Secured by OVHcloud WAF (OWAF)

This site sits behind OVHcloud’s Web Application Firewall

waf.success.ovh is a demo origin. OWAF inspects traffic with OWASP CRS before anything reaches this nginx backend — try a payload, or see how the path works.

Abstract teal shield protecting application infrastructure
OWASP CRS 4.x · Inline · European infrastructure

Start here

Three paths — skip the brochure and go straight to the lab.

Test it!

Submit SQLi, XSS, and other samples. In Blocking mode you should get 403 before origin.

Open the lab

How it works

Follow a request from DNS through OWAF CRS to this nginx container.

See the path

Threats

What CRS is aimed at on this demo — with deep links into matching Test it! sections.

Browse threats

Ready to probe the WAF?

Use the guided forms on Test it! — then confirm matches in the WAF Console.