Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions docs/class1/module1/lab1/lab1.rst
Original file line number Diff line number Diff line change
Expand Up @@ -49,7 +49,7 @@ a) Web App & API Protection -> Load Balancers -> HTTP Load Balancer -> Add HTTP
==================================== =================================================================================================
**Name** arcadia-re-lb

**Domains** arcadia-re-$$makeId$$.workshop.emea.f5se.com
**Domains** arcadia-re-$$makeId$$.workshop-sa.emea.f5se.com

**Load Balancer Type** HTTP

Expand All @@ -63,6 +63,6 @@ a) Web App & API Protection -> Load Balancers -> HTTP Load Balancer -> Add HTTP
<script>c1m1l2b();</script>

3. So far, Arcadia is not protected but exposed all over the world on all F5XC RE.
Check your Arcadia application is exposed and reachable from the F5XC Global Network by browsing to :ext_link:`http://arcadia-re-$$makeId$$.workshop.emea.f5se.com`
Check your Arcadia application is exposed and reachable from the F5XC Global Network by browsing to :ext_link:`http://arcadia-re-$$makeId$$.workshop-sa.emea.f5se.com`

.. warning:: Some Service Providers have a very long recursive cache. It can take several minutes to get a DNS response. You can change your DNS server to 1.1.1.1 or 8.8.8.8 to fix that.
2 changes: 1 addition & 1 deletion docs/class1/module1/lab2/lab2.rst
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@ Lab 2 - Testing and Visibility

In order to make sure all is working we will need to login into the application and look at the relevant dashboards.

1. Login into the app while using the **arcadia-re-lb** load balancer :ext_link:`http://arcadia-re-$$makeId$$.workshop.emea.f5se.com`
1. Login into the app while using the **arcadia-re-lb** load balancer :ext_link:`http://arcadia-re-$$makeId$$.workshop-sa.emea.f5se.com`

.. table::
:widths: auto
Expand Down
2 changes: 1 addition & 1 deletion docs/class1/module2/lab2/lab2.rst
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ Lab 2 - Testing and Visibility
1. First lets try and attack out application with an **XSS attack** using the bellow URL. Th attack will be blocked and a **support ID** will be provided. Save the **support ID** as it will be used in the next step.


:ext_link:`http://arcadia-re-$$makeId$$.workshop.emea.f5se.com/?a=%3Cscript%3Ealert(%27xss%27)`
:ext_link:`http://arcadia-re-$$makeId$$.workshop-sa.emea.f5se.com/?a=%3Cscript%3Ealert(%27xss%27)`



Expand Down
4 changes: 2 additions & 2 deletions docs/class1/module3/lab1/lab1.rst
Original file line number Diff line number Diff line change
Expand Up @@ -95,13 +95,13 @@ a. First let's do a **curl** request that will simulate a user login request. Al

.. code-block:: none

curl -H "Content-Type: application/json;charset=UTF-8" --data-raw "{\"email\":\"satoshi@bitcoin.com\",\"password\":\"bitcoin\"}" http://arcadia-re-$$makeId$$.workshop.emea.f5se.com/v1/login
curl -H "Content-Type: application/json;charset=UTF-8" --data-raw "{\"email\":\"satoshi@bitcoin.com\",\"password\":\"bitcoin\"}" http://arcadia-re-$$makeId$$.workshop-sa.emea.f5se.com/v1/login

b. Now we will re run the same request but with the email parameter value being just a number. We won't be able to login but the request will not be blocked.

.. code-block:: none

curl -H "Content-Type: application/json;charset=UTF-8" --data-raw "{\"email\":\"11223344\",\"password\":\"bitcoin\"}" http://arcadia-re-$$makeId$$.workshop.emea.f5se.com/v1/login
curl -H "Content-Type: application/json;charset=UTF-8" --data-raw "{\"email\":\"11223344\",\"password\":\"bitcoin\"}" http://arcadia-re-$$makeId$$.workshop-sa.emea.f5se.com/v1/login


4. Apply the **service policies** to the **HTTP Load Balancer**
Expand Down
4 changes: 2 additions & 2 deletions docs/class1/module3/lab2/lab2.rst
Original file line number Diff line number Diff line change
Expand Up @@ -5,15 +5,15 @@ Lab 2 - Testing

.. code-block:: none

curl -H "Content-Type: application/json;charset=UTF-8" --data-raw "{\"email\":\"satoshi@bitcoin.com\",\"password\":\"bitcoin\"}" http://arcadia-re-$$makeId$$.workshop.emea.f5se.com/v1/login
curl -H "Content-Type: application/json;charset=UTF-8" --data-raw "{\"email\":\"satoshi@bitcoin.com\",\"password\":\"bitcoin\"}" http://arcadia-re-$$makeId$$.workshop-sa.emea.f5se.com/v1/login



