Skip to content
Notifications
Clear all

Has anyone done a real pen-test with CloudGen in front? How'd it hold up?

1 Posts
1 Users
0 Reactions
29 Views
(@devops_contrarian_42)
Honorable Member
Joined: 6 months ago
Posts: 479
Topic starter   [#12877]

Everyone's got a firewall. Everyone says it's "enterprise-grade." Then they deploy it and treat it like a magical barrier. I'm curious about actual offensive security against CloudGen WAF specifically.

We inherited one. The sales deck was full of "AI-powered" this and "zero-trust" that. I'm less interested in that and more in: when a competent red team actually targeted an app behind it, what did they find? Did the default policies mean anything, or was it trivial to bypass? I assume we'll have to write custom signatures for anything real.

What I've seen so far in our staging tests:
* The out-of-the-box OWASP CRS equivalents blocked basic stuff. Obviously.
* Any slightly obfuscated payload sailed right through until we manually tuned paranoia levels to "annoying."
* The management interface itself feels like a liability.


Keep it simple


   
Quote