what CloudFlare does. I think it would save a lot of time from having to deal with false positives.

It would also be nice for ASL to use something like Project Honey Pot.


Top
 Profile  
 
 Post subject: Re: WAF Challenge Page + Honey Pot
Unread postPosted: Sat Aug 27, 2011 11:25 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3264
Location: Chantilly, VA
Thank you, I recommend you take a look at the current feature candidates for the next version of ASL here, and cast your votes:

viewtopic.php?f=3&t=5245

Specifically:

"Atomicorp Candidate #4: Redirect blocked users to a web page that explains why they were blocked and provides options based on the policy set by the system owner (examp,e, give them a captcha and allow for spam, admin password and allow XSS rules, report as false positive, etc.) Also for cases where the system owner does not want them to disable the rule, or allow the event, give them information to reach out the system owner to resolve the issue. (the domain and/or system owner would be able to disable/enable this depending on the type of rule triggered)"

And:

"Atomicorp Candidate #1: ASL RBL - basically a system thats driven by our honeypots and contains all the IPs from attackers, spammers, etc. And advanced version of this would allow everyone to participate by contributing your own attack data to the system. And a really advanced version of this would allow you to create your own RBL based on your data sources."

We also already work with Project Honeypot, they use our realtime WAF rules.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 2 posts ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 0 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group