{"id":25307,"date":"2013-09-18T23:42:05","date_gmt":"2013-09-18T23:42:05","guid":{"rendered":"https:\/\/wordpress.org\/plugins-wp\/sucuri-cloudproxy-waf\/"},"modified":"2014-10-08T16:39:56","modified_gmt":"2014-10-08T16:39:56","slug":"sucuri-cloudproxy-waf","status":"closed","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/sucuri-cloudproxy-waf\/","author":20040447,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.4","stable_tag":"1.4","tested":"4.0.38","requires":"","requires_php":"","requires_plugins":"","header_name":"Sucuri CloudProxy Web Firewall (WAF)","header_author":"Sucuri, Inc","header_description":"","assets_banners_color":"d7b7b5","last_updated":"2014-10-08 16:39:56","external_support_url":"","external_repository_url":"","donate_link":"http:\/\/sucuri.net\/website-firewall\/","header_plugin_uri":"http:\/\/cloudproxy.sucuri.net\/","header_author_uri":"http:\/\/sucuri.net","rating":3.7,"author_block_rating":0,"active_installs":100,"downloads":30931,"num_ratings":0,"support_threads":1,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":[],"upgrade_notice":[],"ratings":{"1":"3","2":0,"3":0,"4":0,"5":"6"},"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":"1235421","resolution":"128x128","location":"assets"},"icon-256x256.png":{"filename":"icon-256x256.png","revision":"1235421","resolution":"256x256","location":"assets"}},"assets_banners":{"banner-772x250.jpg":{"filename":"banner-772x250.jpg","revision":"1235421","resolution":"772x250","location":"assets"}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["0.2","0.3","0.4","0.5","0.6","0.7","0.8","1.1","1.2","1.3","1.4"],"block_files":[],"assets_screenshots":[],"screenshots":[],"jetpack_post_was_ever_published":false},"plugin_section":[],"plugin_tags":[1174,1184,1181,600,599],"plugin_category":[54],"plugin_contributors":[77765],"plugin_business_model":[],"class_list":["post-25307","plugin","type-plugin","status-closed","hentry","plugin_tags-firewall","plugin_tags-malware","plugin_tags-scan","plugin_tags-security","plugin_tags-spam","plugin_category-security-and-spam-protection","plugin_contributors-ddsucurinet","plugin_committers-alexandrumatei","plugin_committers-dscalzo"],"banners":[],"icons":{"svg":false,"icon":"https:\/\/s.w.org\/plugins\/geopattern-icon\/sucuri-cloudproxy-waf_d7b7b5.svg","icon_2x":false,"generated":true},"screenshots":[],"raw_content":"<!--section=description-->\n<p>Sucuri Inc is a globally recognized authority in all matters related to\nwebsite security, with specialization in WordPress Security.<\/p>\n\n<p>The <a href=\"http:\/\/sucuri.net\/website-firewall\">Sucuri Security Website Firewall(CloudProxy)<\/a> product is a Cloud-based\nWebsite Application firewall (WAF) and Intrusion Prevention System (IPS)\nproviding everyday website owners Enterprise class security at an affordable\ncost. This security plugin extends the management of the Website Firewall,\nmaking it available to you in your WordPress dashboard. All security features\nare not available in this plugin and for a complete list of the security\nfeature, and its management, visist your <a href=\"https:\/\/login.sucuri.net\">Sucuri Security Dashoard<\/a>.<\/p>\n\n<p>This security plugin performs it's security hardening remotely via a service\nso it does not contain any additional hardening, it employs a number of\nfeatures like virtual hardneing and patching that provide all the security\nhardening your website requires. Additionally, the security hardening is\nperformed off your web server, alleviating the load that attacks place on your\nexisting webserver resources. This service only available via a paid\nsubscription of the <a href=\"https:\/\/sucuri.net\/website-firewall\/signup\">Sucuri Website Firewall<\/a> product.<\/p>\n\n<p>The Sucuri Website Firewall (CloudProxy) product offers you enterprise class perimeter security \nfor your website, addressing some of the biggest issues WordPress websites face in regards to security.<\/p>\n\n<p>This WordPress Security plugin can be used in conjunction with other plugins.\nIt does not replace the <a href=\"https:\/\/wordpress.org\/plugins\/sucuri-scanner\/\">Sucuri Security - Auditing, Malware Scanner and\nHardening plugin<\/a>. The features\nfound in this plugin have been integrated into that plugin, installing it will\nremove this plugin and wrap everything into one toolset.