AppTrana
Getting Started
Frequently Asked Questions
Product Details
API Discovery Feature
API Request to Purge CDN Data
API Scan Coverage for OWASP Top 10
ASN based IP Whitelisting
Advanced Behavioral DDoS
Analysis page - Access Trend Visualization
Analysis page - Attack Trend Visualisation
Asset Discovery
BOT Protection
Browser Protection
Configure Custom Error Pages in AppTrana
Configuring Custom Error Page in AppTrana
Configuring Custom Error and Maintenance Pages in AppTrana WAAP
Custom Bot Configuration
Customize Application Behavior with Bot Score
DNS Management
Enable and Configure Single Sign-On
Enabling SIEM Integration
Enhance Your API Security with API Classification
False Positive Analysis Report on WAAP
Malware Scanning for File Uploads
Manage WAAP Email Alerts
OWASP API Security Top 10 2023 – AppTrana API Protection
Origin Health Check Mechanism
Restricted Admin User
Self Service Rules
SwyftComply
SwyftComply for API Scan
Update Origin Server Address
WAF Automated Bypass and Unbypass
Whitelist Vulnerabilities on the AppTrana WAAP
Product User Guide
Indusface WAS
Getting Started
Product User Guide
API Security Audit
Application Audit[AA]
Asset Monitoring
Dashboard
Malware Monitoring[MM]
New Reporting Structure
Reports
Settings
Summary
Vulnerability Assessment[VA]
Frequently Asked Questions
Feature Summary
API Key Based - Scan Log Export
AcuRisQ – Risk Management with Advanced Risk Scoring
SIEM Integration with Sumo Logic
WAS Consulting License
WAS Defacement Checks
Indusface WAS Scanned Vulnerabilities
Indusface Newsletter
Indusface Product Newsletter - August 19
Indusface Product Newsletter - February 2023
Indusface Product Newsletter - June 20
Indusface Product Newsletter - March 2022
Indusface Product Newsletter - October 19
Indusface Product Newsletter - October 2021
Indusface Product Newsletter- April 2021
Indusface Product Newsletter- October 2022
Indusface Product Newsletter-January21
Product Newsletter of February 18
Product Newsletter of January 18
Product Newsletter of January 19
Product Newsletter of July 18
Product Newsletter of March 18
Product Newsletter of March 19
Product Newsletter of May 18
Product Newsletter of May 19
WAF Portal Revamp June 18
Zero Day Vulnerability Reports
Vulnerabilities Detected in 2023
Vulnerability Report of April 23
Vulnerability Report of August 23
Vulnerability Report of December 23
Vulnerability Report of February 23
Vulnerability Report of January 23
Vulnerability Report of July 23
Vulnerability Report of June 23
Vulnerability Report of March 23
Vulnerability Report of May 23
Vulnerability Report of November 23
Vulnerability Report of October 23
Vulnerability Report of September 23
Vulnerabilities Detected in 2016
CRS Vs Zero Day Vulnerabilities - August 2016
CRS vs Zero Day Vulnerability - September 2016
CRS vs. Zero Day Vulnerability - December 2016
CRS vs. Zero Day Vulnerability - November 2016
CRS vs. Zero Day Vulnerability - October 2016
Vulnerabilities Detected in 2017
Vulnerability Report of April 17
Vulnerability report for Apr 3rd - Apr 9th 17
Vulnerability report for April 17th - Apr 23rd 17
Vulnerability report of April 10th - April 16th
Vulnerability Report of March 17
Vulnerability report for 27th Feb - 5th Mar
Vulnerability report for Mar 13th - Mar 19th
Vulnerability report for Mar 20th - Mar 26th
Vulnerability report for Mar 27th - Apr 2nd
Vulnerability report for Mar 6th - Mar 12th
Vulnerability Report of February 17
Vulnerability Report of January 17
Vulnerability Report of August 17
Vulnerability Report of December 17
Vulnerability Report of July 17
Vulnerability Report of June 17
Vulnerability Report of May 17
Vulnerability Report of November 17
Vulnerability Report of October 17
Vulnerability Report of September 17
Vulnerabilities Detected in 2018
Vulnerability Report of April 18
Vulnerability Report of August 18
Vulnerability Report of December 18
