Show HN:BunkerWeb——开源且云原生的Web应用防火墙
Show HN: BunkerWeb – the open-source and cloud-native WAF

原始链接: https://docs.bunkerweb.io/latest/

BunkerWeb是一个基于NGINX的开源新一代Web应用防火墙(WAF)和Web服务器,旨在默认情况下保护Web服务安全。它可以无缝集成到Linux、Docker和Kubernetes等各种环境中,充当反向代理。BunkerWeb高度可定制,并提供直观的Web UI,允许用户根据特定需求调整安全设置。 其主要功能包括:使用Let's Encrypt自动启用HTTPS,先进的Web安全措施(HTTP标头、数据泄露防护、TLS强化),集成的ModSecurity和OWASP核心规则集,自动禁止可疑活动,连接和请求限制,以及使用验证码阻止机器人。 专业版提供增强的安全性和功能,包括技术监控。BunkerWeb云提供完全托管的SaaS服务。维护人员提供专业的服务,包括支持和咨询。您可以探索演示网站和UI来测试BunkerWeb强大的安全性。

This Hacker News thread discusses BunkerWeb, an open-source, cloud-native WAF. Users inquire about the differences between the open-source and PRO versions, with the developer, bnkty, providing a link to a feature comparison. Some users praised its usefulness in Docker Swarm for WAF and bot traffic management, while others questioned its value compared to alternatives like OWASP ModSecurity, Caddy, Nginx Proxy Manager, and Cloudflare. Concerns were raised about the PRO version's pricing and the vagueness of its feature descriptions. The general consensus is that WAFs like BunkerWeb can be useful for blocking basic attacks, creating custom rules, and as part of a defense-in-depth strategy, but shouldn't be solely relied upon for security, which should be inherently part of the application itself. Some commenters are skeptical of the overall effectiveness of WAFs against sophisticated attacks.
相关文章

原文

Overview

Overview

Make your web services secure by default!

BunkerWeb is a next-generation, open-source Web Application Firewall (WAF).

As a full-featured web server (based on NGINX under the hood), it protects your web services to make them "secure by default." BunkerWeb integrates seamlessly into your existing environments (Linux, Docker, Swarm, Kubernetes, …) as a reverse proxy and is fully configurable (don't panic, there is an awesome web UI if you don't like the CLI) to meet your specific use cases. In other words, cybersecurity is no longer a hassle.

BunkerWeb includes primary security features as part of the core but can be easily extended with additional ones thanks to a plugin system.

Why BunkerWeb?

  • Easy integration into existing environments: Seamlessly integrate BunkerWeb into various environments such as Linux, Docker, Swarm, Kubernetes, and more. Enjoy a smooth transition and hassle-free implementation.

  • Highly customizable: Tailor BunkerWeb to your specific requirements with ease. Enable, disable, and configure features effortlessly, allowing you to customize the security settings according to your unique use case.

  • Secure by default: BunkerWeb provides out-of-the-box, hassle-free minimal security for your web services. Experience peace of mind and enhanced protection right from the start.

  • Awesome web UI: Take control of BunkerWeb more efficiently with the exceptional web user interface (UI). Navigate settings and configurations effortlessly through a user-friendly graphical interface, eliminating the need for the command-line interface (CLI).

  • Plugin system: Extend the capabilities of BunkerWeb to meet your own use cases. Seamlessly integrate additional security measures and customize the functionality of BunkerWeb according to your specific requirements.

  • Free as in "freedom": BunkerWeb is licensed under the free AGPLv3 license, embracing the principles of freedom and openness. Enjoy the freedom to use, modify, and distribute the software, backed by a supportive community.

  • Professional services: Get technical support, tailored consulting, and custom development directly from the maintainers of BunkerWeb. Visit the BunkerWeb Panel for more information.

Security features

Explore the impressive array of security features offered by BunkerWeb. While not exhaustive, here are some notable highlights:

  • HTTPS support with transparent Let's Encrypt automation: Easily secure your web services with automated Let's Encrypt integration, ensuring encrypted communication between clients and your server.

