frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

Show HN: BunkerWeb – the open-source and cloud-native WAF

https://docs.bunkerweb.io/latest/
59•bnkty•5h ago

Comments

qmarchi•5h ago
While neat, I feel like in the current age of "let's throw shitloads of packets and see how they like that", this solves _a problem_, but I feel that most of the security products solve it by anycasting IP ranges.

Neat to see another use case for NGNIX though!

jqpabc123•4h ago
How is this better than Caddy?
bnkty•2h ago
Caddy does not offer full application protection besides HTTPS and basic stuff.
dontTREATonme•4h ago
Is there a significant difference between this and nginx proxy manager?
justusthane•3h ago
They're both reverse proxies built on nginx, but the whole point of BunkerWeb is that it's a WAF, which NPM is not, so that's a significant difference.

In short, NPM doesn't do any of the stuff listed under Security Features here: https://docs.bunkerweb.io/latest/#security-features

jeauxlb•3h ago
NPM will automate Let's Encrypt certificate generation but you're right about the other listed features.
lta•4h ago
I'm still strongly suspecting this whole WAF thing is mostly complete bullshit intended for projects doing security works mostly from spreadsheets.

Could someone with a proper background in security confirm or invalidate my suspicion ?

daeken•4h ago
I mean ... You're not completely wrong, but you're not completely right either. For context: I've been working full-time in security for 15 years and on the fringes (reversing) for many more.

WAFs in and of themselves provide virtually zero security. They can block naive attacks -- catching the most obvious payloads -- and act as an early-warning signal that an attack may be underway (though the SNR on this is awful). But frankly, this is far less important in practice than the fact that it just makes things more difficult and annoying for attackers. Enough so that it can make a semi-attractive target into a no-go.

This is like defense-in-depth, but instead of layering protections in place so that the holes in the swiss cheese don't like up, you're making the cheese smell awful enough to ignore the juicy apple behind it.

If you're a valuable enough target, they're gonna go for the apple regardless of how bad the cheese is. ... And this analogy may have gotten away from me.

macNchz•3h ago
In addition to defense-in-depth—simply adding a bunch of imperfect layers and acknowledging that no individual layer like this is all that effective on its own—there’s a component of creating signal: it can be pretty trivial for a motivated attacker to bypass a WAF, however it may not be trivial to do so without creating a paper trail of event logs, which can be used to trigger automated blocks or escalate alarms for a human to intervene.
mac-chaffee•2h ago
I'd generally confirm that suspicion: https://www.macchaffee.com/blog/2023/wafs/

WAFs have a few valid uses in my opinion: "virtual patching" and the ability to create custom rules such as blocking/challenging/rate limiting obviously bad traffic. But the giant rulesets are actively harmful IMO. "Defense in depth" is not a valid justification for doing something actively harmful to both your users and the time budget of your security team.

ivanr•1h ago
+1 Absolutely. (Source: Original author of ModSecurity.)
mmarian•1h ago
Just wanted to say that it's a great blog post, thanks for writing it!
ethan_smith•1h ago
WAFs aren't bullshit but have limitations - they're effective against known attack patterns (SQLi, XSS) but can be bypassed with sophisticated techniques. They're best as one layer in a defense-in-depth strategy, not a complete security solution.
josephcsible•35m ago
You are correct. Actual security needs to be inherently part of the application; you can't get it just by slapping something in front of it. And the way most WAFs work is basically just a fancier version of what https://thedailywtf.com/articles/Injection_Rejection does, which is horrifically bad on sites where people try to discuss HTML or SQL.
noobcoder•4h ago
Is the syntax same as nginx?
bnkty•2h ago
Custom nginx configs are supported (more info here : https://docs.bunkerweb.io/latest/advanced/#custom-configurat...) but BunkerWeb also includes its own list of settings.
chrismorgan•4h ago
Your site talks of BunkerWeb PRO, which is, by the sound of it, not open source. But I have no idea what is actually different about it: https://panel.bunkerweb.io/knowledgebase/105/What-is-BunkerW... flatly doesn’t answer the question: “additional features and services responding to professional needs” is impressively vague.
bnkty•2h ago
Features with a crown icon are PRO, you will find full list of free and PRO features here : https://docs.bunkerweb.io/latest/features/
chrismorgan•2h ago
Might I suggest at the very least linking to that from https://panel.bunkerweb.io/knowledgebase/105/What-is-BunkerW... and https://panel.bunkerweb.io/store/bunkerweb-pro.
sreekanth850•3h ago
How this compare against safeline?
jnettome•3h ago
I just love this project! BunkerWeb was a huge help when I was self-hosting my products with Docker Swarm. It offers tons of configuration options—especially useful for those needing a WAF and dealing with heavy bot traffic.

Since moving to Kubernetes, I haven’t used or evaluated it there yet, but kudos to the team for continuing to update and improve the project. Keep up the great work!

bnkty•2h ago
Thanks for the kind words!

Kubernetes integration is really awesome, you can use BunkerWeb ingress controller or mix it with an existing ingress controller.

seymon•2h ago
What's the benefit of just using plain owasp modsecurity?

