Re: Protection for new WAF bypass for SQL injection json based payload

Christian Folini <[email protected]> Tue, 13 Dec 2022 23:11:03 +0100
Newsgroups gmane.comp.apache.mod-security.user
Message-ID <20221213221103.GC44628@leander>
Hi there,

We looked at it from a CRS perspective.

Detection is spotty at paranoia level 1, but CRS detects all the payloads
at PL2. There is pull request that aims to detect everything at PL1.

https://github.com/coreruleset/coreruleset/pull/3055

Best,

Christian

On Tue, Dec 13, 2022 at 09:30:21PM +0530, homesh joshi wrote:
> Hi All,
> 
> Has any one tested the new method mentioned here
> https://claroty.com/team82/research/js-on-security-off-abusing-json-based-sql-to-bypass-waf
> 
> 
> any successfully block the same with modsec ?
> 
> Thanks,
> Homesh


> _______________________________________________
> mod-security-users mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/mod-security-users
> Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
> http://www.modsecurity.org/projects/commercial/rules/
> http://www.modsecurity.org/projects/commercial/support/



_______________________________________________
mod-security-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
http://www.modsecurity.org/projects/commercial/rules/
http://www.modsecurity.org/projects/commercial/support/