15 repository-uri
Gateways that monitor and filter incoming web traffic to block malicious requests targeting specific applications.
Explore 15 awesome GitHub repositories matching security & cryptography · Web Application Firewalls. Refine with filters or upvote what's useful.
Acest proiect este un director curatoriat de comunitate cu software open-source conceput pentru implementarea în medii de server private și laboratoare de acasă (home labs). Servește drept resursă cuprinzătoare pentru descoperirea alternativelor independente, auto-găzduite, la serviciile cloud mainstream, permițând utilizatorilor să mențină proprietatea deplină a datelor și controlul asupra infrastructurii lor digitale. Directorul este structurat printr-o taxonomie ierarhică ce organizează o colecție vastă de aplicații în categorii logice, variind de la gestionarea media și analiza datelor la comunicare privată și instrumente de productivitate în echipă. Se distinge printr-un proces colaborativ de peer-review, unde membrii comunității validează calitatea și relevanța fiecărei trimiteri pentru a se asigura că directorul rămâne precis și fiabil. Proiectul acoperă o suprafață largă de capabilități, inclusiv automatizarea infrastructurii, implementarea serviciilor bazate pe containere și gestionarea configurației declarative. Aceste instrumente ajută utilizatorii să mențină medii de server reproductibile și să gestioneze dependențele complexe ale serviciilor pe hardware privat. Directorul este menținut ca un repository controlat prin versiuni, asigurându-se că toate actualizările și modificările conduse de comunitate sunt urmărite și transparente.
Filters incoming web traffic to block malicious requests and prevent unauthorized access by scraper bots.
Traefik is a cloud-native edge router and API gateway designed to manage service communication and traffic flow across distributed infrastructure. It functions as a dynamic service proxy that automatically discovers backend services and configures routing rules in real time, eliminating the need for manual restarts or complex configuration updates. By integrating directly with container orchestrators and service registries, it maintains a consistent state for network traffic, load balancing, and security policy enforcement. The project distinguishes itself through its deep integration with di
Embeds high-performance firewall capabilities directly into the traffic path to secure API endpoints without external dependencies.
SafeLine is a containerized web application firewall and reverse proxy designed to secure web services by inspecting incoming HTTP traffic. It acts as a security gateway that sits in front of backend infrastructure to filter malicious requests and enforce access policies before they reach the application server. The platform distinguishes itself through advanced bot mitigation and content protection capabilities. It employs challenge-response mechanisms to verify human users and dynamically obfuscates HTML and JavaScript content to prevent unauthorized scraping and code tampering. These featu
Inspects incoming HTTP traffic to block common web vulnerabilities and malicious requests as a reverse proxy firewall.
Excelize is a library for reading and writing spreadsheet files in the Office Open XML format. It provides a comprehensive suite of tools for programmatically creating, modifying, and analyzing workbooks, worksheets, and cell data, ensuring compatibility across various office software suites through structured XML serialization. The library distinguishes itself with a built-in formula calculation engine that evaluates complex mathematical and logical expressions directly against workbook data. It also features a memory-mapped streaming architecture, which allows for the efficient processing o
Inspects incoming traffic against a rule engine to detect and block common web exploits like SQL injection.
XSStrike is a security tool designed to detect cross-site scripting vulnerabilities through parameter fuzzing and web response analysis. It functions as a web application fuzzer and vulnerability scanner that identifies injection points and security flaws. The project includes a specialized utility for detecting blind XSS, where payloads execute asynchronously or on separate pages. It also features a JavaScript library auditor to identify outdated libraries with known vulnerabilities and a dedicated tool for identifying and bypassing web application firewalls using various evasion techniques.
Identifies the presence of security filters and applies specific evasion techniques to bypass them.
The AWS Cloud Development Kit is an infrastructure-as-code framework that enables developers to define and provision cloud resources using familiar programming languages. By utilizing construct-based synthesis, it translates high-level, object-oriented code into declarative templates, allowing for the automated management of complex cloud environments through a centralized, code-driven control plane. The framework distinguishes itself through its ability to model infrastructure as a dependency-aware resource graph, ensuring that components are provisioned and updated in the correct order. It
Integrates with web application firewalls to filter malicious traffic and defend against common web-based attacks.
CrowdSec is a collaborative, distributed security engine designed for threat detection and infrastructure protection. It functions as an intrusion detection system that parses logs and network traffic to identify malicious patterns, utilizing a bucket-based threshold detection model to aggregate events and trigger alerts. The platform is built on a modular architecture that includes a centralized local API server for managing security signals and a relational database for persistent storage of remediation decisions. What distinguishes the project is its decoupled enforcement model, which offl
Configures web application firewall rules to inspect and filter incoming traffic for malicious patterns.