Vulnerability Report of February 18
Vulnerability Report of January 18
Vulnerability Report of July 18
Vulnerability Report of June 18
Vulnerability Report of March 18
Vulnerability Report of November 18
Vulnerability Report of October 18
Vulnerability Report of September 18
Vulnerability Reports of May 18
Vulnerabilities Detected in 2019
Vulnerability Report of April 19
Vulnerability Report of August 19
Vulnerability Report of December 19
Vulnerability Report of February 19
Vulnerability Report of January 19
Vulnerability Report of July 19
Vulnerability Report of June 19
Vulnerability Report of March 19
Vulnerability Report of May 19
Vulnerability Report of November 19
Vulnerability Report of October 19
Vulnerability Report of September 19
vulnerabilities Detected in 2020
Vulnerability Report of April 20
Vulnerability Report of December 20
Vulnerability Report of February 20
Vulnerability Report of January 20
Vulnerability Report of July 20
Vulnerability Report of June 20
Vulnerability Report of March 20
Vulnerability Report of May 20
Vulnerability Report of November 20
Vulnerability Report of October 20
Vulnerability Report of Sep 20
Vulnerabilities Detected in 2021
Vulnerability Report of April 21
Vulnerability Report of August 21
Vulnerability Report of December 21
Vulnerability Report of February 21
Vulnerability Report of January 21
Vulnerability Report of July 21
Vulnerability Report of June 21
Vulnerability Report of March 21
Vulnerability Report of May 21
Vulnerability Report of November 21
Vulnerability Report of October 21
Vulnerability Report of September 21
Vulnerabilities Detected in 2022
Vulnerability Report of April 22
Vulnerability Report of August 22
Vulnerability Report of February 22
Vulnerability Report of January 22
Vulnerability Report of July 22
Vulnerability Report of June 22
Vulnerability Report of March 22
Vulnerability Report of May 22
Vulnerability Report of November 22
Vulnerability Report of October 22
Vulnerability Report of September 22
Zero-Day Vulnerability Report - December 2022
Vulnerabilities Detected in 2024
Vulnerability Report of April 2024
Vulnerability Report of August 2024
Vulnerability Report of February 2024
Vulnerability Report of January 2024
Vulnerability Report of July 2024
Vulnerability Report of June 2024
Vulnerability Report of March 2024
Vulnerability Report of May 2024
Vulnerability Report of November 2024
Vulnerability Report of October 2024
Vulnerability Report of September 2024
Security Bulletin
Vulnerabilities 2024
CVE-2024-1071 – Critical Vulnerability in Ultimate Member WordPress Plugin
CVE-2024-4577 – A PHP CGI Argument Injection Vulnerability in Windows Servers
CVE-2024-4879 & CVE-2024-5217 Exposed - The Risks of RCE in ServiceNow
CVE-2024-8517 – Unauthenticated Remote Code Execution in SPIP
Critical Apache OFBiz Zero-day AuthBiz (CVE-2023-49070 and CVE-2023-51467)
Hotjar's OAuth+XSS Flaw Exposes Millions at Risk of Account Takeover
ScreenConnect Authentication Bypass (CVE-2024-1709 & CVE-2024-1708)
Adobe ColdFusion Vulnerabilities Exploited in the Wild
Apache Struts 2 Vulnerability CVE-2023-50164 Exposed
Apache log4j RCE vulnerability
ApacheStructs_VG
CVE-2024-8190 – OS Command Injection in Ivanti CSA
CVE-2024-9264 - Grafana’s SQL Expressions Vulnerability
HTTP/2 Rapid Reset Attack Vulnerability
Multiple Moveit Transfer Vulnerabilities
Oracle WebLogic Server Deserialization
Remote Unauthenticated API Access Vulnerabilities in Ivanti
Unpacking the Zimbra Cross-Site Scripting Vulnerability(CVE-2023-37580)
Table of Contents
- All Categories
- AppTrana
- Getting Started
- Start Free with Advance Plan
Start Free with Advance Plan
Updated by Author
Indusface AppTrana is a cloud-based, comprehensive, and fully managed application security platform that provides Web Application Firewall, Web Application Scanning, API Protection, DDoS & Bot Mitigation, Malware Monitoring, with 24/7 security expertise.
