Re: Protection for new WAF bypass for SQL injection json based payload
homesh joshi <[email protected]> Wed, 14 Dec 2022 08:32:18 +0530
| Newsgroups | gmane.comp.apache.mod-security.user |
|---|---|
| Message-ID | <CAAjxK7sk+aCAg6Ryv5nA-X=V4mS83pNGFmJUtebQNHhJ+SKygQ@mail.gmail.com> |
--===============0058985452543296931== Content-Type: multipart/alternative; boundary="000000000000a41b7605efc0f7d3" --000000000000a41b7605efc0f7d3 Content-Type: text/plain; charset="UTF-8" Thank you Christian. On Wed, 14 Dec, 2022, 3:46 am Christian Folini, <[email protected]> wrote: > Hi there, > > We looked at it from a CRS perspective. > > Detection is spotty at paranoia level 1, but CRS detects all the payloads > at PL2. There is pull request that aims to detect everything at PL1. > > https://github.com/coreruleset/coreruleset/pull/3055 > > Best, > > Christian > > On Tue, Dec 13, 2022 at 09:30:21PM +0530, homesh joshi wrote: > > Hi All, > > > > Has any one tested the new method mentioned here > > > https://claroty.com/team82/research/js-on-security-off-abusing-json-based-sql-to-bypass-waf > > > > > > any successfully block the same with modsec ? > > > > Thanks, > > Homesh > > > > _______________________________________________ > > mod-security-users mailing list > > [email protected] > > https://lists.sourceforge.net/lists/listinfo/mod-security-users > > Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs: > > http://www.modsecurity.org/projects/commercial/rules/ > > http://www.modsecurity.org/projects/commercial/support/ > > > > _______________________________________________ > mod-security-users mailing list > [email protected] > https://lists.sourceforge.net/lists/listinfo/mod-security-users > Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs: > http://www.modsecurity.org/projects/commercial/rules/ > http://www.modsecurity.org/projects/commercial/support/ > --000000000000a41b7605efc0f7d3 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"auto">Thank you Christian.</div><br><div class=3D"gmail_quote">= <div dir=3D"ltr" class=3D"gmail_attr">On Wed, 14 Dec, 2022, 3:46 am Christi= an Folini, <<a href=3D"mailto:[email protected]">christian.fol= [email protected]</a>> wrote:<br></div><blockquote class=3D"gmail_quote" st= yle=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Hi th= ere,<br> <br> We looked at it from a CRS perspective.<br> <br> Detection is spotty at paranoia level 1, but CRS detects all the payloads<b= r> at PL2. There is pull request that aims to detect everything at PL1.<br> <br> <a href=3D"https://github.com/coreruleset/coreruleset/pull/3055" rel=3D"nor= eferrer noreferrer" target=3D"_blank">https://github.com/coreruleset/coreru= leset/pull/3055</a><br> <br> Best,<br> <br> Christian<br> <br> On Tue, Dec 13, 2022 at 09:30:21PM +0530, homesh joshi wrote:<br> > Hi All,<br> > <br> > Has any one tested the new method mentioned here<br> > <a href=3D"https://claroty.com/team82/research/js-on-security-off-abus= ing-json-based-sql-to-bypass-waf" rel=3D"noreferrer noreferrer" target=3D"_= blank">https://claroty.com/team82/research/js-on-security-off-abusing-json-= based-sql-to-bypass-waf</a><br> > <br> > <br> > any successfully block the same with modsec ?<br> > <br> > Thanks,<br> > Homesh<br> <br> <br> > _______________________________________________<br> > mod-security-users mailing list<br> > <a href=3D"mailto:[email protected]" target=3D"= _blank" rel=3D"noreferrer">[email protected]</a><br> > <a href=3D"https://lists.sourceforge.net/lists/listinfo/mod-security-u= sers" rel=3D"noreferrer noreferrer" target=3D"_blank">https://lists.sourcef= orge.net/lists/listinfo/mod-security-users</a><br> > Commercial ModSecurity Rules and Support from Trustwave's SpiderLa= bs:<br> > <a href=3D"http://www.modsecurity.org/projects/commercial/rules/" rel= =3D"noreferrer noreferrer" target=3D"_blank">http://www.modsecurity.org/pro= jects/commercial/rules/</a><br> > <a href=3D"http://www.modsecurity.org/projects/commercial/support/" re= l=3D"noreferrer noreferrer" target=3D"_blank">http://www.modsecurity.org/pr= ojects/commercial/support/</a><br> <br> <br> <br> _______________________________________________<br> mod-security-users mailing list<br> <a href=3D"mailto:[email protected]" target=3D"_blan= k" rel=3D"noreferrer">[email protected]</a><br> <a href=3D"https://lists.sourceforge.net/lists/listinfo/mod-security-users"= rel=3D"noreferrer noreferrer" target=3D"_blank">https://lists.sourceforge.= net/lists/listinfo/mod-security-users</a><br> Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:<b= r> <a href=3D"http://www.modsecurity.org/projects/commercial/rules/" rel=3D"no= referrer noreferrer" target=3D"_blank">http://www.modsecurity.org/projects/= commercial/rules/</a><br> <a href=3D"http://www.modsecurity.org/projects/commercial/support/" rel=3D"= noreferrer noreferrer" target=3D"_blank">http://www.modsecurity.org/project= s/commercial/support/</a><br> </blockquote></div> --000000000000a41b7605efc0f7d3-- --===============0058985452543296931== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline --===============0058985452543296931== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ mod-security-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/mod-security-users Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs: http://www.modsecurity.org/projects/commercial/rules/ http://www.modsecurity.org/projects/commercial/support/ --===============0058985452543296931==--