Month: March 2023

credintial stuffing

Credential stuffing is no DDoS!

Ik haw dit faak heard oer de rin fan de lêste pear jier: ien ûnderfynt in swiere DDoS-oanfal op har webside. As ik har freegje hokker soarte oanfal se ûnderfine, is it antwurd faak dat de skealike minsken harren tûzenen of sels miljoenen POST-oanfragen stjoere. As ik…
Read more

applikaasje DDoS-aanfallen

Application layer DDoS attacks, and how they can be mitigated

DDoS (ferdield denial of service) en DoS (denial of service) oanfallen kinne breed klassearre wurde yn trije kategoryen basearre op 'e lagen fan it OSI-model dy't se rjochtsje: netwurk-laach (Laach 3), transport-laach (Laach 4), en applikaasjelaach (Laach 7). Laach 3 and Layer 4 oanfallen binne typysk minder kompleks–hoewol't se dat kinnen…
Read more

Web Application Firewall (WAF)

The WAF is dead, long live the WAF!

The web application firewall (WAF) is a security tool used to guard against unwanted access to web applications. It is often a security device that sits on top of a web server and guards against threats from the internet or from beyond the network perimeter. Unlike Layer 3 (Network) and Layer 4 (Transport) firewalls, which…
Read more