  • State-of-the-art web security: Benefit from cutting-edge web security measures, including comprehensive HTTP security headers, prevention of data leaks, and TLS hardening techniques.

  • Integrated ModSecurity WAF with the OWASP Core Rule Set: Enjoy enhanced protection against web application attacks with the integration of ModSecurity, fortified by the renowned OWASP Core Rule Set.

  • Automatic ban of strange behaviors based on HTTP status codes: BunkerWeb intelligently identifies and blocks suspicious activities by automatically banning behaviors that trigger abnormal HTTP status codes.

  • Apply connection and request limits for clients: Set limits on the number of connections and requests from clients, preventing resource exhaustion and ensuring fair usage of server resources.

  • Block bots with challenge-based verification: Keep malicious bots at bay by challenging them to solve puzzles such as cookies, JavaScript tests, captchas, hCaptcha, reCAPTCHA, or Turnstile, effectively blocking unauthorized access.

  • Block known bad IPs with external blacklists and DNSBL: Utilize external blacklists and DNS-based blackhole lists (DNSBL) to proactively block known malicious IP addresses, bolstering your defense against potential threats.

  • And much more...: BunkerWeb is packed with a plethora of additional security features that go beyond this list, providing you with comprehensive protection and peace of mind.

To delve deeper into the core security features, we invite you to explore the security tuning section of the documentation. Discover how BunkerWeb empowers you to fine-tune and optimize security measures according to your specific needs.

Demo

A demo website protected with BunkerWeb is available at demo.bunkerweb.io. Feel free to visit it and perform some security tests.

Web UI

BunkerWeb offers an optional user interface to manage your instances and their configurations. An online read-only demo is available at demo-ui.bunkerweb.io. Feel free to test it yourself.

BunkerWeb Cloud

Overview

BunkerWeb Cloud

Don't want to self-host and manage your own BunkerWeb instance(s)? You might be interested in BunkerWeb Cloud, our fully managed SaaS offering for BunkerWeb.

Try our BunkerWeb Cloud offer and get access to:

  • A fully managed BunkerWeb instance hosted in our cloud
  • All BunkerWeb features, including PRO ones
  • A monitoring platform with dashboards and alerts
  • Technical support to assist you with configuration

If you are interested in the BunkerWeb Cloud offering, don't hesitate to contact us so we can discuss your needs.

PRO version

BunkerWeb PRO free trial

Want to quickly test BunkerWeb PRO for one month? Use the code freetrial when placing your order on the BunkerWeb panel or by clicking here to directly to apply the promo code (will be effective at checkout).

When using BunkerWeb, you have the choice of the version you want to use: open-source or PRO.

Whether it's enhanced security, an enriched user experience, or technical monitoring, the BunkerWeb PRO version allows you to fully benefit from BunkerWeb and meet your professional needs.

In the documentation or the user interface, PRO features are annotated with a crown crown pro icon to distinguish them from those integrated into the open-source version.

You can upgrade from the open-source version to the PRO one easily and at any time. The process is straightforward:

Do not hesitate to visit the BunkerWeb panel or contact us if you have any questions regarding the PRO version.

Professional services

Get the most out of BunkerWeb by accessing professional services directly from the maintainers of the project. From technical support to tailored consulting and development, we are here to assist you in securing your web services.

You will find more information by visiting the BunkerWeb Panel, our dedicated platform for professional services.

Don't hesitate to contact us if you have any questions. We will be more than happy to respond to your needs.

Ecosystem, community, and resources

Official websites, tools, and resources about BunkerWeb:

  • Website: Get more information, news, and articles about BunkerWeb.
  • Panel: A dedicated platform to order and manage professional services (e.g., technical support) around BunkerWeb.
  • Documentation: Technical documentation of the BunkerWeb solution.
  • Demo: Demonstration website of BunkerWeb. Don't hesitate to attempt attacks to test the robustness of the solution.
  • Web UI: Online read-only demo of the web UI of BunkerWeb.
  • Threatmap: Live cyberattacks blocked by BunkerWeb instances all around the world.

Community and social networks:

联系我们 contact @ memedata.com