Live data from Hacker News

Abusing the PHP Query String Parser to Bypass IDS, IPS, and WAF

secjuice.com

31–33 of 33 posts

Re: Abusing the PHP Query String Parser to Bypass IDS, IPS, and WAF

#31
post #25

Earlier quoted context omitted.

You can click on the timestamp of a comment and reply to it there so you don't have to @ people like a barbarian.

You can give the usability information about this website without calling a group of people barbarians.

I jokingly compared a single person to a barbarian without calling anyone a barbarian, like a barbarian.

Re: Abusing the PHP Query String Parser to Bypass IDS, IPS, and WAF

#32

Earlier quoted context omitted.

WAF has it's purpose but it's clearly not a silver bullet. Nothing is.

WAF is brittle and breaks more than it fixes IMO. It's just regex against URL's in 99% of cases. If you think you need one, you need to fix the app code, there will be more vulnerabilities it doesn't block

WAF provides a lot of other things, such as IP based filtering.

Re: Abusing the PHP Query String Parser to Bypass IDS, IPS, and WAF

#33
post #31

Earlier quoted context omitted.

You can give the usability information about this website without calling a group of people barbarians.

I jokingly compared a single person to a barbarian without calling anyone a barbarian, like a barbarian.

Then again, we are in discussion regarding PHP, so someone's bound to point out we're a bunch of neanthardal barbarians just because of that. So it could have been just a kneejerk reaction.
Post reply on HN