Rule files, and bans for a clear sign of attack (closes #24)
check / check (push) Successful in 3m13s
check / check (push) Successful in 3m13s
Every *.rules file in SWWAF_RULES_DIR is read at start and on each change, and each request is checked against the rules after the rate limits: log notes a match, block refuses with 403, ban refuses and bans the netblock for SWWAF_ATTACK_BAN_DURATION, made permanent by its next request or clear sign of attack. path, query and uri are matched as the request line sent them. bans.json gains each ban's cause, and ban notes count earlier bans by cause. The image ships 00-default.rules. Judgement call: a header sent twice is matched with its values joined by ", ". Judgement call: SWWAF_MAX_BAN_DURATION does not cap a ban for an attack. Not in this unit: offences for rule matches, with the error burst. Model: opus-5-5
This commit is contained in:
@@ -167,6 +167,10 @@ RUN groupadd --system --gid 65532 smallwebwaf \
|
||||
# smallwebwaf user at each start.
|
||||
RUN mkdir /var/lib/smallwebwaf
|
||||
|
||||
# The default rule file, in SWWAF_RULES_DIR by default, where an app's
|
||||
# Dockerfile can copy rule files of its own beside it.
|
||||
COPY share/rules.d/00-default.rules /etc/smallwebwaf/rules.d/00-default.rules
|
||||
|
||||
# runsvinit starts runit's runsvdir on /etc/service, where Ubuntu's sv
|
||||
# looks too.
|
||||
COPY --chmod=755 share/smallwebwaf.run /etc/service/smallwebwaf/run
|
||||
|
||||
Reference in New Issue
Block a user