CPGuard WAF คืออะไร วิธีป้องกันเว็บจากการโจมตีทุกรูปแบบ
Web Application Firewall ของ CPGuard ป้องกันเว็บจากการโจมตีได้อย่างไร และทำไมถึงสำคัญกว่า Plugin WordPress
สารบัญ
WAF คืออะไร และ CPGuard WAF ทำงานอย่างไร
Web Application Firewall (WAF) คือระบบที่คอยตรวจสอบและกรอง HTTP/HTTPS Request ทุกอันก่อนที่จะถึง PHP หรือ Database ของเว็บ CPGuard WAF ทำงานที่ระดับ Server ซึ่งหมายความว่าป้องกันได้แม้โค้ดของเว็บจะมีช่องโหว่อยู่ โดยใช้ Rule Set ที่อ้างอิง OWASP Top 10 — รายการความเสี่ยงหลักของ Web Application ที่ใช้เป็นมาตรฐานสากล
A Web Application Firewall inspects every HTTP/HTTPS request before it reaches PHP or the database. CPGuard WAF operates at the server level — meaning it protects websites even when application code contains vulnerabilities — using a rule set aligned with OWASP Top 10, the international standard for web application security risks.
- ตรวจทุก Request ก่อนถึง PHP และ Database
- ป้องกันได้แม้โค้ดภายในมีช่องโหว่
- Rule อิง OWASP Top 10 มาตรฐานสากล
- อัปเดต Rule อัตโนมัติตามภัยคุกคามใหม่
- ทำงานร่วมกับ Malware Scanner และ Firewall ของ CPGuard
บล็อก SQL Injection
SQL Injection คือการโจมตีที่ผู้ไม่หวังดีแทรก SQL Command เข้าไปใน Input ของเว็บเพื่อดึงหรือแก้ไขข้อมูลใน Database โดยตรง เป็นหนึ่งในการโจมตีที่พบบ่อยที่สุดในโลก CPGuard WAF ตรวจจับ Pattern ของ SQL Injection และบล็อก Request นั้นก่อนที่จะถึง Database ทำให้แม้เว็บที่ใช้ PHP เก่าและไม่ได้ Sanitize Input ก็ยังปลอดภัยจากภัยนี้ได้
SQL Injection inserts SQL commands into web inputs to directly extract or modify database data — one of the most common web attacks. CPGuard WAF detects SQL Injection patterns and blocks those requests before they reach the database, protecting even older PHP sites that do not properly sanitise user input.
- ตรวจ Pattern เช่น
OR 1=1,UNION SELECT,DROP TABLE - บล็อก Blind SQL Injection ที่ตรวจยากกว่า
- ป้องกัน WordPress + Plugin ที่มีช่องโหว่ SQL
- Log การโจมตีทุกครั้งสำหรับการตรวจสอบ
บล็อก Cross-Site Scripting (XSS)
XSS คือการฝัง Script อันตรายลงในหน้าเว็บผ่าน Input ที่ไม่ได้ Sanitize เมื่อผู้ใช้คนอื่นเปิดหน้านั้น Script จะรันในเบราว์เซอร์ของเหยื่อ ทำให้แฮ็กเกอร์ขโมย Session Cookie, Redirect ไปยังเว็บอันตราย หรือแสดงหน้า Phishing ปลอม CPGuard WAF ตรวจจับ XSS Pattern ทั้ง Reflected XSS, Stored XSS และ DOM-based XSS ก่อนที่ Script จะถูกบันทึกหรือ Execute
XSS embeds malicious scripts in web pages via unsanitised inputs; when other users load the page, the script executes in their browser — enabling session cookie theft, malicious redirects, or phishing overlays. CPGuard WAF detects Reflected, Stored, and DOM-based XSS patterns before scripts are stored or executed.
- ตรวจ
<script>Tags และ Event Handler ใน Input - บล็อก JavaScript Protocol ที่แฝงใน URL หรือ Attribute
- ป้องกัน Stored XSS ก่อนบันทึกลง Database
- ลด False Positive ด้วย Whitelist Mode
บล็อก RFI และ LFI
Remote File Inclusion (RFI) และ Local File Inclusion (LFI) คือการโจมตีที่หลอกให้ PHP โหลดไฟล์จากแหล่งภายนอก (RFI) หรือจากระบบไฟล์ที่ไม่ควรเข้าถึงได้ (LFI) เช่น /etc/passwd หรือไฟล์ Config ของระบบ CPGuard WAF ตรวจจับ Parameter ที่มี Path Traversal Pattern หรือ URL ภายนอกและบล็อกก่อนที่ PHP จะประมวลผล
RFI tricks PHP into loading files from external sources; LFI accesses local system files that should be inaccessible, such as /etc/passwd or system configuration files. CPGuard WAF detects path traversal patterns and external URL parameters, blocking them before PHP processes the request.
