|Last Updated|| ||Ratings|| ||Unique User Downloads|| ||Download Rankings|
|2017-11-12 (8 days ago) || 79%||Total: 492 This week: 11||All time: 5,674 This week: 57|
This package can block malicious requests using a white list.
It alters the .htaccess file to make requests for PHP pages go through a filter script that acts like a reverse proxy to implement a Web application framework (WAF).
The filter script will block requests of unauthorized format but the package provides a Web interface for the administrator white list requests of expected formats for the current Web application.
Prize: One big elePHPant Plush Mascott
|Some security attacks are performed by sending requests to Web servers that it is not expected to handle.
One way to minimize the chances of these attacks happening is to use a Web application firewall (WAF).
This package implements a Web Application Firewall in PHP for Web servers that support htaccess configuration.
It alters the .htaccess file so requests are handled by a script of this framework. It keeps track of a white list of request URLs supported by your application, so only approved URL formats are allowed.
URLs with unknown formats are put in moderation, so an administrator can approve the URLs or not for future requests.
This way the application can be protected from types of requests meant to perform security exploits.
Web App Firewall
WAFs goal is protect sites against hackers and virus attacks.
Web App Firewall its PHP application that implement principle of reverse-proxy , control of types variables accepted by server , and comfortable management interface.<br>
W.A.F. supported to work under LAMP servers with .htaccess files support.
Security protection based on white-list strategy: after starting "Learn" mode program collect map of requests, and user have to approve requests. After starting "Guard" mode - program accept only known requests.
Program using white-list strategy, it is more absolute protection, but its requires a lot of work on configuration.
In the program using Intellectual graphical UI , its give an opportunity regularize most chaotic structure.
Google Charts https://developers.google.com/chart/<br>
Linux OS, Apache webserver with support htaccess and mod_rewrite,PHP5 with support CURL and MySQL<br>
Web App Firewall organize reverse-proxy by injection to .htaccess file, and writing Rewrite Rules with security key 1.
WAF script get redirected request and parse path and parameters sent from user. Detect created rules for specified situation and block or accept request via prepared politics.
If request approved, WAF script sending request back to server via CURL with added security key 2 (.htaccess rule miss request if detect key2).
If request blocked, WAF save logs and show 404 page.
Set W.A.F Status Learn on, and Guard off.
Now program start collect request-map from every request to site, leave it for one week for view more complete structure of site.
Write me for help RomanShneer@gmail.com<br>
<a href="https://www.paypal.com/cgi-bin/webscr?cmd=_s-xclick&hosted_button_id=ECZBTKBD7T6A8"><img src="https://www.paypalobjects.com/en_US/i/btn/btn_donate_SM.gif"></a>
||Applications that use this package
If you know an application of this package, send a message to the author to add a link here.