Protection for new WAF bypass for SQL injection json based payload

homesh joshi <[email protected]> Tue, 13 Dec 2022 21:30:21 +0530
Newsgroups gmane.comp.apache.mod-security.user
Message-ID <CAAjxK7ttFc6_2uJx8b92c=DN_jr+T+90D6NMhwVE0er10A2QTw@mail.gmail.com>
--===============1144011403936745499==
Content-Type: multipart/alternative; boundary="000000000000452df005efb7b897"

--000000000000452df005efb7b897
Content-Type: text/plain; charset="UTF-8"

Hi All,

Has any one tested the new method mentioned here
https://claroty.com/team82/research/js-on-security-off-abusing-json-based-sql-to-bypass-waf


any successfully block the same with modsec ?

Thanks,
Homesh

--000000000000452df005efb7b897
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div>Hi All,</div><div><br></div><div>Has any one tested t=
he new method mentioned here <a href=3D"https://claroty.com/team82/research=
/js-on-security-off-abusing-json-based-sql-to-bypass-waf">https://claroty.c=
om/team82/research/js-on-security-off-abusing-json-based-sql-to-bypass-waf =
<br></a></div><div><br></div><div>any successfully block the same with mods=
ec ?</div><div><br></div><div>Thanks,</div><div>Homesh<br></div><br></div>

--000000000000452df005efb7b897--


--===============1144011403936745499==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline


--===============1144011403936745499==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
mod-security-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
http://www.modsecurity.org/projects/commercial/rules/
http://www.modsecurity.org/projects/commercial/support/

--===============1144011403936745499==--