<\/p>\n\n<p>Some of the security issues this product protects your website includes:<\/p>\n\n<ul>\n<li>Security Filtering of all traffic - blocking all security related issues before it hits your website \/ web server<\/li>\n<li>Apply Security Patches Virtually<\/li>\n<li>Virtual Security Hardening<\/li>\n<li>Block of Cross Site Scripting (XSS) attacks<\/li>\n<li>Block of SQL Injection (SLQi) attacks<\/li>\n<li>Block of Remote \/ Local File Inclusion (RFI\/LFI) attacks<\/li>\n<li>Block of Remote Code Execution (RCE) attacks<\/li>\n<li>Advanced Security Access Control Features (i.e., IP whitelisting, 2FA, etc..)<\/li>\n<li>Performance Optimization<\/li>\n<li>Fully Managed Security Protection for Your Website<\/li>\n<\/ul>\n\n<p>A few features of the Sucuri Security Website Firewall product deserve special\nattention for the added value website owners get. They include:<\/p>\n\n<h4>Denial of Service (DDOS) Security Mitigation<\/h4>\n\n<p>Denial of Service (DoS\/DDoS) attacks are not new, but are growing in popularity.\nThe introduction of new booster services, that allow any online users\nto pay someone else to attack someone elses website, have created an influx of\nDoS attacks. They range in scale and impact, but often the impact of such an\nattack is simple - to bring your website down. Kill it's availability and make\nsure that your visitors are unable to access the website.<\/p>\n\n<p>This is especially true if you are leveraging shared server space, this often\nmeans the resources allocated to your one website are marginal and any influx\nin traffic could completely disable your websites performance. If the problem\npersits, you run the risk of getting kicked off your hosts environment.<\/p>\n\n<h4>Brute Force Protection<\/h4>\n\n<p>This is a serious issue in WordPress security. There was a time where many\nperceived this to be an impossibility due to challenges in networks, that is\nno longer the case. Technology has made it so that the latency that was once\nintroduced via networks is no longer the bottlekneck.<\/p>\n\n<p>Brute Force attacks are a security threat that every website owner must be\nmindful of. It's an act in which the attacker attempts to continously\npenetrate your environment, using a variety of attempts with varying username\n\/ password combination in an effort to gain entry. With the hopes that they\nwill get lucky. This can be achieved with other security plugins, but\nattackers continue to develop evasive techniques to bypass security plugins\nthat live an operate at the application layer of your website.<\/p>\n\n<p>This security protection takes place at the edge, offloading the attack from\nyour web server and providing you optimal website security.<\/p>\n\n<h4>Vulnerability Security Exploitation Prevention<\/h4>\n\n<p>This is one of the neatest features our product has to offer. Our research\ninto vulnerabilities has led to some of the largest security disclosures in\n2014 pertaining to software security vulnerabilities. This has affected some\nof the largest brands to inlcude the MailPoet Newsletter plugin, All-in-One\nSEO plugin, RevSlider plugin, and many more.<\/p>\n\n<p>Vulnerabilty exploitation is a big issue today for website owners leveraging\nthe WordPress platform. It is easy to install WordPress, even easier to find a\nplugin that performs a specific function, but often the last thought a website\nowner has is around the security of the code they are putting into their\nwebsite. It's also impossible for the website owner to know whether the code\nis good or bad, or what to do if it's bad but still offers the feature they\nare interested in.<\/p>\n\n<p>Being able to stop attackers from exploiting these security weaknesses is\nimperative for website owners.<\/p>\n\n<h4>Malware Prevention<\/h4>\n\n<p>A malware issue is a security event in which Malicious Software (Malware) has\nbeen injected into your website. It often comes in the form of a\ndrive-by-download or something equivalent in which your website is used as a\nspring board to attack your visitors. Imageine for a moment that someone\nvisiting your website, trusts that your security is top-notch, and gets their\nlocal machine hacked.