WAF and AppSec Controls
42 incident problems about WAF and AppSec Controls. Start with the reviewed ones.
먼저 읽을 가이드
추천 문제
All problems (42)
SECURITY-017Session cookie becomes insecure after CDN to origin scheme mismatchUsers arrive over HTTPS, but origin headers make the app think the request is plain HTTP and weaken the session cookie flags.SecurityIntermediate20 minProSECURITY-029OAuth callback accepted on web tier but rejected after load balancer hopOAuth callback accepted on web tier but rejected is a hands-on troubleshooting drill. The callback parameters are correct, yet one load balancer rewrite alters the host or scheme expected by validation. Identity and Access Management needs to be checked by narrowing scope, rec...SecurityIntermediate22 minPro