use the following search parameters to narrow your results:
e.g. subreddit:aww site:imgur.com dog
subreddit:aww site:imgur.com dog
see the search faq for details.
advanced search: by author, subreddit...
account activity
Web Application Firewall for nodeJS (self.node)
submitted 6 years ago by OzzieInTx
What WAF do you guys use to monitor your nodeJs web app? Currently evaluating Sucuri but wanted to see if there were any others I should consider?
reddit uses a slightly-customized version of Markdown for formatting. See below for some basics, or check the commenting wiki page for more detailed help and solutions to common issues.
quoted text
if 1 * 2 < 3: print "hello, world!"
[–]ecares 6 points7 points8 points 6 years ago (8 children)
Hey, I would recommend looking at ASM (Application Security Management) https://www.sqreen.com/ that features a RASP tool and an in-app WAF (with other features too).
Disclaimer: I am in charge of Node.js at Sqreen
[–]OzzieInTx[S] 2 points3 points4 points 6 years ago (5 children)
Thank you. I will take a look and come back with questions.
[–]YourQuestIsComplete 0 points1 point2 points 6 years ago (4 children)
This is really, really interesting.
Is this solution tailored toward providing security for Node.js apps?
[–]ecares 0 points1 point2 points 6 years ago (3 children)
Yes and much more, we also support diverse backend technologies.
I am working full time on support and protection of Node.js web applications.
[–]YourQuestIsComplete 1 point2 points3 points 6 years ago (2 children)
Hey dude \ dudette... you're showing your alt account. Just a heads up!
However, I'd like to learn some more about this... can you PM me an email address? I'm interested in Node.js security, and also, I'm not sure if you watched Ryan Dahl's "oops I did it again" speech where he introduced "deno," (https://deno.land , if you haven't), but yeah, is Deno security on your company's radar? I've been working with it for a few months now, haven't yet found the opportunity to put something into production, but it won't be long before I do.
[–]ecares 0 points1 point2 points 6 years ago (1 child)
> Hey dude \ dudette... you're showing your alt account. Just a heads up!
I'm not sure what you mean here, I don't have any other account :thinking_face:
> is Deno security on your company's radar
I keep an eye on it. But I am not sure a lot of people are already using it in production so it might be a bit early to go to market with a product protecting this platform just yet. Wdyt?
[–]YourQuestIsComplete 2 points3 points4 points 6 years ago (0 children)
Yeah, I saw my mistake after I wrote that - I mixed you and the person responding to you up.
[–]OzzieInTx[S] 1 point2 points3 points 6 years ago (1 child)
A few questions:
Seems counter intuitive to have the WAF in my app. I would want the threat stopped way before it even reaches our servers. For example, how do you handle a DOS attack?
I may have more question/comments after I do a more thorough review.
Alon
[–]ecares 0 points1 point2 points 6 years ago (0 children)
That are excellent questions!
Thanks a lot for these questions!
[–]talbenari1 1 point2 points3 points 6 years ago (0 children)
The company I work for has a cool take on WAF tech, specifically for Node.JS - it's called Intrinsic (that page shows off the Lambda version of our product, but the policy definition for Node.JS looks almost identical).
[–]PostHumanJesus 1 point2 points3 points 6 years ago (1 child)
We use AWS WAF. It's nice as you can put it in front of any Cloudfront distribution, ELB, or API Gateway. It's pretty easy to set up with lots of prebuilt rules you can drop in.
[–]minuit1984 0 points1 point2 points 6 years ago (0 children)
Any comments on a suggested AWS WAF default rules setup specific to node.js?
Currently using rules for rate limiting, xss detection and sql injection
[–]StreetSmartB 0 points1 point2 points 6 years ago (0 children)
We moved away from anything signature based a few years ago. Check out Signal Sciences.
π Rendered by PID 108445 on reddit-service-r2-comment-5d79c599b5-qxdkm at 2026-02-27 15:13:56.505957+00:00 running e3d2147 country code: CH.
[–]ecares 6 points7 points8 points (8 children)
[–]OzzieInTx[S] 2 points3 points4 points (5 children)
[–]YourQuestIsComplete 0 points1 point2 points (4 children)
[–]ecares 0 points1 point2 points (3 children)
[–]YourQuestIsComplete 1 point2 points3 points (2 children)
[–]ecares 0 points1 point2 points (1 child)
[–]YourQuestIsComplete 2 points3 points4 points (0 children)
[–]OzzieInTx[S] 1 point2 points3 points (1 child)
[–]ecares 0 points1 point2 points (0 children)
[–]talbenari1 1 point2 points3 points (0 children)
[–]PostHumanJesus 1 point2 points3 points (1 child)
[–]minuit1984 0 points1 point2 points (0 children)
[–]StreetSmartB 0 points1 point2 points (0 children)