[prev in list] [next in list] [prev in thread] [next in thread] 

List:       full-disclosure
Subject:    [FD] Web Application Firewall bypass - part 3
From:       Red Timmy Security <publications () redtimmy ! com>
Date:       2020-06-07 18:16:46
Message-ID: d64931940350525669659a991ee4ca61 () redtimmy ! com
[Download RAW message or body]

Hi
we have published the part 3 of "How to hack a company by circumventing 
its WAF for fun and profit". We basically show how the usage of a single 
character can be abused to skip common checks performed at layer 7 by 
network devices and security appliances.

Also another case where F5 Big-IP WAF is bypassed by means of SSRF is 
shown.

Full story here:
https://www.redtimmy.com/web-application-hacking/how-to-hack-a-company-by-circumventing-its-waf-for-fun-and-profit-part-3/


Regards
RedTimmy Security

_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: http://seclists.org/fulldisclosure/


[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic