In WAF we (should not) trust
blog.quarkslab.com | research | #appsec | #web-security | #command-obfuscation | #waf | #http | #pentest | #payload-obfuscation | #waf-bypass
Summary
Quarkslab deep-dives WAF bypasses: how blacklists, penalty boxes, rate limiting and parsing discrepancies between a WAF and its backend can be abused to sneak malicious payloads through.
- Published
- Collected
Skip to content