Protection for new WAF bypass for SQL injection json based payload
homesh joshi <[email protected]> Tue, 13 Dec 2022 21:30:21 +0530
| Newsgroups | gmane.comp.apache.mod-security.user |
|---|---|
| Message-ID | <CAAjxK7ttFc6_2uJx8b92c=DN_jr+T+90D6NMhwVE0er10A2QTw@mail.gmail.com> |
--===============1144011403936745499== Content-Type: multipart/alternative; boundary="000000000000452df005efb7b897" --000000000000452df005efb7b897 Content-Type: text/plain; charset="UTF-8" Hi All, Has any one tested the new method mentioned here https://claroty.com/team82/research/js-on-security-off-abusing-json-based-sql-to-bypass-waf any successfully block the same with modsec ? Thanks, Homesh --000000000000452df005efb7b897 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div>Hi All,</div><div><br></div><div>Has any one tested t= he new method mentioned here <a href=3D"https://claroty.com/team82/research= /js-on-security-off-abusing-json-based-sql-to-bypass-waf">https://claroty.c= om/team82/research/js-on-security-off-abusing-json-based-sql-to-bypass-waf = <br></a></div><div><br></div><div>any successfully block the same with mods= ec ?</div><div><br></div><div>Thanks,</div><div>Homesh<br></div><br></div> --000000000000452df005efb7b897-- --===============1144011403936745499== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline --===============1144011403936745499== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ mod-security-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/mod-security-users Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs: http://www.modsecurity.org/projects/commercial/rules/ http://www.modsecurity.org/projects/commercial/support/ --===============1144011403936745499==--