Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

In WAF we (should not) trust

Summary

Quarkslab deep-dives WAF bypasses: how blacklists, penalty boxes, rate limiting and parsing discrepancies between a WAF and its backend can be abused to sneak malicious payloads through.
Published
Collected

original ↗

Related coverage

back