The WAF & OWASP Top 10 policy group contains a robust set of policies that protect your application against the most critical security risks standardized by the Open Web Application Security Project (OWASP).
Some policies in this policy group also block the response phase of a request to prevent data leakage. For example, the Personally identifiable information (PII) policy can block a response if personal or private information is detected. In such cases, the request will return a status code 200 OK, but the response will be blocked.
You can review the OWASP Threats rules and enable or disable them in the Gcore Customer Portal:
-
Navigate to WAAP > Default Rules.
-
In the domain dropdown at the top of the page, select the needed domain.
-
Click the OWASP Threats tab to view and adjust the rules.
InfoOnly the Open redirect and Personally identifiable information policies are disabled by default. To enable a policy, turn on the toggle near that policy.
The following table features the full list of policies that you can configure as part of the WAF & OWASP top threats policy group. These policies correspond to the most common types of threats.