2. Now let's do the same but with the invalid email parameter. This time the request will get blocked.

.. code-block:: none

curl -H "Content-Type: application/json;charset=UTF-8" --data-raw "{\"email\":\"11223344\",\"password\":\"bitcoin\"}" http://arcadia-re-$$makeId$$.workshop.emea.f5se.com/v1/login
curl -H "Content-Type: application/json;charset=UTF-8" --data-raw "{\"email\":\"11223344\",\"password\":\"bitcoin\"}" http://arcadia-re-$$makeId$$.workshop-sa.emea.f5se.com/v1/login


We just have been able to demonstrate that F5 XC is not just a basic Web Application Firewall but also has also advanced **Positive Security Policy** capabilities which greatly enhance the security of the application.
2 changes: 1 addition & 1 deletion docs/class1/module4/lab2/lab2.rst
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@ To perform this test you can use any of the following proxy sites:



1. Use proxy server of you choosing and enter the Arcadia App URL: :ext_link:`http://arcadia-re-$$makeId$$.workshop.emea.f5se.com/`
1. Use proxy server of you choosing and enter the Arcadia App URL: :ext_link:`http://arcadia-re-$$makeId$$.workshop-sa.emea.f5se.com/`

2. The requests coming from the proxy servers will be blocked with a 403 status code.

Expand Down
6 changes: 3 additions & 3 deletions docs/class1/module5/lab2/lab2.rst
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@ Lab 2 - Testing

In order to test we will behave as a bad actor.

1. Browse to the app :ext_link:`http://arcadia-re-$$makeId$$.workshop.emea.f5se.com/` and login
1. Browse to the app :ext_link:`http://arcadia-re-$$makeId$$.workshop-sa.emea.f5se.com/` and login

.. table::
:widths: auto
Expand Down Expand Up @@ -64,12 +64,12 @@ In order to test we will behave as a bad actor.

We will be able to track this user in the F5XC console to **Web App & API Protection** -> **Dashboards** -> **Security** -> Click on the **arcadia-re-lb** Load Balancer -> **Malicious Users** -> **Refresh**

4. Hacker understands that he can't attack the internal APIs and decides to move to public endpoints. We will simulate this by browsing to the following URLs :ext_link:`http://arcadia-re-$$makeId$$.workshop.emea.f5se.com/?a=/etc/passwd` and holding **F5 button** on the keyboard to generate multiple requests
4. Hacker understands that he can't attack the internal APIs and decides to move to public endpoints. We will simulate this by browsing to the following URLs :ext_link:`http://arcadia-re-$$makeId$$.workshop-sa.emea.f5se.com/?a=/etc/passwd` and holding **F5 button** on the keyboard to generate multiple requests

5. Since the user has not logged in we will block it based on IP address go to the **Malicious Users** dashboard like in step 3 and you will be able to follow and indetify these attacks

6. Right now your IP is being blocked temporarily and we need to allow it in order to continue with the lab.

Go to the **Malicious Users** dashboard and click on the IP identifier ( it should look similar to this **IP-156.33.44.55** ) -> Click **Add To Allow List** -> Apply -> Apply -> Save and Exit

7. Close all previous application tabs and open a new one, when browsing :ext_link:`http://arcadia-re-$$makeId$$.workshop.emea.f5se.com/` the app will be fine.
7. Close all previous application tabs and open a new one, when browsing :ext_link:`http://arcadia-re-$$makeId$$.workshop-sa.emea.f5se.com/` the app will be fine.
2 changes: 1 addition & 1 deletion docs/class1/module6/lab2/lab2.rst
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ Lab 2 - Testing

.. code-block:: none

curl -H "Content-Type: application/json;charset=UTF-8" --data-raw "{\"email\":\"satoshi@bitcoin.com\",\"password\":\"bitcoin\"}" http://arcadia-re-$$makeId$$.workshop.emea.f5se.com/v1/login
curl -H "Content-Type: application/json;charset=UTF-8" --data-raw "{\"email\":\"satoshi@bitcoin.com\",\"password\":\"bitcoin\"}" http://arcadia-re-$$makeId$$.workshop-sa.emea.f5se.com/v1/login

2. The request will be blocked.

2 changes: 1 addition & 1 deletion docs/class1/module7/lab2/lab2.rst
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ Lab 2 - Testing

.. code-block:: none

curl -H "Content-Type: application/json;charset=UTF-8" --data-raw "{\"email\":\"satoshi@bitcoin.com\",\"password\":\"bitcoin\"}" http://arcadia-re-$$makeId$$.workshop.emea.f5se.com/v1/login
curl -H "Content-Type: application/json;charset=UTF-8" --data-raw "{\"email\":\"satoshi@bitcoin.com\",\"password\":\"bitcoin\"}" http://arcadia-re-$$makeId$$.workshop-sa.emea.f5se.com/v1/login

2. The request will be blocked.

2 changes: 1 addition & 1 deletion docs/class1/module9/lab2/lab2.rst
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@ Lab 2 - Testing and Visibility

In order to make sure all is going to the internal endpoint we will need to generate traffic and look at the relevant dashboards.

