A ModSecurity + OWASP Core Rule Set firewall was placed in front of a test web app, then attacked with real SQL injection, XSS, path-traversal and command-injection payloads. This page shows what got blocked, what didn't, and why — read the KPI row first, then the category and detail views for specifics.
The four numbers that summarize whether the firewall is doing its job.
Of the malicious payloads sent through the WAF, how many were stopped vs. how many reached the application in each category.
A WAF that blocks everything isn't useful — this confirms normal, benign traffic still gets through.
Filter by target or attack category, or click a column header to sort. This table is the full underlying data behind every chart above.
| Target | Category | Payload | HTTP status | Outcome |
|---|
An example excerpt from ModSecurity's audit log for one blocked request — this is illustrative; your own run writes real entries to ./audit.log.