BalCCon2k24

Protecting web applications with FOSS
2024-09-22, 13:00–13:45 (Europe/Belgrade), Tesla

Doing with free open-source software what could cost a lot, and benchmarking solutions to find the best fit.


Let's talk about Reverse Proxies and WAFs, and more specifically about HAProxy, mod_security2, OWASP Coraza, OWASP Core Rule Set and fail2ban to protect web applications from some (but not all) nasty web attacks. We'll see integration between HAProxy Community Edition and WAFs, and benchmark results comparing mod_security2 and Coraza, to help us choose.

Security Architect at myDid and independent auditor/pentester/teacher in France.