Juan Pablo Tosso Profile
Juan Pablo Tosso

@jptosso

Followers
177
Following
264
Media
6
Statuses
105

OWASP #Coraza author - Father - Solutions Architect at @traceableai - ๐Ÿ‡ช๐Ÿ‡ธ๐Ÿ‡ฌ๐Ÿ‡ง๐Ÿ‡ต๐Ÿ‡น - Opinions on the house; not on the company tab

Galicia, Spain
Joined September 2009
Don't wanna be here? Send us removal request.
@jptosso
Juan Pablo Tosso
1 year
Hey @wallarm I was wondering why your implementation of Coraza for your API Firewall is called modsec.go, and you mentioned here ModSecurity but not Coraza :( https://t.co/d4o1WX1pyR A bit of credit would be much appreciated
0
0
1
@jptosso
Juan Pablo Tosso
2 years
V3.0.3 is our first feature release, including HTTP audit logs and memoize, which optimizes the memory consumption while multiple instances of coraza are running by safely sharing regexes and dictionaries across rules
@corazaio
Coraza WAF
2 years
๐Ÿš€ New release is out! Notably it adds support for HTTPS log writer and adds support for memoization for regexes and aho-corasick dictionaries to reduce memory consumption in multi #WAF connectors
1
0
0
@corazaio
Coraza WAF
2 years
Exciting news! ๐ŸŽ‰ OWASP Coraza WAF has officially graduated to a Production Project. This stamp of trust from #OWASP attests to Coraza's readiness as a reliable, production-level #appsec solution. Here's to creating a safer digital world with #coraza! #WAF
1
11
25
@corazaio
Coraza WAF
3 years
๐Ÿ”Security Alert! We've issued a critical patch in #Coraza v3.0.1 to resolve a high-severity vulnerability (7.5 CVSSv3) causing app crashes on malicious requests due to log.Fatalf misuse. Upgrade NOW๐Ÿš€: https://t.co/D8g4waliEa. Thanks to @rmb1222 for the detection! #owasp #coraza
Tweet card summary image
github.com
Important This tag fixes a high-severity vulnerability. See GHSA-c2pj-v37r-2p6h Full Changelog: v3.0.0...v3.0.1
0
4
6
@corazaio
Coraza WAF
3 years
Our coraza-proxy-wasm 0.1.0 is out, the first pre-release of the proxy-wasm extension based on @owasp Coraza v3.0. This extension can be used both on @EnvoyProxy and @IstioMesh to leverage #WAF features and @CoreRuleSet #wasm https://t.co/wi8GZRCqVX
github.com
Initial release This is the very first release of coraza-proxy-wasm based on coraza@v3. You can download the wasm binary directly from the assets section or use the docker image docker pull ghcr.io...
0
4
6
@jptosso
Juan Pablo Tosso
3 years
๐Ÿš€ Big plans on the horizon! We're setting sights on integrating #CorazaWAF with #Nginx - a game-changer for web app & API security. Want to be part of this major shift? Dive in here: https://t.co/wgJ4njvbvs. Even a simple retweet can help us make a safer web! #CyberSecurity
github.com
Hello everyone, We have an exciting project on the table, and we're looking to engage the collective brilliance of this community. We're seeking contributions from individual engineers, ope...
0
4
5
@jptosso
Juan Pablo Tosso
3 years
@rx Sandbox url:
0
0
0
@jptosso
Juan Pablo Tosso
3 years
Did you know #OWASP #coraza supports RESTful parameters as rule variables? SecRule REQUEST_URI "@restpath /users/{user_id}" "..." SecRule ARGS:user_id "@rx \d+" "...msg:'User id is numeric'" Try this in our sandbox
4
0
2
@jptosso
Juan Pablo Tosso
3 years
Special thanks to the core development team and all contributors!! Thanks, @traceableai, @Tetrateio, @intel, for your support and contributions. Thanks to @CoreRuleSet for providing valuable insights and working with us.
1
2
4
@jptosso
Juan Pablo Tosso
3 years
๐Ÿš€Proud to announce #owasp #Coraza v3.0.0! A game-changer for #WebApplicationSecurity and #APISecurity. Major performance leaps๐Ÿ”, reworked API๐Ÿ”ง, and full #CRSv4 support๐Ÿ›ก๏ธ. Embrace the cloud-native, developer-friendly era of #WAF. Dive into the details & join the journey๐Ÿ‘‰
1
6
13
@caddyserver
Caddy Web Server
3 years
One of our maintainers, Weidi Deng, created this awesome demo comparing HTTP/1.1, HTTP/2, and HTTP/3, using a single Caddy config. (It also helps expose browser quirks with HTTP versions. You may be surprised!)
moebuta.org
A demo of http3's impact on downloading many small images and how to implement it
2
19
53
@corazaio
Coraza WAF
3 years
At Wed May 27 13:07:27 2020 -0400 we pushed the first Coraza commit. Happy Aniversary!!! 51039d9
0
1
5
@matt_tesauro
Matt Tesauro
3 years
The latest episode of the @owasp podcast has just dropped: Rethinking WAFs with OWASP Coraza https://t.co/otUl5t68YR Can WAFs be cloud-native and k8s friendly? @corazaio thinks so. @OWASP_podcast #owasp #appsec #waf #blueteam #devsecops #k8s #waf #golang
0
6
13
@jptosso
Juan Pablo Tosso
3 years
Should WAF engines be responsible for enforcing RFC compliance for HTTP, or is it better left to the ruleset? #waf #coraza #owasp #coreruleset
0
0
0
@jptosso
Juan Pablo Tosso
3 years
๐Ÿค” Let's talk about WAF and WebSockets! Are you using a WAF to protect your real-time communications? What challenges have you faced? Share your experiences and insights below ๐Ÿ‘‡ #websockets #WAF #cybersecurity #owasp #coraza
0
1
1
@corazaio
Coraza WAF
3 years
OWASP Coraza v3.0.0-rc.2 is finally here! ๐Ÿ”ฅ Our state-of-the-art web application firewall just got even stronger ๐Ÿ’ช Protect your website from attacks like a boss with Coraza. Upgrade now and experience the ultimate defense against cyber threats! #owasp
Tweet card summary image
github.com
What's Changed Use bitset for inferred phases by @anuraaga in #727 Document test failures due to regex matching arbitrary bytes by @anuraaga in #730 Enable multiline mode for rx by @anuraaga i...
0
7
2
@OWASP_de
OWASP Germany
3 years
Hurry up! In 2 days the #OWASP Hamburg meeting hosts a free talk (online) from Felipe Zipitria + @jptosso presenting the new #WAF engine #Coraza. A new OWASP project in Golang also supporting the @OWASP @CoreRuleSet https://t.co/jEsqZNVvwf Everybody's welcome. So are RTs ;)
Tweet card summary image
meetup.com
Hello out there / Hola por ahรญ, it's been a while, I havenยดt much luck chasing speakers the past months. But the sun is shining again, so here we go ;-) Weยดd like to invi
0
8
10