3 ms·
I don't think so. This rule for example probably block attacks on a dozen old WordPress vulnerabilities.
by schnable 1y ago
I don't think so. This rule for example probably block attacks on a dozen old WordPress vulnerabilities.
- kiitos 1y agoAnd a rule that denies everything blocks all vulnerabilities entirely. A false positive from a conservative evaluation of a query parameter or header value is one thing, conceivably understandable. A false positive due to the content of a blog post is something else altogether.
- afiori 1y agoThis is a strawman, especially if like the parent claims this was improving security for one of the most popular website backends ever. Rules like this might very well have had incredible positive impact on ten of thousands of websites at the cost of some weird debugging sessions for dozens of programmers (made up numbers obviously).
- kiitos 1y agoLook, any WAF that blocks a document like <!DOCTYPE html> <html lang="en"> <body> <p>/etc/hosts is a file on Unix hosts</p> is pretty clearly broken. And you can't meaningfully measure product metrics like impact for fundamentally broken products.
- afiori 1y ago> is pretty clearly broken agree > And you can't meaningfully measure product metrics like impact for fundamentally broken products disagree
- kiitos 1y agoI have a WAF that blocks everything. It's obviously fundamentally broken, but in terms of product metrics like impact, it's incredible! It stops 100% of attacks!