3 ms·
Yes. Needing any of these to secure your application means the app code is broken. Every WAF I've used breaks URL's randomly because they're just pattern match
by nullwasamistake 7y ago
Yes. Needing any of these to secure your application means the app code is broken.
Every WAF I've used breaks URL's randomly because they're just pattern matching against known attacks to a definitely broken system.
Any properly engineered system is invulnerable to all attacks a WAF would catch at the HTTP level
- cwojno 7y agoI also suspect this to be the case. However, the reason you get a WAF is because you either want a security blanket or don't have the resources to implement the service in a "good" or... even: "decent" language ;).