Juan Pablo Tosso
@jptosso
Followers
177
Following
264
Media
6
Statuses
105
OWASP #Coraza author - Father - Solutions Architect at @traceableai - ๐ช๐ธ๐ฌ๐ง๐ต๐น - Opinions on the house; not on the company tab
Galicia, Spain
Joined September 2009
Hey @wallarm I was wondering why your implementation of Coraza for your API Firewall is called modsec.go, and you mentioned here ModSecurity but not Coraza :( https://t.co/d4o1WX1pyR A bit of credit would be much appreciated
0
0
1
๐ Six talks in the next three months, existing times: September: - https://t.co/Kv6DYbGLTo - https://t.co/ItWjPXrx3h - https://t.co/aypoTBQEh3 October: - https://t.co/Y3whJAQM99 - https://t.co/7bHdE7zuoT November: -
events.canonical.com
UbuCon Korea ๋ ํ๊ตญ ๋ด ์ฐ๋ถํฌ ๊ธฐ์ฌ์ ๋ฐ ์ฌ์ฉ์๋ฅผ ๋์์ผ๋ก ๋งค๋
์ด๋ฆฌ๋ ํ์ฌ๋ก, ์ฐ๋ถํฌ ๊ด๋ จ ์ฌ๋ก์ ๋
ธํ์ฐ๋ฅผ ๊ณต์ ํ๋ ๋ชจ์์ ์ฅ ์
๋๋ค. UbuCon Korea 2023 ํ์ฌ์์๋ "๊ฐ๋ฐ์ ์์ฐ์ฑ์ ์ํ ์ฐ๋ถํฌ (Ubuntu for Developer Productivity)"๋ฅผ ํ
๋ง๋ก ํ๋ก๊ทธ๋จ์ด ๊ตฌ์ฑ๋ ์์ ์
๋๋ค.๋ณธ ์น์ฌ์ดํธ๋ ๋ฐํ ์ ์์...
1
1
4
V3.0.3 is our first feature release, including HTTP audit logs and memoize, which optimizes the memory consumption while multiple instances of coraza are running by safely sharing regexes and dictionaries across rules
๐ New release is out! Notably it adds support for HTTPS log writer and adds support for memoization for regexes and aho-corasick dictionaries to reduce memory consumption in multi #WAF connectors
1
0
0
๐Security Alert! We've issued a critical patch in #Coraza v3.0.1 to resolve a high-severity vulnerability (7.5 CVSSv3) causing app crashes on malicious requests due to log.Fatalf misuse. Upgrade NOW๐: https://t.co/D8g4waliEa. Thanks to @rmb1222 for the detection! #owasp #coraza
github.com
Important This tag fixes a high-severity vulnerability. See GHSA-c2pj-v37r-2p6h Full Changelog: v3.0.0...v3.0.1
0
4
6
Our coraza-proxy-wasm 0.1.0 is out, the first pre-release of the proxy-wasm extension based on @owasp Coraza v3.0. This extension can be used both on @EnvoyProxy and @IstioMesh to leverage #WAF features and @CoreRuleSet #wasm
https://t.co/wi8GZRCqVX
github.com
Initial release This is the very first release of coraza-proxy-wasm based on coraza@v3. You can download the wasm binary directly from the assets section or use the docker image docker pull ghcr.io...
0
4
6
๐ Big plans on the horizon! We're setting sights on integrating #CorazaWAF with #Nginx - a game-changer for web app & API security. Want to be part of this major shift? Dive in here: https://t.co/wgJ4njvbvs. Even a simple retweet can help us make a safer web! #CyberSecurity
github.com
Hello everyone, We have an exciting project on the table, and we're looking to engage the collective brilliance of this community. We're seeking contributions from individual engineers, ope...
0
4
5
Today we released #OWASP Coraza v3.0.0, a huge community effort that brought in lots of improvements in performance, API and compatibility https://t.co/VVCxOtTXVi Join the party! #waf #golang #security
github.com
What's Changed Coraza's latest v3.0.0 release brings a highly refactored engine that offers more flexibility and major improvements. Notable changes include: Performance improvement: Perfo...
0
12
12
Special thanks to the core development team and all contributors!! Thanks, @traceableai, @Tetrateio, @intel, for your support and contributions. Thanks to @CoreRuleSet for providing valuable insights and working with us.
1
2
4
๐Proud to announce #owasp #Coraza v3.0.0! A game-changer for #WebApplicationSecurity and #APISecurity. Major performance leaps๐, reworked API๐ง, and full #CRSv4 support๐ก๏ธ. Embrace the cloud-native, developer-friendly era of #WAF. Dive into the details & join the journey๐
1
6
13
We just released Coraza Caddy v2.0.0 RC1. Please do try it and comment! https://t.co/BKdPWu7avj
#WAF cc @caddyserver
github.com
What's Changed Updates coraza, uses parseServerName by @M4tteoP in #43 chore: refactors connector. by @jcchavezs in #49 chore: deprecates Include config field. by @jcchavezs in #51 feat: align...
0
6
12
One of our maintainers, Weidi Deng, created this awesome demo comparing HTTP/1.1, HTTP/2, and HTTP/3, using a single Caddy config. (It also helps expose browser quirks with HTTP versions. You may be surprised!)
moebuta.org
A demo of http3's impact on downloading many small images and how to implement it
2
19
53
At Wed May 27 13:07:27 2020 -0400 we pushed the first Coraza commit. Happy Aniversary!!! 51039d9
0
1
5
The latest episode of the @owasp podcast has just dropped: Rethinking WAFs with OWASP Coraza https://t.co/otUl5t68YR Can WAFs be cloud-native and k8s friendly? @corazaio thinks so. @OWASP_podcast
#owasp #appsec #waf #blueteam #devsecops #k8s #waf #golang
0
6
13
Should WAF engines be responsible for enforcing RFC compliance for HTTP, or is it better left to the ruleset? #waf #coraza #owasp #coreruleset
0
0
0
๐ค Let's talk about WAF and WebSockets! Are you using a WAF to protect your real-time communications? What challenges have you faced? Share your experiences and insights below ๐ #websockets #WAF #cybersecurity #owasp #coraza
0
1
1
OWASP Coraza v3.0.0-rc.2 is finally here! ๐ฅ Our state-of-the-art web application firewall just got even stronger ๐ช Protect your website from attacks like a boss with Coraza. Upgrade now and experience the ultimate defense against cyber threats! #owasp
github.com
What's Changed Use bitset for inferred phases by @anuraaga in #727 Document test failures due to regex matching arbitrary bytes by @anuraaga in #730 Enable multiline mode for rx by @anuraaga i...
0
7
2
Hurry up! In 2 days the #OWASP Hamburg meeting hosts a free talk (online) from Felipe Zipitria + @jptosso presenting the new #WAF engine #Coraza. A new OWASP project in Golang also supporting the @OWASP @CoreRuleSet
https://t.co/jEsqZNVvwf Everybody's welcome. So are RTs ;)
meetup.com
Hello out there / Hola por ahรญ, it's been a while, I havenยดt much luck chasing speakers the past months. But the sun is shining again, so here we go ;-) Weยดd like to invi
0
8
10