Wafris Profile Banner
Wafris Profile
Wafris

@wafrisorg

Followers
226
Following
2
Media
20
Statuses
57

Wafris is the open-source Web Application Firewall that works with your web framework to protect your sites from dark traffic, intrusions, and attacks.

Your Web Framework
Joined October 2022
Don't wanna be here? Send us removal request.
Explore trending content on Musk Viewer
@wafrisorg
Wafris
8 months
We're trying to make managing the security of your web apps as automatic as possible. One way we accomplish that is with rulesets: collections of rules specific to threats, frameworks, and goals.
Tweet media one
1
1
7
@wafrisorg
Wafris
9 months
A small sample of some of the rules we put in place for a site that was getting hit with tons of bot/probe traffic.
Tweet media one
Tweet media two
0
1
5
@wafrisorg
Wafris
8 months
We analyzed the traffic of one of our beta users after they put Wafris on their production site. - 50% AI Bots scraping the site - 35% SEO Bots scraping the site - 15% Legit traffic
Tweet media one
0
1
4
@wafrisorg
Wafris
9 months
We're really excited to be heading out to RailsWorld next week and are bringing gifts for everybody.
Tweet media one
1
1
3
@wafrisorg
Wafris
8 months
We just published a new guide on how to better configure Redis for your Wafris instance. Get your 𝚖𝚊𝚡𝚖𝚎𝚖𝚘𝚛𝚢-𝚙𝚘𝚕𝚒𝚌𝚢 𝚟𝚘𝚕𝚊𝚝𝚒𝚕𝚎-𝚝𝚝𝚕 on.
Tweet media one
0
1
3
@wafrisorg
Wafris
8 months
A ton of good feedback and questions have been making it our way after publishing our RailsWorld 2023 recap post. We're always happy to chat with other dev-focused founders about these things. Feel free to DM @rmcastil or @mbuckbee
1
2
3
@wafrisorg
Wafris
8 months
@avo_hq @shortrubynews @yarotheslav Feeling is mutual, you all (on Rails) should give @avo_hq a try
0
0
3
@wafrisorg
Wafris
8 months
How bad are bot probes? We brought a new site up on Wafris, and out of the first 30 IP addresses to connect to it, 25 were malicious bots.
Tweet media one
0
1
3
@wafrisorg
Wafris
9 months
One week to #RailsWorld ! Hope to see you there!
0
0
2
@wafrisorg
Wafris
7 months
Can you tell what this bot is doing? (see screenshot) Answer: it’s a bot using 🇨🇳 Chinese proxy servers, probing for compressed, manually backed-up copies of the site that are kept on the server. Backups that might have API keys, ENV files, or other high-value targets.
Tweet media one
0
0
2
@wafrisorg
Wafris
7 months
It’s essential to recognize that bots going directly for the jugular aren’t playing around but exhibiting direct hostile intent. Here, the second screenshot shows where a single bot (proxied through the US, UK, and Latvia) is ripping through 27 exploits in 3 seconds. 3/3
0
0
0
@wafrisorg
Wafris
7 months
Seems like a good time to announce publicly that we're going to have our Laravel client out very soon (we're still looking for some more beta testers) and are working on a Pulse card for it.
@taylorotwell
Taylor Otwell ☁️ 🦹
7 months
Introducing Laravel Pulse. 💓 Pulse delivers at-a-glance insights into your production application's performance and usage. Track down slow jobs and endpoints, find your most active users, and more. Next week on GitHub. A gift from Laravel to you.
142
505
3K
0
0
2
@wafrisorg
Wafris
7 months
@rskopecek @_swanson Yeah, that's pretty much the case across the board for "public" sites, API/backend sites see fewer (but often more concerning attacks). One of our early users saw a 95% bandwidth savings as their site was so ridden with bots.
0
0
1
@wafrisorg
Wafris
9 months
Why do bots request random seeming images, js and CSS files on your site? (And they do; go look in your logs). They released free/open source themes into the wild that contain backdoors and exploits. The requests identify sites with the compromised themes.
Tweet media one
0
2
1
@wafrisorg
Wafris
8 months
@againstagility Welp, we called our "Code For Insanity" and just give it out at conferences.
1
0
1
@wafrisorg
Wafris
6 months
@__pradyumna @Shpigford @gitlab Well, to be fair we did submit our gem so it's a bit of gemception.
0
0
2
@wafrisorg
Wafris
9 months
@jlogic @mbuckbee They don't (because most don't trigger js) - which is a separate problem as it's very misleading as to what your actual traffic hitting your site is.
1
0
1
@wafrisorg
Wafris
7 months
🤖 Bots are learning too quickly. They now scrape for domains, names, and emails to enhance their probing abilities. Here's a screenshot (from our dashboard) of a 🇨🇳 Chinese bot (based on path requests) making proxied requests through a 🇹🇷 Turkish IP. 1/2
Tweet media one
1
0
1
@wafrisorg
Wafris
8 months
@DouTatsu We’re pretty close. Want to wrap up some things before fully turning on self service. Two weeks tops but are trying to have it done this week.
1
0
1
@wafrisorg
Wafris
7 months
How to spot fakes? One of the easiest ways is to check the "age" of the browser version, given that most are now constantly updated, and older versions stick out. Then there's this Chinese botnet (see screenshot)
Tweet media one
0
0
1