{"repo":"baidu/openrasp","free":true,"listed":false,"github":"https://github.com/baidu/openrasp","clone":"git clone https://github.com/baidu/openrasp.git","description":"🔥Open source RASP solution","language":"C++","stars":2986,"topics":["waf","devsecops","security","iast","rasp"],"license":"Apache-2.0","category":"security-tools","readme_excerpt":"OpenRASP Introduction Unlike perimeter control solutions like WAF, OpenRASP directly integrates its protection engine into the application server by instrumentation. It can monitor various events including database queries, file operations and network requests etc. When an attack happens, WAF matches the malicious request with its signatures and blocks it. OpenRASP takes a different approach by hooking sensitive functions and examines/blocks the inputs fed into them. As a result, this examination is context-aware and in-place. It brings in the following benefits: 1. Only successful attacks can trigger alarms, resulting in lower false positive and higher detection rate; 2. Detailed stack trace is logged, which makes the forensic analysis easier; 3. Insusceptible to malformed protocol. Quick Start See detailed installation instructions here We also provide a few test cases that are corresponding to OWASP TOP 10 attacks, download here GitBook Documentation This is a backup of the original documents from rasp.baidu.com, provided in case the site is unavailable. Access it here: https://test-730.gitbook.io/openrasp-documents-old FAQ 1. List of supported web application servers We've fully tested OpenRASP on the following application servers for Linux platforms: Java Tomcat 6-9 JBoss 4.X Jetty 7-9 Resin 3-4 SpringBoot 1-2 IBM WebSphpere 8.5, 9.0 WebLogic 10.3.6, 12.2.1 PHP 5.3-5.6, 7.0-7.4 The support of other web application servers will also be soon included in the coming releases","default_branch":null,"files":null,"tree":[],"storefront":"/r/baidu","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/baidu/openrasp/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}