Thoughts on Web Application Firewalls
netspi.com | blog | #secure-coding | #sql-injection | #waf | #application-security | #defense-in-depth
Summary
Pushes back on the claim that WAFs beat fixing vulnerable code: filters can be bypassed, need lengthy tuning, and have their own flaws, so WAFs belong in defense-in-depth, not code substitution.
- Published
- Collected
Skip to content