Bunkerized Nginx is a containerized security automation system that provides a secure reverse proxy and web application firewall. It focuses on protecting web applications by monitoring container labels within cloud-native orchestration systems to automatically update security settings and firewall rules. The system distinguishes itself through automated security operations, including the automatic management of SSL certificates and an automated client banning mechanism that blocks IP addresses based on HTTP status codes. It features bot challenge mechanisms using CAPTCHAs, JavaScript, or coo
Provides a gateway to monitor and filter incoming web traffic to protect applications from common cyber attacks.
fuzzdb is a collection of datasets designed for web application penetration testing and dynamic fuzzing. It provides a fuzzing payload dictionary, a resource discovery wordlist, and a fault injection dataset containing corrupted Unicode, null bytes, and escape codes to trigger application crashes and logic errors. The project includes a security filter bypass list featuring polyglots and encoded strings to evade web application firewalls and input validation filters. It also provides a comprehensive web application penetration testing dataset specifically for identifying flaws such as cross-s
Provides curated lists of patterns and regex dictionaries to bypass security filters and WAFs during testing.
reconftw is an attack surface management framework and reconnaissance workflow orchestrator designed to automate the discovery, mapping, and monitoring of external digital assets. It operates as a modular tool-chain pipeline that coordinates a sequence of security tools to perform intelligence gathering and vulnerability scanning. The project distinguishes itself through a cloud-native deployment model that parallelizes scanning workloads across a fleet of remote VPS instances to bypass local resource constraints. It utilizes container-based environment isolation to ensure consistent executio
Includes utilities designed to identify the presence and type of web application firewalls protecting a target.
AllAboutBugBounty is a curated collection of bug bounty techniques and payloads for web application security testing. It serves as a reference resource covering common web vulnerabilities and exploitation methods for security researchers, providing a structured approach to identifying and exploiting web application security flaws in bug bounty programs. The repository covers a wide range of attack categories including authentication bypass, cross-site scripting injection, server-side request forgery, web cache poisoning, and business logic abuse. It includes techniques for bypassing access co
Provides WAF-specific payloads to deliver cross-site scripting attacks by evading security filters.
WAFW00F allows one to identify and fingerprint Web Application Firewall (WAF) products protecting a website.
Identifies whether a website is protected by a WAF through HTTP response analysis.
TacticalRMM is a remote monitoring and management platform designed for overseeing endpoints and automating IT administration. It functions as an endpoint management tool and IT automation framework, providing a centralized dashboard for executing scripts, monitoring system health, and managing remote devices across multiple tenants. The platform distinguishes itself through a comprehensive remote administration suite that includes real-time shell access, remote file management, and registry editing. It integrates with third-party remote desktop software and provides a hierarchical policy inh
Implements a core rule set to detect and block common web attacks while allowing legitimate traffic.
Allinssl is a multi-platform certificate manager and ACME automator designed to handle the full lifecycle of security certificates. It provides a web-based management interface to orchestrate the issuance, renewal, and deployment of certificates across various servers and cloud environments. The system distinguishes itself through an orchestration engine that pushes certificates to diverse targets, including web application firewalls, server control panels, and remote hosts. It automates domain ownership verification using DNS challenges across multiple providers and employs an event-driven w
Automates the delivery of SSL certificates to Safeline WAF using API tokens.
Acest proiect este un Kubernetes ingress controller care gestionează traficul extern prin configurarea dinamică a load balancer-ului HAProxy. Funcționează ca o punte între resursele cluster-ului și planul de date al rețelei, traducând definițiile de ingress de nivel înalt în configurații proxy active pentru a ruta traficul HTTP, TCP și UDP în medii containerizate. Controller-ul se distinge printr-o arhitectură decuplată care separă logica planului de control de procesul proxy, permițând gestionarea independentă a ciclului de viață și versionarea. Utilizează generarea de configurații bazată pe șabloane și reîncărcarea la cald în timp real prin socket-uri Unix pentru a aplica actualizările de rutare fără întreruperi ale serviciului. Prin suportarea tiparelor de trafic avansate, cum ar fi orchestrarea deployment-ului blue-green, manipularea header-elor și injectarea de parametri personalizați, oferă o alternativă ușoară la implementările complete de service mesh pentru gestionarea traficului la margine (edge). Platforma include o suită completă de capabilități operaționale, acoperind gestionarea automată a certificatelor TLS, politici granulare de control al accesului și integrarea cu firewall-uri pentru aplicații web externe. De asemenea, oferă o observabilitate robustă prin logarea traficului personalizat, metrici de performanță și verificări auxiliare ale stării de sănătate care ajustează dinamic ponderile de echilibrare a sarcinii bazate pe starea backend-ului în timp real. Controller-ul suportă modele de deployment flexibile, inclusiv scoping la nivel de namespace și filtrare de resurse, pentru a permite operarea multi-tenant într-un singur cluster. Se integrează cu tiparele standard de rețea Kubernetes și Gateway API pentru a asigura compatibilitatea cu fluxurile de lucru de infrastructură existente.
Connects to external security agents to inspect incoming traffic for malicious patterns and block unauthorized requests.