Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Hacker News: New Attack Method to Bypass Popular Web Application Firewalls

Has anyone run into this?

https://thehackernews.com/2022/12/researchers-detail-new-attack-method-to.html?_m=3n%2e009a%2e2910%2eqq0ao0edmj%2e1vo3

Cheers - Bob



This thread was automatically locked due to age.
Parents Reply Children
  • In my experience, I have come across a lot of WAFs. Some of them are very strong, others are very weak. Yes, sometimes they do manage to successfully prevent XSS or SQL injection, but I have never evaluated a WebApp where a WAF managed to successfully mitigate all the vulnerabilities I discovered, let alone the majority of the OWASP top 10.

    A WAF should be viewed as an additional security measure rather than a comprehensive response to security threats.