Zum Inhalt springen
Datum unbekanntAngaben zum Datum

Kein Datum in der Quelle. Der Eintrag stammt aus dem ersten Abruf der Quelle, der Tag der Aufnahme sagt nichts über das Erscheinen.

Erstmals gesehen am .

HAProxy Enterprise von HAProxy

HAProxy Enterprise 3.3r1: OWASP CRS 4 und Captcha-Änderungen

HAProxy Enterprise 3.3r1 unterstützt im WAF jetzt OWASP CRS Version 4 (auch zurückportiert auf 3.0r1, 3.1r1 und 3.2r1) und bringt im Captcha-Modul zwei Breaking Changes (neue Action http-response captcha(<captcha_section>) und angepasste filter-Direktiven) sowie neue Captcha-Section-Direktiven.

Key changes in the HAProxy Enterprise 3.3r1 release include:

HAProxy Enterprise WAF

HAProxy Enterprise 3.3r1 WAF introduces support for OWASP CRS version 4. This enhancement is backported to HAProxy Enterprise versions 3.0r1, 3.1r1, and 3.2r1.

Captcha module

Updates to the Captcha module include:

  • Breaking change: Frontend configurations must include the new http-response captcha(<captcha_section>) action. See Actions.

  • Breaking change: The filter directives in frontend configurations must append unless METH_POST { path /.well-known/haproxy/captcha_callback }. For example:

    haproxy

    filter htmldom mode strict head-append '%[captcha.js(<captcha_section>)]' unless METH_POST { path /.well-known/haproxy/captcha_callback }

    haproxy

    filter htmldom mode strict head-append '%[captcha.js(<captcha_section>)]' unless METH_POST { path /.well-known/haproxy/captcha_callback }

  • New captcha section directives: callback-token <expr>, callback-token-lf <fmt>, callback-valid-time <sec>, cookie-name <name>, and cust-html-file-lf <file>. See Captcha section directives for details. …

Originalquelle(öffnet in neuem Tab)Problem melden

Datum unbekanntAngaben zum Datum

Kein Datum in der Quelle. Der Eintrag stammt aus dem ersten Abruf der Quelle, der Tag der Aufnahme sagt nichts über das Erscheinen.

Erstmals gesehen am .

HAProxy Enterprise von HAProxy

HAProxy Enterprise 3.2r1: Besseres Bot Management mit JA4-Fingerprint

HAProxy Enterprise 3.2r1 verbessert das Bot Management Modul durch bessere Integration mit vorgeschalteten Proxys (Übergabe des JA4-Fingerprints), Klassifizierung von Bedrohungstypen wie DDoS, Brute Force, Schwachstellenscans und Web Scraping sowie die Nutzung von botmgmt-evaluate in defaults-Sections.

Key changes in the HAProxy Enterprise 3.2r1 release include:

Bot Management module

  • The Bot Management module now has better integration with third-party proxies. Proxies in front of HAProxy Enterprise often remove some client information before relaying the request, which can impact the accuracy of the module’s scoring. For instance, they sometimes remove the client’s source IP address or information about the client’s TLS stack. To solve that, you can configure the proxy to pass that information as HTTP request headers and then pass it to the Bot Management module. Specifically in this version, you can send the client’s TLS stack profile via a JA4 fingerprint.

  • The Bot Management module can now tell which type of threat was posed by a suspicious bot. When you enable threat detection, the module will analyze the bot’s behavior and attempt to classify it. Classifications include DDoS, login brute forcing, vulnerability scanning, and web scraping.

  • You can now use the botmgmt-evaluate directive in a defaults section.

Web Application Firewall module …

Originalquelle(öffnet in neuem Tab)Problem melden

Datum unbekanntAngaben zum Datum

Kein Datum in der Quelle. Der Eintrag stammt aus dem ersten Abruf der Quelle, der Tag der Aufnahme sagt nichts über das Erscheinen.

Erstmals gesehen am .

HAProxy Enterprise von HAProxy

HAProxy Enterprise 3.1r1: ADFSPIP-Modul, WAF-Profile, Captcha-Cookies

HAProxy Enterprise 3.1r1 führt das neue ADFSPIP-Modul für den externen Zugriff auf Webanwendungen im Firmennetz, WAF-Profile über die neue waf-profile-Section und zusätzliche Cookie-Optionen im Captcha-Modul ein.

Key changes in the HAProxy Enterprise 3.1r1 release include:

ADFSPIP module

  • The new ADFSPIP module enables HAProxy Enterprise to give external clients access to web applications running in a Windows corporate network. HAProxy Enterprise becomes a proxy in front of Microsoft Active Directory Federation Services and web applications running inside the corporate network. It can route external clients to an AD FS sign-in page and to the web applications that they would otherwise not be able to reach.

Web Application Firewall module

  • The Web Application Firewall (WAF) has added support for WAF profiles. Defined in the new waf-profile section, a profile specifies a set of WAF parameters that can be applied to any WAF in the configuration. You can define multiple WAF profiles in a configuration.

Captcha module

  • New Captcha module options give you better control over the cookie that the module creates in the user’s browser. You can set the cookie’s domain, expiration, max age, path, SameSite option, and Secure option.

Global Profiling Engine …

Originalquelle(öffnet in neuem Tab)Problem melden