3 ms·
Nothing is abused, nothing is bypassed. The article makes it sound like IDS/IPS&WAF are intended to do input validation so it fits the applications model of th
by founderling 7y ago
Nothing is abused, nothing is bypassed.
The article makes it sound like IDS/IPS&WAF are intended to do input validation so it fits the applications model of the data.
They are not.
They are intended to harden the whole stack a little bit against yet undiscovered vulnerabilities.
By the same logic, this "article" could claim that it is possible to abuse Pythons strip() function to bypass WAF rules because filtering for the user name "root" will not filter out " root" and many login systems do strip whitespace before processing the input.
This applies to any language. Here on HN I can log in as "founderling" or " founderling" just fine.
If you want to filter out something in WAF, you 1) have to do it right and 2) do not do it for input validation at all.
It has nothing to do with the language if you fail at 1 and or 2.