Re: Detection evasion technique by invalid UTF-8 sequences

Frank Knobbe <[email protected]>
Newsgroups gmane.comp.security.ids
Message-ID <1238116317.9601.78.camel@localhost>
On Mon, 2009-03-23 at 11:44 +0900, [email protected] wrote:
[...]
> Detection by IDS/IPS/WAF(Web Application Firewall) is evaded by 
> inserting invalid UTF-8 sequences on the way of SQL keywords(select,
> union, declare and so on). 


I'm curious, which IDS/IPS/WAF products have you tested that were not
able to properly normalize the URL parameters?

Which products are affected? If the IDS/IPS/WAF products are able to
normalize the traffic properly, where is the problem?

-Frank



-- 
It is said that the Internet is a public utility. As such, it is best
compared to a sewer. A big, fat pipe with a bunch of crap sloshing
against your ports.
signature.asc (application/pgp-signature, 188 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.10 (FreeBSD)

iD8DBQBJzCfdpIc56HlJ1YARAsxYAJ9T4mSDnEk8tPLvvu6zz5WQrTD+zACePaVn
TzzlyuvdzOwxEEO2pR3EJ4M=
=h43d
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.