Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Thoughts on Web Application Firewalls

Summary

Pushes back on the claim that WAFs beat fixing vulnerable code: filters can be bypassed, need lengthy tuning, and have their own flaws, so WAFs belong in defense-in-depth, not code substitution.
Published
Collected

original ↗