An Insight into RSAC 2023: 6 Keywords of RSAC 2023

Keyword 1: Stronger Together Alone we can do so little; together we can do so much." - Helen Keller The theme of this year's conference is "Stronger Together". What does "Stronger" mean? What is the specific scope to be “Together”? “Stronger" refers to the ability of the business itself to...

NSFOCUS Lua-based Anti-DDoS Solution

Limitations of Pre-configured DDoS Protection Policies Lots of organizations have realized that DDoS defense is critical to the availability of network infrastructure. But most Anti-DDoS solutions in the market still rely on pre-configured protection policies with multiple threshold options to offer multi-layered protection at different levels. However, this approach has...

Apache RocketMQ Remote Code Execution Vulnerability (CVS 2023-33246)

Overview Recently, NSFOCUS CERT found that the PoC of Apache RocketMQ remote code execution vulnerability (CVE-2023-33246) was publicly disclosed online. Due to the lack of appropriate permission verification in some components such as NameServer, Broker, and Controller of RocketMQ, they were unintentionally exposed to the external network. In specific circumstances,...

Illegal Download Protection

When a client downloads a file from a server, NSFOCUS WAF performs protection based on the file type, file size or MIME type. If the download file matches an illegal download restriction policy, NSFOCUS WAF allows or blocks the download based on the corresponding action specified in the policy, and...