<?xml version="1.0" encoding="UTF-8"?><oembed><type>video</type><version>1.0</version><html>&lt;iframe src=&quot;https://www.loom.com/embed/0d1f3219338849c7ad4e71d3b8b3a23e&quot; frameborder=&quot;0&quot; width=&quot;1920&quot; height=&quot;1440&quot; webkitallowfullscreen mozallowfullscreen allowfullscreen&gt;&lt;/iframe&gt;</html><height>1440</height><width>1920</width><provider_name>Loom</provider_name><provider_url>https://www.loom.com</provider_url><thumbnail_height>1440</thumbnail_height><thumbnail_width>1920</thumbnail_width><thumbnail_url>https://cdn.loom.com/sessions/thumbnails/0d1f3219338849c7ad4e71d3b8b3a23e-8c5696370444e290.gif</thumbnail_url><duration>3950.478</duration><title>Web Application Security</title><description>This Loom introduces an end-to-end web application security lab using Azure Application Gateway with Web Application Firewall v2 in front of a deliberately vulnerable DVWA instance. The presenter sets expectations that it is not just a simple “turn on the firewall” exercise, emphasizing important design decisions such as how the vulnerable host is isolated and how the WAF policy is structured, including why signature-based filtering can fall short. The lab will demonstrate role-based attacks against the app and how the firewall blocks them. All resources and state are deployed using Terraform with a shared remote backend, as described in the repo layout.</description></oembed>