NoLimitSecu #520 - BunkerWeb

NoLimitSecu #520 - BunkerWeb

🎙 NoLimitSecu 👥 2K 📅 November 17, 2025 ⏱ 29 min 👁 164 📄 interview 🧭 2026-08-16
Available in: English (current) Français

Keywords

WAFopen sourceBunkerWebcybersecurityreverse proxy

Summary

In this episode of NoLimitSecu, Florian Pitance, founder of Bunkerity, discusses BunkerWeb, an open-source Web Application Firewall (WAF). He explains the role of a WAF as a reverse proxy that inspects HTTP/HTTPS traffic to protect web applications. Pitance describes his motivation for creating BunkerWeb, citing the lack of a turnkey, open-source solution that is easy to deploy and manage. The project is built on Nginx, with Lua for request handling and Python for auxiliary components like the admin interface and scheduler. He discusses the challenges faced, including performance issues and two CVEs related to open redirects, which were responsibly disclosed. The business model relies on an AGPLv3 license with dual licensing, a professional version with additional features, and a cloud offering. BunkerWeb integrates with ModSecurity and OWASP Core Rule Set, and includes features like anti-bot, rate limiting, and suspicious behavior detection. Pitance also mentions telemetry for threat intelligence and partnerships with CrowdSec. He reflects on the importance of commercial thinking from day one and the role of consulting and audits in funding development. The episode provides insights into the open-source business model and the technical aspects of building a WAF.

190 words

Critical Evaluation

Value of the Information & Strength of the Argument

The value of the information is high for those interested in open-source security tools and WAFs. The guest provides practical insights into the design choices, challenges, and business model of BunkerWeb. The argumentation is coherent and grounded in real-world experience, though it lacks deep technical detail or comparative analysis with other WAFs. The discussion is more conversational than rigorous, but it offers valuable perspectives on the open-source ecosystem and cybersecurity practices.

Scientific Rigor, Source Quality, Title Accuracy

The scientific rigor is moderate. The guest is a credible practitioner, but the claims are not backed by formal citations or data. The sources mentioned are the project’s GitHub and official websites, which are appropriate for the topic. The title accurately reflects the content, focusing on BunkerWeb. The discussion is informative but not exhaustive, and it does not engage with academic literature or independent evaluations.

151 words

Title / Content Match

The title accurately reflects the content, which is a focused discussion on BunkerWeb.

Quality & Reliability

7/10

The interview features a practitioner with direct experience in developing and operating a WAF. Technical claims are plausible and consistent with known practices, but there is no independent verification or detailed technical evidence.

Key Moments

Cited Sources

Concurring Sources

Contribution & Novelties

The video provides an insider perspective on developing and commercializing an open-source WAF. It highlights the importance of balancing technical innovation with business viability. The discussion on telemetry and threat intelligence sharing is particularly relevant for modern security operations.

Pour aller plus loin :

80 words

Radar Profile

The radar profile shows balanced scores across information quantity, quality, technical level, and reliability, with a slight emphasis on practical experience over academic rigor. The video is a solid introduction to BunkerWeb and open-source WAFs, suitable for practitioners.

Reliability 7/10

💬 No comments were provided for analysis.