<\/p>\n\n<p>The attacker then proceeds to steal all their credentials (i.e., emails,\nsocial media account, financial institutions). This user has now lost their\nlife savings and is unable to pay their bills while the matter gets resolved,\nwhich can take months if not years.<\/p>\n\n<p>This is the reality of the pain malware introduces.<\/p>\n\n<h4>Zero Day Immediate Response<\/h4>\n\n<p>This is a very unqiue security feature that allows our security team to\nrespend immediately when a new security incident is released. Zero day events\noccur all the time, they are events that are released for public consumption\nbut have no existing solutions in place. This happens when an attacker\nidentifies a potentially big issue and is interested in watching it all burn.\nWhen this happens your website is left to it's own devices to implement a\nsolution that addresses the problem, if you don't implement it in time or\nadequately you run the risk of getting compromised.<\/p>\n\n<p>With this security feature, Sucuri is able to proactively protect your website\nwithin minutes of a security event, like a Zero Day, being released to the\nworld. Example of this at work include the recent Bash vulnerabilities, and\nmany of the software vulnerabilities mentioned above (i.e., RevSlider,\nMailpoet, etc...).<\/p>\n\n<p>You can read more about some of the features here: <a href=\"http:\/\/sucuri.net\/website-firewall\">Sucuri Security - Website Firewall (CloudProxy)<\/a><\/p>\n\n<p>Update-to-date pricing and features can always be found on the <a href=\"http:\/\/sucuri.net\/website-firewall\/signup\">Plans &amp;\nPricing<\/a> page.<\/p>\n\n<h3>Credits<\/h3>\n\n<ul>\n<li><a href=\"http:\/\/sucuri.net\/website-firewall\/\">Sucuri Website Firewall (CloudProxy)<\/a><\/li>\n<li><a href=\"http:\/\/sucuri.net\">Sucuri, Inc<\/a><\/li>\n<\/ul>\n\n<!--section=installation-->\n<p>Make note that this plugin requires the purchase of the Sucuri Security\nWebsite Firewall (CloudProxy) security product. To attain this product you\nmust signup via the Website Firewall <a href=\"https:\/\/sucuri.net\/website-firewall\/signup\">purchase page<\/a>.<\/p>\n\n<p>Once that is done, you can enable this plugin by following these steps:<\/p>\n\n<ol>\n<li><p>You will want to log into your WordPress administration panel - (e.g.,\nhttp:\/\/yourdomain\/wp-admin)<\/p><\/li>\n<li><p>Navigate to <strong>Plugins Menu<\/strong> option in your WordPress\nadministration panel<\/p><\/li>\n<li><p>Select <strong>Add New<\/strong><\/p><\/li>\n<li><p>Type <strong>Sucuri<\/strong> in the <strong>Search<\/strong> box, and click\n<strong>Search<\/strong> plugins.<\/p><\/li>\n<li><p>The first option you get should be for <strong>Sucuri Security - Website\nFirewall (CloudProxy<\/strong><\/p><\/li>\n<li><p>Select <strong>Install Now<\/strong><\/p><\/li>\n<li><p>Now choose to <strong>Activate<\/strong> the plugin.<\/p><\/li>\n<li><p>Log into your <a href=\"https:\/\/login.sucuri.net\">Sucuri Security dashboard<\/a>.<\/p><\/li>\n<li><p>Click on the <strong>CloudProxy Website Firewall<\/strong> menu option.<\/p><\/li>\n<li><p>Select <strong>settings<\/strong> for the configured website (i.e., next to\nyour website the states should read Activated) and select API.<\/p><\/li>\n<li><p>Copy the <strong>API Key: [randomly generated string]<\/strong>.<\/p><\/li>\n<li><p>Return to your WordPress administration panel.<\/p><\/li>\n<li><p>Click on the <strong>Sucuri WAF<\/strong> menu option in your WP\nadminstration panel.<\/p><\/li>\n<li><p>Paste the API Key into the input box next to <strong>CloudProxy API\nkey<\/strong>.<\/p><\/li>\n<li><p>Click <strong>Update API Key<\/strong>.<\/p><\/li>\n<li><p>Sit back and enjoy!!!<\/p><\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt>What does Sucuri Website Firewall (CloudProxy) do that other WordPress security plugins don't do?<\/dt>\n<dd><p>It is the only enterprise class Website Application Firewall (WAF) designed\nfor WordPress users. It is a true WAF providing real-time protection, where\nother plugins are reactive and depend on disclosures before protecting your\nwebsite. It also uses a state of the art whitelist application profiling\nmodel, contrary to traditional blacklisting WAF systems.<\/p><\/dd>\n<dt>Will Sucuri Security Website Firewall (CloudProxy) slow my site down?<\/dt>\n<dd><p>No. It will actually improve the performance of your website.<\/p><\/dd>\n<dt>How often is Sucuri Website Firewall (CloudProxy) plugin updated?