Re: Protection for new WAF bypass for SQL injection json based payload
Christian Folini <[email protected]> Tue, 13 Dec 2022 23:11:03 +0100
| Newsgroups | gmane.comp.apache.mod-security.user |
|---|---|
| Message-ID | <20221213221103.GC44628@leander> |
Hi there, We looked at it from a CRS perspective. Detection is spotty at paranoia level 1, but CRS detects all the payloads at PL2. There is pull request that aims to detect everything at PL1. https://github.com/coreruleset/coreruleset/pull/3055 Best, Christian On Tue, Dec 13, 2022 at 09:30:21PM +0530, homesh joshi wrote: > Hi All, > > Has any one tested the new method mentioned here > https://claroty.com/team82/research/js-on-security-off-abusing-json-based-sql-to-bypass-waf > > > any successfully block the same with modsec ? > > Thanks, > Homesh > _______________________________________________ > mod-security-users mailing list > [email protected] > https://lists.sourceforge.net/lists/listinfo/mod-security-users > Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs: > http://www.modsecurity.org/projects/commercial/rules/ > http://www.modsecurity.org/projects/commercial/support/ _______________________________________________ mod-security-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/mod-security-users Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs: http://www.modsecurity.org/projects/commercial/rules/ http://www.modsecurity.org/projects/commercial/support/