Service · Cybersecurity

Web application firewall (WAF)

An online shop gets daily visits from things that are not customers: bots trying passwords on the PrestaShop admin panel, scanners hunting for a vulnerable module, competitors copying the catalogue and prices every hour and, most costly of all, networks using the checkout to test stolen cards against the Redsys payment gateway. Each failed transaction carries a fee and, if it keeps happening, the bank starts asking questions. A web application firewall sits in front of the site and filters that traffic before it reaches the server. We set it up on Cloudflare, AWS WAF, Azure Front Door or a module on your own server, depending on where the site is hosted, and tune it so it stops the bots without getting in the way of shoppers buying on their phones in the middle of the sales.

OWASP Top 10
baseline rules switched on
Admin panel
out of reach for bots
Weeks ahead
of Black Friday and the sales
No change
of hosting or platform

What falls within the scope of this service

A WAF does not fix a vulnerable module, but it buys time to update it and removes most of the automated noise.

Pin down the details with one of our engineers

Baseline rules

Protection against SQL injection, cross-site scripting and known attacks on PrestaShop, WooCommerce, WordPress and Magento, using provider-managed rules that update themselves.

Admin panel

Back office access limited by country, by address or by identity, with a cap on attempts. The admin URL stops being the busiest door on the shop.

Card testing

Rate limits on the basket and checkout, challenges for suspicious sessions and alerts when gateway declines climb. For many shops this is the protection that saves the most money.

Bots and crawlers

We tell legitimate search engines apart from bots that scrape prices or hammer the internal search. The first are let through; the second are slowed down or stopped.

Denial of service

Protection against bursts of malicious traffic at application level, which can take a small shop offline without any huge attack.

Reports

A monthly summary of what was blocked and which false positives were fixed, so you know what the filter is stopping and whether it bothers anyone.

How the engagement unfolds, one stage at a time

Every WAF starts in observation mode. Switching on blocking without knowing your real traffic is the fastest way to lose sales.

01

Review

Platform, hosting, DNS, payment gateway and installed modules. We decide where the filter goes with the smallest possible change.

02

Observation

One or two weeks logging what the WAF would block, to spot legitimate requests that look like attacks, such as a marketplace feed or calls from the ERP.

03

Gradual blocking

Rules are enabled family by family, starting with the safest, and checked daily in the first few days.

04

Ongoing tuning

A monthly review or, under a support plan, continuous follow-up, with particular care before each campaign.

Stolen-card testing shows up on the payment gateway bill before it shows on the website. Hundreds of small declined payments overnight generate fees and bank warnings while the shop carries on as if nothing were wrong. A per-session attempt limit and a bot challenge cut it off before the bank gets in touch.

Common questions

Usually not. Cloud WAFs such as Cloudflare work by changing DNS so traffic passes through them before reaching your current server. If the site runs on AWS or Azure, we use that provider's own service. Your hosting stays the same.

Not if it is configured properly. Legitimate search engine crawlers are recognised and allowed through. A WAF with caching also tends to speed up page loads, which does help rankings.

We identify them during observation: the Amazon.es or PcComponentes feed, calls from Channable or Lengow, ERP synchronisation and notifications from Redsys or Bizum. Each gets a documented exception so none of them breaks.

No. The WAF lowers the risk until the update arrives and holds back automated traffic, but a vulnerable module is still vulnerable. It is one more layer alongside updates, strong back office passwords and backups.

Stop the bots before your next campaign

Tell us which platform your shop or site runs on, where it is hosted and which payment gateway you use. We will reply with a setup proposal.

Hours
Monday to Friday, 9:00-18:00 Spanish time (CET), answers within a working day
Meetings
Video calls via Google Meet or Teams

This site only stores the cookies it needs to work and to remember your chosen city. No advertising or tracking cookies are set. See our privacy policy for the details.