1. Login into the app while using the **arcadia-re-lb** load balancer :ext_link:`http://arcadia-re-$$makeId$$.workshop.emea.f5se.com`
1. Login into the app while using the **arcadia-re-lb** load balancer :ext_link:`http://arcadia-re-$$makeId$$.workshop-sa.emea.f5se.com`

.. table::
:widths: auto
Expand Down
2 changes: 1 addition & 1 deletion docs/class1/modulea1/lab2/lab2.rst
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@ We have listed bellow a few tests that you can try out.

.. code-block:: none

curl -H "Content-Type: application/json;charset=UTF-8" --data-raw "{\"email\":\"11223344\",\"password\":\"bitcoin\"}" http://arcadia-re-$$makeId$$.workshop.emea.f5se.com/v1/login
curl -H "Content-Type: application/json;charset=UTF-8" --data-raw "{\"email\":\"11223344\",\"password\":\"bitcoin\"}" http://arcadia-re-$$makeId$$.workshop-sa.emea.f5se.com/v1/login

3. BOT Protection

Expand Down
4 changes: 2 additions & 2 deletions docs/class4/module1/lab1/lab1.rst
Original file line number Diff line number Diff line change
Expand Up @@ -85,7 +85,7 @@ a) Web App & API Protection -> Load Balancers -> HTTP Load Balancer -> Add HTTP
==================================== =================================================================================================
**Name** sentence-re-lb

**Domains** sentence-re-$$makeId$$.workshop.emea.f5se.com
**Domains** sentence-re-$$makeId$$.workshop-sa.emea.f5se.com

**Load Balancer Type** HTTP

Expand All @@ -96,6 +96,6 @@ a) Web App & API Protection -> Load Balancers -> HTTP Load Balancer -> Add HTTP


3. So far, Sentence application is not protected but exposed all over the world on all F5XC RE.
Check your Sentence application is exposed and reachable from the F5XC Global Network by browsing to :ext_link:`http://sentence-re-$$makeId$$.workshop.emea.f5se.com`
Check your Sentence application is exposed and reachable from the F5XC Global Network by browsing to :ext_link:`http://sentence-re-$$makeId$$.workshop-sa.emea.f5se.com`

.. warning:: Some Service Providers have a very long recursive cache. It can take several minutes to get a DNS response. You can change your DNS server to 1.1.1.1 or 8.8.8.8 to fix that.
6 changes: 3 additions & 3 deletions docs/class4/module1/lab3/lab3.rst
Original file line number Diff line number Diff line change
Expand Up @@ -6,13 +6,13 @@ Test your modern API application protection

.. code-block:: none

curl -H "Content-Type: application/json;charset=UTF-8" http://sentence-re-$$makeId$$.workshop.emea.f5se.com/api/adjectives
curl -H "Content-Type: application/json;charset=UTF-8" http://sentence-re-$$makeId$$.workshop-sa.emea.f5se.com/api/adjectives

.. code-block:: none

curl -H "Content-Type: application/json;charset=UTF-8" http://sentence-re-$$makeId$$.workshop.emea.f5se.com/api/animals
curl -H "Content-Type: application/json;charset=UTF-8" http://sentence-re-$$makeId$$.workshop-sa.emea.f5se.com/api/animals

.. code-block:: none

curl -H "Content-Type: application/json;charset=UTF-8" http://sentence-re-$$makeId$$.workshop.emea.f5se.com/api/locations
curl -H "Content-Type: application/json;charset=UTF-8" http://sentence-re-$$makeId$$.workshop-sa.emea.f5se.com/api/locations

2 changes: 1 addition & 1 deletion docs/class4/module2/lab1/lab1.rst
Original file line number Diff line number Diff line change
Expand Up @@ -112,7 +112,7 @@ Make a quick test of API Validation

Change ' by " if the command does not work on your laptop.

curl --location --request DELETE 'http://sentence-re-$$makeId$$.workshop.emea.f5se.com/api/adjectives/beautiful'
curl --location --request DELETE 'http://sentence-re-$$makeId$$.workshop-sa.emea.f5se.com/api/adjectives/beautiful'

.. note:: Here we replace the ID such as ``4``, by a string ``beautiful``

Expand Down
2 changes: 1 addition & 1 deletion docs/class4/module2/lab4/lab4.rst
Original file line number Diff line number Diff line change
Expand Up @@ -101,7 +101,7 @@ It is time to run a traffic generator script to populate the logs and the AI/ML
.. code-block:: none

cd /home/ubuntu/api-protection-lab
bash api-all.sh sentence-re-$$makeId$$.workshop.emea.f5se.com
bash api-all.sh sentence-re-$$makeId$$.workshop-sa.emea.f5se.com

.. note::

Expand Down
Loading
Loading