4 ms·
That WAF needs to be tuned. If they’re worried about the possibility of a local file read that can disclose /etc/shadow, there are much bigger issues.
by rtev 4y ago
That WAF needs to be tuned. If they’re worried about the possibility of a local file read that can disclose /etc/shadow, there are much bigger issues.
- thayne 4y agoOr it is defense in depth. Although blocking it even if the / is percent encoded seems a bit excessive, especially as a default.