6 ms·
The challenge of a WAF is it has no context of the application behind it. It doesn't really know what "good" input is for a specific application, so instead it
by billyhoffman 6y ago
The challenge of a WAF is it has no context of the application behind it. It doesn't really know what "good" input is for a specific application, so instead it tried to block "bad" things with a blacklist.
If the WAF ships with too strict of a blacklist, legit input gets block (All the people named "O'Brian" that can't use a web app...) If an attacker can make an attack look close enough to pass the blacklist, they win. In this example, the attacker had to remove whitespace, remove a math operation sign (=), and send english letters with a few special characters that could be in normal text (quote, forward slash, asterisk).
WAFs will never catch everything, and if they are advertised as such, that is snake oil. But WAFs can help by providing a ready made blacklist that can supplement input validation inside the app, which does have context about what valid input should look like.
- gskourou 6y agoI have also seen backend application which strip out certain "bad" tags (i.e. <script>). I remember being able to perform an XSS attack by sending a payload that looked like: <sc<script>ript>alert(/XSS/)</sc<script>ript> This passed the WAF inspection, but then got trimmed by the backend application and this is what was left: <script>alert(/XSS/)</script> written in the page source. Maybe I'll write about that case too if I find where I put the attack evidence. You can anyway see that bad validation by the actual application programmers can disable the WAF's capabilities.
- colejohnson66 6y agoIsn’t the correct solution to replace '<' and '>' with '<' and '>'?
- krapp 6y agoYeah, escaping entities when rendering, using prepared statements in the database. It's not rocket science.
- gskourou 6y agoamen
- tannhaeuser 6y agoOr, you know, using ordinary SGML validation which has the capability to block disallowed elements since 1986.
- yyyk 6y agoThe correct solution is to apply Content-Security-Policy plus character escaping as needed.