<\/dt>\n<dd><p>It's currently set to update on a weekly \/ bi-weekly basis, depending on a\nvariety of factors. We reserve to update more or less frequently, it's\ndependent on operational needs. Bug \/ security fixes always take priority.<\/p><\/dd>\n<dt>What if I need support?<\/dt>\n<dd><p>In order to use this plugin you require a paid subscription so to get support\nyou can log into your Sucuri Security dashboard and <a href=\"https:\/\/support.sucuri.net\/support\/?new\">submit a\nticket<\/a>.<\/p><\/dd>\n<dt>Where can I find material on the Sucuri Website Firewall (CloudProxy) product?<\/dt>\n<dd><p>Existing users should feel free to make use of our open <a href=\"http:\/\/kb.sucuri.net\/cloudproxy\">Knowledge Base<\/a>.<\/p>\n\n<p>For potential users we recommend starting on the <a href=\"http:\/\/sucuri.net\/website-firewall\/\">Sucuri Security Website Firewall product page<\/a><\/p><\/dd>\n<dt>What if my site security has already been compromised by a hacker?<\/dt>\n<dd><p>If you have already been hacked then this plugin and product will do little to\naddress your immediate issue. We recommend leveraging the <a href=\"http:\/\/sucuri.net\/website-antivirus\/\">Sucuri Security\nWebsite AntiVirus<\/a> to clear any existing\nsecurity issues (i.e., malware infections, [Google Blacklists](https:\/\/sucuri.net\/google-blacklisted-my-website, etc...)<\/p><\/dd>\n<dt>Will Sucuri Security Website Fireawll (CloudProxy) protect me against the Timthumb security problem?<\/dt>\n<dd><p>Absolutely. The TimeThumb vulnerability is categorized as a Remote File Influction (RFI) vulnerability and that is definitely something that our plugin protects against.<\/p><\/dd>\n<dt>Will Sucuri Security Website Firewall (CloudProxy) conflict with the WordFence plugin?<\/dt>\n<dd><p>It should not, but it's possible. Some of the features might be redundant, you\nshould be able to remove and \/ or disable redundant features.<\/p><\/dd>\n<dt>Should I use the Sucuri Security Website Firewall (CloudProxy) plugin in conjunction with the [Sucuri Security - Auditing, Malware Scanner, and Hardening plugin](https:\/\/wordpress.org\/plugins\/sucuri-scanner\/)?<\/dt>\n<dd><p>Once you install the Sucuri Security - Auditing, Malware Scanner, and\nHardening plugin the Website Firewall plugin will be removed from your\ndashboard. The maintenance features of the Website Firewall plugin have been\nintegrated into our Free Security scanner.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.4<\/h4>\n\n<ul>\n<li>Cleaning up a few typos.<\/li>\n<\/ul>\n\n<h4>1.3<\/h4>\n\n<ul>\n<li>Readme and content changes.<\/li>\n<\/ul>\n\n<h4>1.2<\/h4>\n\n<ul>\n<li>Fixed CloudProxy status when behind a CDN.<\/li>\n<li>New calls to API v2.<\/li>\n<li>Code cleanup.<\/li>\n<\/ul>\n\n<h4>1.1<\/h4>\n\n<ul>\n<li>Improved messaging.<\/li>\n<\/ul>\n\n<h4>1.0<\/h4>\n\n<ul>\n<li>Added support for the new servers and naming we have.<\/li>\n<\/ul>\n\n<h4>0.8<\/h4>\n\n<ul>\n<li>Adding filters + new API url.<\/li>\n<\/ul>\n\n<h4>0.7<\/h4>\n\n<ul>\n<li>Adding pagination to the results.<\/li>\n<\/ul>\n\n<h4>0.6<\/h4>\n\n<ul>\n<li>A few more audit logs improvements.<\/li>\n<\/ul>\n\n<h4>0.5<\/h4>\n\n<ul>\n<li>Adding more details on the caching type and audit logs.<\/li>\n<\/ul>\n\n<h4>0.3<\/h4>\n\n<ul>\n<li>Fixed some typos.<\/li>\n<\/ul>\n\n<h4>0.2<\/h4>\n\n<ul>\n<li>Added option to allow the user to clear their CloudProxy caching.<\/li>\n<li>Added listing of the latest audit log entries.<\/li>\n<\/ul>\n\n<h4>0.1<\/h4>\n\n<ul>\n<li>First version.<\/li>\n<\/ul>","raw_excerpt":"Sucuri Security Website Firewall (CloudProxy) is a subscription based WAF and Cloud-based IPS designed to provide optimal security to everyday website &hellip;","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/25307","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=25307"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/dscalzo"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=25307"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=25307"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=25307"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=25307"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=25307"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=25307"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}