Re: Bypassing WAF via HTTP Pollution

Ivan Ristic <[email protected]> Thu, 4 Oct 2012 10:40:14 +0100
Newsgroups gmane.comp.security.websecurity,gmane.comp.security.web-applications,gmane.comp.security.penetration
Message-ID <CANHgQ8Ew9jPNtK6X+crDmvpaZyq2kkYAe1rj_Ym2hm5zL1b_ZQ@mail.gmail.com>
I guess this would be a good opportunity for me to mention my research
on the topic:

Protocol-level evasion of web application firewalls
http://blog.ivanristic.com/2012/07/protocol-level-evasion-of-web-application-firewalls.html


On Wed, Oct 3, 2012 at 10:55 AM, Danux <[email protected]> wrote:
> By playing CSAW CTF you always learn something new (at least myself).
>
> Hope you enjoy it:
>
> http://danuxx.blogspot.com/2012/10/bypassing-waf-via-http-parameter.html
>
> --
> DanUx
>
> _______________________________________________
> The Web Security Mailing List
>
> WebSecurity RSS Feed
> http://www.webappsec.org/rss/websecurity.rss
>
> Join WASC on LinkedIn http://www.linkedin.com/e/gis/83336/4B20E4374DBA
>
> WASC on Twitter
> http://twitter.com/wascupdates
>
> [email protected]
> http://lists.webappsec.org/mailman/listinfo/websecurity_lists.webappsec.org



-- 
Ivan Ristić

_______________________________________________
The Web Security Mailing List

WebSecurity RSS Feed
http://www.webappsec.org/rss/websecurity.rss

Join WASC on LinkedIn http://www.linkedin.com/e/gis/83336/4B20E4374DBA

WASC on Twitter
http://twitter.com/wascupdates

[email protected]
http://lists.webappsec.org/mailman/listinfo/websecurity_lists.webappsec.org