No video

Google Cloud Armor - Deep Dive

  Рет қаралды 13,131

Cloud Monkey

Cloud Monkey

Күн бұрын

Deep dive on Google Cloud Armor where you will learn:
What is Google Cloud Armor
Learn Google Cloud Armor Key Concepts
Security Policies
Rules Language
Preconfigured WAF rules
Named IP address lists
Google Cloud Armor Adaptive Protection
Demo
Deploying OWASP Juice Shop websites on Cloud VM(s)/Load Balancer
Explore vulnerabilities on the website
Configure Cloud Armor and fix vulnerabilities
Fix SQL Injection
Fix Cross Site Scripting (XSS)
Fix Local File Inclusion (LFI)
Fix Directory Listing
Testing
Logging/Monitoring
OWASP Juice Shop Test Setup Script: gist.github.com/salimpadela/d...
Rules Language Reference: cloud.google.com/armor/docs/r...
List of Preconfigured WAF rules: cloud.google.com/armor/docs/r...
OWASP ModSecurity Core Rule Set: coreruleset.org/
Chapters:
0:00:00 Introduction to Google Cloud Armor
0:19:11 Demo - Setup OWASP Juice Shop Test Application
0:33:29 Demo - Exploit SQL Injection Vulnerability
0:35:44 Demo - Setup Cloud Armor
0:47:20 Demo - Troubleshooting False Positive Response And Fixing It
0:47:20 Demo - Verify SQL Injection Vulnerability Is Fixed
0:55:09 Demo - Exploit Cross Site Scripting (XSS) Vulnerability
0:55:40 Demo - Fix Cross Site Scripting (XSS) Vulnerability
1:02:31 Demo - Exploit Local File Inclusion (LFI) Vulnerability
1:04:09 Demo - Fix Local File Inclusion (LFI) Vulnerability
1:05:36 Demo - Exploit Directory Listing/Browsing Vulnerability (Request Path)
1:07:03 Demo - Fix Directory Listing/Browsing Vulnerability (Request Path)

Пікірлер: 32
@slickray1411
@slickray1411 Жыл бұрын
Just started to use Cloud Armor. This video is very helpful and instructive. Thanks
@namdeoamit
@namdeoamit 14 күн бұрын
Just stared to learn GCP and this video was very good. It covered all the topics in very simple and easy to understand language, thanks for making this helpful and instructive video.
@CloudMonkey
@CloudMonkey 13 күн бұрын
Glad you enjoyed it!
@rfranciscos236
@rfranciscos236 Жыл бұрын
Thank you for the detailed explanation
@CloudMonkey
@CloudMonkey 6 ай бұрын
Glad you liked it!
@GovindraoKatture
@GovindraoKatture Жыл бұрын
Awesome...
@govardhananks8815
@govardhananks8815 Жыл бұрын
Nice video for understanding cloud armor
@CloudMonkey
@CloudMonkey Жыл бұрын
Glad you liked it
@amitpawar3859
@amitpawar3859 Жыл бұрын
Nice video and very informative.. Keep up the great work sir.. Thanks
@CloudMonkey
@CloudMonkey Жыл бұрын
Thank you
@user-nf8ux8wy9q
@user-nf8ux8wy9q 6 ай бұрын
it is helpful.
@amitbajpai3431
@amitbajpai3431 6 ай бұрын
Thank you so much for this video
@CloudMonkey
@CloudMonkey 6 ай бұрын
You are so welcome!
@anandnerurkar8482
@anandnerurkar8482 Жыл бұрын
very good info. thanks for sharing video.
@CloudMonkey
@CloudMonkey 6 ай бұрын
Glad you liked it!
@lovemishti8296
@lovemishti8296 Жыл бұрын
Superb explanation 😊😊
@CloudMonkey
@CloudMonkey 6 ай бұрын
Glad you liked it!
@ChandrashekharVerma-ci3gi
@ChandrashekharVerma-ci3gi Жыл бұрын
Thanks for the video, It's very informative, Looks like in the custom rule language there is no option to match the request body and deny access. If it is available, then I would love to have it on your next video.
@patrickroyce3956
@patrickroyce3956 Ай бұрын
Nicely done!! best detailed video I came across
@CloudMonkey
@CloudMonkey Ай бұрын
Glad it was helpful!
@marcpinke9413
@marcpinke9413 5 ай бұрын
Are the WAF rules already turned on just by creating the policy or do you have to assign them by hand in order for the WAT to run them? Love the video!
@NarenderPanwar-dk9vy
@NarenderPanwar-dk9vy Жыл бұрын
Very nice explanation. But I am not getting the logs in Policy logs. How do I add the ID now?
@valentinursuleac3933
@valentinursuleac3933 Жыл бұрын
How to exclude specific URL from inspection?
@AndresLeonRangel
@AndresLeonRangel 10 ай бұрын
can you go granular on the rules? Too much exclusion cant be good
@JaimohanR
@JaimohanR Жыл бұрын
is there a way to block .exe files using cloud armor
@nishantmishra73
@nishantmishra73 Жыл бұрын
Hey I am testing cloud armor but im getting some false positive with specific "string" in the POST request. Can I write a specific allow rule to bypass the blocking rule? Eg if "string" is present in the POST request then ALLOW request.
@CloudMonkey
@CloudMonkey Жыл бұрын
I don’t think you can write a rule from scratch. You may want to explore excluding those rules that block like I showed you in the video.
@nawmem92
@nawmem92 Жыл бұрын
Good tutorial, but on top of it, I'd love to have an Apple Juice with you sire! :P :P
@CloudMonkey
@CloudMonkey Жыл бұрын
Lol. Sure. 😂
@surendharankati8054
@surendharankati8054 8 ай бұрын
Is there any other vedio more advance concept on cloud armor
@aarushsingh2006
@aarushsingh2006 Жыл бұрын
Do you provide paid training?
Google Cloud Platform (GCP) - Google Cloud Functions Deep Dive
1:50:36
Cloud Load Balancing Deep Dive and Best Practices (Cloud Next '19)
50:49
Google Cloud Tech
Рет қаралды 45 М.
小蚂蚁被感动了!火影忍者 #佐助 #家庭
00:54
火影忍者一家
Рет қаралды 30 МЛН
IQ Level: 10000
00:10
Younes Zarou
Рет қаралды 11 МЛН
Получилось у Миланы?😂
00:13
ХАБИБ
Рет қаралды 5 МЛН
لقد سرقت حلوى القطن بشكل خفي لأصنع مصاصة🤫😎
00:33
Cool Tool SHORTS Arabic
Рет қаралды 28 МЛН
Google Cloud Platform (GCP) - Cloud Run
1:53:07
Cloud Monkey
Рет қаралды 27 М.
Google Cloud NAT
33:14
Cloud Monkey
Рет қаралды 1,1 М.
reCAPTCHA Enterprise for Web Application Bot Protection
12:12
Nodematic Tutorials
Рет қаралды 391
Cloud Armor | GCP Networking
16:46
TechTrapture
Рет қаралды 3,1 М.
AWS Web Application Firewall (WAF) Full Tutorial | Hands-on
36:15
Loi Liang Yang
Рет қаралды 13 М.
GCP - How to build HA VPN connections between Google Cloud and AWS
48:52
Sandboxing your containers with gVisor (Cloud Next '18)
53:06
Google Cloud Tech
Рет қаралды 5 М.
Google Cloud Platform (GCP) - HTTP Load Balancer
24:32
Cloud Monkey
Рет қаралды 34 М.
小蚂蚁被感动了!火影忍者 #佐助 #家庭
00:54
火影忍者一家
Рет қаралды 30 МЛН