Live data from Hacker News

Wallarm (YC S16) Uses Incoming Hacker Attacks to Reveal Security Flaws

themacro.com

21–22 of 22 posts

Re: Wallarm (YC S16) Uses Incoming Hacker Attacks to Reveal Security Flaws

#21
post #20

Earlier quoted context omitted.

How do you intend to prevent false positives? As a power user, I am concerned about the possibility of widespread adoption of your product and/or others like it. I don't want my bank to ban me just because I use a browser extension to capture my own cookies from my own valid session and pipe them into a shell script I wrote to invoke curl to harvest my latest bank statement as a PDF and store it locally. Supposing th…

The main idea about Wallarm is to get inner knowledge of how the application works and how users use it. Based on this data, we craft dynamic rules for every single applications or API. The simplest example is what data transmitted in different parameters of the form field or API calls. For example, it's OK if someone put an SQL Injection payload at Stack-overflow site in the form writing a security-related article.…

So I can CSRF the bank site with a SQLi in the login form, and ban anybody who clicks my link?

Re: Wallarm (YC S16) Uses Incoming Hacker Attacks to Reveal Security Flaws

#22
post #20

Earlier quoted context omitted.

How do you intend to prevent false positives? As a power user, I am concerned about the possibility of widespread adoption of your product and/or others like it. I don't want my bank to ban me just because I use a browser extension to capture my own cookies from my own valid session and pipe them into a shell script I wrote to invoke curl to harvest my latest bank statement as a PDF and store it locally. Supposing th…

The main idea about Wallarm is to get inner knowledge of how the application works and how users use it. Based on this data, we craft dynamic rules for every single applications or API. The simplest example is what data transmitted in different parameters of the form field or API calls. For example, it's OK if someone put an SQL Injection payload at Stack-overflow site in the form writing a security-related article.…

[deleted]
Post reply on HN