#WAFs

Inautiloinautilo
2026-02-10
Kevin Karhan :verified:kkarhan@infosec.space
2024-06-19

@fennix personally, I think that #WAFs are a scam on-par with 3rd party #Antivirus on #Windows and #Mobile OSes like #Android akd #iOS!

2024-06-18

Defeat all #WAFs with this one simple trick!

Cloudflare/AWS/GCP/Azure hate him...

Append to all response bodies:

<script>zzzzzz=alert</script>

Change all xss detection payloads from
alert() to zzzzzz()

Laugh.

*Note: may require additional inclusion of nonce but don't worry everyone uses a CDN these days and their vetting process is terrible, except in cases where they have no vetting and they just straight hot load from github...

#infosec #pentest

Andrew Howexanadu@tech.lgbt
2023-02-15

Currently at #OWASP Global AppSec Dublin and having a great time! Come say hi if any fellow Mastodonians are also here 🥳 Let's talk #WAFs, #ModSecurity, OWASP Core Rule Set, and load balancing 😄

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst