Re: Protection for new WAF bypass for SQL injection json based payload

homesh joshi <[email protected]> Wed, 14 Dec 2022 08:32:18 +0530
Newsgroups gmane.comp.apache.mod-security.user
Message-ID <CAAjxK7sk+aCAg6Ryv5nA-X=V4mS83pNGFmJUtebQNHhJ+SKygQ@mail.gmail.com>
--===============0058985452543296931==
Content-Type: multipart/alternative; boundary="000000000000a41b7605efc0f7d3"

--000000000000a41b7605efc0f7d3
Content-Type: text/plain; charset="UTF-8"

Thank you Christian.

On Wed, 14 Dec, 2022, 3:46 am Christian Folini, <[email protected]>
wrote:

> Hi there,
>
> We looked at it from a CRS perspective.
>
> Detection is spotty at paranoia level 1, but CRS detects all the payloads
> at PL2. There is pull request that aims to detect everything at PL1.
>
> https://github.com/coreruleset/coreruleset/pull/3055
>
> Best,
>
> Christian
>
> On Tue, Dec 13, 2022 at 09:30:21PM +0530, homesh joshi wrote:
> > Hi All,
> >
> > Has any one tested the new method mentioned here
> >
> https://claroty.com/team82/research/js-on-security-off-abusing-json-based-sql-to-bypass-waf
> >
> >
> > any successfully block the same with modsec ?
> >
> > Thanks,
> > Homesh
>
>
> > _______________________________________________
> > mod-security-users mailing list
> > [email protected]
> > https://lists.sourceforge.net/lists/listinfo/mod-security-users
> > Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
> > http://www.modsecurity.org/projects/commercial/rules/
> > http://www.modsecurity.org/projects/commercial/support/
>
>
>
> _______________________________________________
> mod-security-users mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/mod-security-users
> Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
> http://www.modsecurity.org/projects/commercial/rules/
> http://www.modsecurity.org/projects/commercial/support/
>

--000000000000a41b7605efc0f7d3
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"auto">Thank you Christian.</div><br><div class=3D"gmail_quote">=
<div dir=3D"ltr" class=3D"gmail_attr">On Wed, 14 Dec, 2022, 3:46 am Christi=
an Folini, &lt;<a href=3D"mailto:[email protected]">christian.fol=
[email protected]</a>&gt; wrote:<br></div><blockquote class=3D"gmail_quote" st=
yle=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Hi th=
ere,<br>
<br>
We looked at it from a CRS perspective.<br>
<br>
Detection is spotty at paranoia level 1, but CRS detects all the payloads<b=
r>
at PL2. There is pull request that aims to detect everything at PL1.<br>
<br>
<a href=3D"https://github.com/coreruleset/coreruleset/pull/3055" rel=3D"nor=
eferrer noreferrer" target=3D"_blank">https://github.com/coreruleset/coreru=
leset/pull/3055</a><br>
<br>
Best,<br>
<br>
Christian<br>
<br>
On Tue, Dec 13, 2022 at 09:30:21PM +0530, homesh joshi wrote:<br>
&gt; Hi All,<br>
&gt; <br>
&gt; Has any one tested the new method mentioned here<br>
&gt; <a href=3D"https://claroty.com/team82/research/js-on-security-off-abus=
ing-json-based-sql-to-bypass-waf" rel=3D"noreferrer noreferrer" target=3D"_=
blank">https://claroty.com/team82/research/js-on-security-off-abusing-json-=
based-sql-to-bypass-waf</a><br>
&gt; <br>
&gt; <br>
&gt; any successfully block the same with modsec ?<br>
&gt; <br>
&gt; Thanks,<br>
&gt; Homesh<br>
<br>
<br>
&gt; _______________________________________________<br>
&gt; mod-security-users mailing list<br>
&gt; <a href=3D"mailto:[email protected]" target=3D"=
_blank" rel=3D"noreferrer">[email protected]</a><br>
&gt; <a href=3D"https://lists.sourceforge.net/lists/listinfo/mod-security-u=
sers" rel=3D"noreferrer noreferrer" target=3D"_blank">https://lists.sourcef=
orge.net/lists/listinfo/mod-security-users</a><br>
&gt; Commercial ModSecurity Rules and Support from Trustwave&#39;s SpiderLa=
bs:<br>
&gt; <a href=3D"http://www.modsecurity.org/projects/commercial/rules/" rel=
=3D"noreferrer noreferrer" target=3D"_blank">http://www.modsecurity.org/pro=
jects/commercial/rules/</a><br>
&gt; <a href=3D"http://www.modsecurity.org/projects/commercial/support/" re=
l=3D"noreferrer noreferrer" target=3D"_blank">http://www.modsecurity.org/pr=
ojects/commercial/support/</a><br>
<br>
<br>
<br>
_______________________________________________<br>
mod-security-users mailing list<br>
<a href=3D"mailto:[email protected]" target=3D"_blan=
k" rel=3D"noreferrer">[email protected]</a><br>
<a href=3D"https://lists.sourceforge.net/lists/listinfo/mod-security-users"=
 rel=3D"noreferrer noreferrer" target=3D"_blank">https://lists.sourceforge.=
net/lists/listinfo/mod-security-users</a><br>
Commercial ModSecurity Rules and Support from Trustwave&#39;s SpiderLabs:<b=
r>
<a href=3D"http://www.modsecurity.org/projects/commercial/rules/" rel=3D"no=
referrer noreferrer" target=3D"_blank">http://www.modsecurity.org/projects/=
commercial/rules/</a><br>
<a href=3D"http://www.modsecurity.org/projects/commercial/support/" rel=3D"=
noreferrer noreferrer" target=3D"_blank">http://www.modsecurity.org/project=
s/commercial/support/</a><br>
</blockquote></div>

--000000000000a41b7605efc0f7d3--


--===============0058985452543296931==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline


--===============0058985452543296931==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
mod-security-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
http://www.modsecurity.org/projects/commercial/rules/
http://www.modsecurity.org/projects/commercial/support/

--===============0058985452543296931==--