The Advance pricing plan has a 14 days free trial option in which the user is put in bypass mode for 14 more days after the trail period. To know more:
- Go to https://indusface.com
- Click on Application Protection > Web Application Firewall.
- Click on the Pricing tab to view the features and further details.
- Select WEB APPLICATION > Advanced > Start Free.
- A registration page opens.
Parameter | Description |
Business E-Mail | Enter your valid business Email ID. It is a mandatory field. |
Company Name [Optional] | Enter your company name in this field. |
Mobile Number | Enter your working mobile number with the country code. |
End User Agreement | Click on End User Agreement and click the check box after reading, to proceed further. |
- After entering valid details, click the SIGN-UP FOR FREE button to proceed further.
- A verification link would be sent to your registered email ID. Check your Spam/Junk folder in case you haven't received the mail.
- Click on the verification link.
Onboarding:
- By Default, the deployment type is selected as SAAS.
- There are two options for onboarding:
- AppTrana Trial
- I have my Own License
AppTrana Trial
- By default, AppTrana Trial option is selected.
- Click on the Proceed button to continue with Apptrana Trial. Next, the Domain Details page appears.
- Click on here to skip other scenarios and continue from Domain Details page.
I have my own license
- Click on the I have my own license option to upload a license. Then, an Add Promo code option appears.
- Click on the Add symbol (plus button) to add a Promo code. Then, an Add License pop-up appears.
- Contact our Support for a License or any further information.
- Click on the License field, copy the Promo Code and click the Add License button.
- An error message is displayed if the Promo code is wrong for the plan type or if it has been already used.
- License information such as Expiry Date, Websites(consumed/total), Plan Type, and Deployment Type are displayed.
- Click on the Proceed button. Next, the Domain Details page appears.
Domain Details
- Enter your domain name, click on the Proceed button to continue with the Advance plan.
- Origin IP Address and Scan Url fields are pre-populated.
- Click on the Proceed button to continue without enabling CDN in AppTrana and do not require AppTrana to scan behind login page.
- Click on the Back button to go back to the previous step.
[OR]
- Click on the Enable CDN and/or Require AppTrana to scan behind login page toggle button to activate scans on further authenticated data.
- “Require AppTrana to scan behind login page” option sends an email notification to our support team, to request the user credentials, and to place the website on the scanner.
- Click on the Proceed button. Then, the SSL Configuration Details page appears.
The Choose SSL Configuration for your site page has three options. They are:
1) Proceed with Our free SSL Certificate
- By default, the option Proceed with our free SSL certificate is selected.
- Click on the Proceed button to continue with the free certificate. Next, the Process Flow Chart option appears.
- The final Process Flow Chart displays the flow of the Indusface AppTrana Security provided to a website.
- Click on the Done button to close the pop-up. The Dashboard page appears next.
- The onboarded website’s details such as Scan URI, IP Address etc., are displayed.
(OR)
2) I have my own SSL certificate
- Select the I have my own SSL Certificate option to upload your own certificates in the given fields and click on the Verify button. The Process Flow Chart appears next.
- For successful upload, kindly check the format of SSL certificates before.
- Click on the Back button to go back to the previous step.
Parameter | Description |
Private Key | Copy your private key into any text editor and paste the certificate from the editor in the Private Key field. |
Public | Copy your public key into any text editor and paste the certificate from the editor in the Public field. |
Chain | Copy your chain certificate into any text editor and paste the certificate from the editor to the Chain field. Note: While updating multiple chain certificates, paste one below another with a line space. |
- The final Process Flow Chart displays the flow of the Indusface AppTrana security provided to a website.
- Click on the Done button to close the pop-up. The Dashboard page appears next.
- The onboarded website’s details such as Scan URI, IP Address etc., are displayed.
(OR)
3) I don't have SSL certificate. Please help me by one
- This option is to provide the user with the Indusface LetsEncrypt certificate immediately.
- Click on the “I don’t have SSL certificate. Please help me buy one” option to seek help from Indusface AppTrana team and then, click on the Proceed button.
- The final Process Flow Chart displays the flow of the Indusface AppTrana security provided to a website.
- Click on the Done button to close the pop-up. The Dashboard page appears next.
- The onboarded website’ details such as Scan URI, IP Address etc., are displayed.
- The user needs to upgrade the subscription to the Premium Plan to continue with 24/7 AppTrana protection.