- ตรวจจับ
../Path Traversal ใน URL Parameter - บล็อก
http://และftp://ใน Include Path - ป้องกันการอ่าน /etc/passwd, wp-config.php ผ่าน LFI
- หยุด Shell Upload ผ่าน RFI
Brute Force Protection
นอกจาก WAF แล้ว CPGuard มีโมดูล Brute Force Protection ที่นับจำนวนครั้งที่ IP ใดๆ พยายาม Login ผิดซ้ำๆ เมื่อถึงเกณฑ์ที่ตั้งไว้ ระบบจะ Block IP นั้นอัตโนมัติเป็นระยะเวลาที่กำหนด ครอบคลุมทั้ง WordPress wp-login.php, DirectAdmin Login, FTP, SSH และ Email Login
Beyond WAF, CPGuard includes Brute Force Protection that counts repeated failed login attempts from any IP. When a configurable threshold is hit, the IP is automatically blocked for a set duration. Coverage includes WordPress wp-login.php, DirectAdmin, FTP, SSH, and email login.
- นับ Failed Login และ Block IP อัตโนมัติ
- ครอบคลุม WordPress, DirectAdmin, FTP, SSH, Email
- ตั้ง Threshold และ Block Duration ได้
- Whitelist IP ที่เชื่อถือได้เพื่อป้องกัน False Positive
- แจ้งเตือน Admin เมื่อตรวจพบการโจมตี Brute Force
การอัปเดต Rule อัตโนมัติ
ภัยคุกคามเว็บพัฒนาอยู่ตลอดเวลา Rule WAF ที่ไม่อัปเดตจะตามไม่ทันการโจมตีใหม่ CPGuard ออกแบบให้อัปเดต Rule อัตโนมัติจากฐานข้อมูลกลาง ทำให้ WAF ครอบคลุมช่องโหว่ใหม่ที่เพิ่งถูกค้นพบโดยไม่ต้องให้ Server Admin ทำเอง ลดภาระการ Maintain ระบบอย่างมาก
Web threats evolve constantly — WAF rules that are not updated quickly fall behind new attack techniques. CPGuard is designed to automatically update rules from a central database, keeping WAF coverage current against newly discovered vulnerabilities without requiring server administrator intervention.
- อัปเดต Rule อัตโนมัติจากฐานข้อมูลกลาง
- ครอบคลุมช่องโหว่ใหม่ใน WordPress, Plugin, PHP
- ไม่ต้อง Manual Update โดย Admin
- ระบบ Rollback ถ้า Rule ใหม่สร้าง False Positive มากเกิน
Whitelist และการตั้งค่า Exception
บางครั้ง WAF อาจบล็อก Request ที่ถูกต้องของเว็บ เช่น WooCommerce Checkout ที่มี Special Character หรือ API Endpoint ที่รับ JSON ที่มีโครงสร้างคล้าย Payload CPGuard รองรับการตั้งค่า Whitelist Rule สำหรับ URL หรือ Parameter ที่ต้องการให้ผ่านโดยไม่ตรวจสอบ ทำให้ทั้งความปลอดภัยและ Functionality ของเว็บอยู่ร่วมกันได้
WAF rules occasionally block legitimate web requests — for example, WooCommerce checkout fields containing special characters, or API endpoints receiving JSON that resembles an attack payload. CPGuard supports whitelist rules for specific URLs or parameters that should bypass WAF inspection, balancing security with application functionality.
- Whitelist URL เฉพาะ (เช่น /api/endpoint) ได้
- Whitelist Parameter เฉพาะบน Path ที่กำหนด
- IP Whitelist สำหรับ Trusted Source
- ทดสอบ Rule ใหม่ใน Log-only Mode ก่อน Enforce จริง
เลือก Hosting ที่มี WAF ระดับ Server
การมี WAF ระดับ Server ต่างจากการใช้แค่ Plugin รักษาความปลอดภัยใน WordPress ตรงที่ทำงานก่อน PHP จะ Load ทำให้หยุดการโจมตีได้เร็วกว่าและไม่กระทบ Performance AsiaGB.com ให้บริการ Hosting และ VPS ที่มีระบบรักษาความปลอดภัยระดับ Server พร้อม SSD Storage, DirectAdmin, Support ภาษาไทย 24 ชั่วโมง และ uptime 99%
Server-level WAF differs from WordPress security plugins in that it operates before PHP loads — stopping attacks faster and without performance impact on the application. AsiaGB.com provides hosting and VPS with server-level security, SSD storage, DirectAdmin, 24-hour Thai support, and 99% uptime.
- WAF ระดับ Server หยุดการโจมตีก่อน PHP Load
- ไม่กินทรัพยากร PHP ไม่เหมือน Plugin ใน WordPress
- ป้องกันทุก App บน Server พร้อมกัน ไม่ใช่แค่ WordPress
- ถาม Provider ว่ามี WAF ระดับ Server ก่อนสมัคร