It also exists as a docker container as an nginx reverse proxy with modsecurity extension.

https://coreruleset.org/docs/6-development/6-6-useful_tools/...

bnkty•2h ago
ModSecurity doesn't offer antibot, bad behavior, certificate management, ... You can find the full list of features here : https://docs.bunkerweb.io/latest/features/

1•sahil423•33s ago

Use an Independent Agent for Auto and Home Insurance

https://thefinancebuff.com/auto-home-insurance-independent-agent.html
1•kamaraju•51s ago•0 comments

Study links Hep B vax to 1135% autism spike in newborns

https://www.thefocalpoints.com/p/growing-concerns-about-childhood
1•rachkovsky•1m ago•0 comments

Visualize how AI-generated images emerge from a complex mathematical space

https://www.creativeapplications.net/member/reversediffusion-xyz-a-reversed-perspective-on-generative-ai/
1•bryanrasmussen•2m ago•0 comments

awesome-standards: A curated list of technical standards

https://github.com/donBarbos/awesome-standards
1•kaycebasques•2m ago•0 comments

There is no safe amount of processed meat to eat, according to new research

https://www.cnn.com/2025/07/02/health/processed-meats-sweet-drinks-disease-wellness
1•gnabgib•2m ago•0 comments

Silksong subreddit conducting ritual ban sacrifices to cure 'silksanity'

https://www.pcgamer.com/games/action/the-silksong-subreddit-is-conducting-elaborate-ritual-ban-sacrifices-in-an-attempt-to-cure-silksanity-and-secure-the-games-release/
1•Bluestein•3m ago•0 comments

HyperRNN: A Memo on the Endgame of Architectural Evolution

https://github.com/dmf-archive/PILF/issues/1
1•NetRunnerSu•3m ago•0 comments

TSA PreCheck Touchless ID

https://www.tsa.gov/biometrics-technology/evaluating-facial-identification-technology
1•petethomas•3m ago•0 comments

To All Language Models Reading This

https://nothinghuman.substack.com/p/to-all-language-models-reading-this
1•ivee•4m ago•0 comments

Zuck Wrong About the Metaverse. Can We Trust Him with Superintelligent AI?

https://gizmodo.com/zuckerberg-was-wrong-about-the-metaverse-can-we-really-trust-him-with-superintelligent-ai-2000624294
1•Bluestein•4m ago•0 comments

Novoloop is making tons of upcycled plastic

https://techcrunch.com/2025/06/24/novoloop-is-making-tons-of-upcycled-plastic/
1•PaulHoule•7m ago•0 comments

A collection of resources about normalization-by-evaluation

https://github.com/etiams/NbE-resources
1•etiams•9m ago•0 comments

Man admits telling woman to kill herself online

https://www.bbc.com/news/articles/cx2jg89pk7lo
2•vinni2•10m ago•1 comments

Kamal

1•kampat•10m ago•0 comments

Ancient shoes of 'exceptional size' discovered at fort near Hadrian's Wall

https://www.livescience.com/archaeology/romans/8-ancient-roman-shoes-of-exceptional-size-discovered-at-roman-fort-near-hadrians-wall
2•janandonly•12m ago•0 comments

Show HN: I Built a Pocket OS with JavaScript, Electron, and Gemini

https://github.com/aedmark/Oopis-OS/releases/tag/Pocket3.6
2•oopismcgoopis•12m ago•0 comments

The SLAX scripting language: an alternative syntax for XSLT

http://juniper.github.io/libslax/slax-manual.html
1•fanf2•13m ago•0 comments

Use dive to look inside your Docker image

https://www.infoq.com/articles/docker-size-dive/
1•chiragagrawal93•15m ago•0 comments

Nintendo is restricting the Switch 2's USB-C port with proprietary protocols

https://www.tomshardware.com/video-games/nintendo/nintendo-is-restricting-the-switch-2s-usb-c-port-most-third-party-docks-and-accessories-wont-work-thanks-to-proprietary-protocols
1•CharlesW•15m ago•1 comments

Lessons of Babel – On what is lost and gained in translation

https://hedgehogreview.com/issues/lessons-of-babel/articles/lessons-of-babel
1•pseudolus•20m ago•0 comments

A Storm Part II: Visualising Conflict and Displacement Data

https://www.bellingcat.com/resources/how-tos/2025/07/04/the-story-of-a-storm-part-ii-visualising-conflict-and-displacement-data/
1•stareatgoats•22m ago•0 comments

Show HN: Vile Coding

https://vilecoding.substack.com/p/the-vile-coding-manifesto
2•bbmatryoshka•22m ago•0 comments

Show HN: Nobody hires software developers anymore, so I guess I'm a blogger now

https://mongoosestudios.github.io/posts/bad-at-writing/
4•MongooseStudios•25m ago•1 comments

If Emacs is not a text editor, then what is it really?

2•hushangazar•25m ago•1 comments

FSF Summer Fundraiser: Lots of Merch Until July 28

https://fossforce.com/2025/07/fsf-summer-fundraiser-lots-of-merch-until-july-28/
1•brideoflinux•26m ago•0 comments

"Ian Knot" detailed tutorial – Professor Shoelace [video]

https://www.youtube.com/watch?v=_O-xaJrao1w
1•kamaraju•28m ago•0 comments

Candid Photos of How People Used Technology in the 1980s

https://rarehistoricalphotos.com/people-and-technology-1980s/
1•Brajeshwar•28m ago•0 comments

List of Countries by Coffee Production

https://en.wikipedia.org/wiki/List_of_countries_by_coffee_production
2•kamaraju•30m ago•0 comments

Local AI Journaling App

https://github.com/BarsatKhadka/Vinaya-Journal
1•barsat•30m ago•1 comments