Quantcast
Channel: Soroush Dalili (@irsdl) Blog
Viewing all articles
Browse latest Browse all 21

x-up-devcap-post-charset Header in ASP.NET to Bypass WAFs Again!

$
0
0
In the past, I showed how the request encoding technique can be abused to bypass web application firewalls (WAFs). The generic WAF solution to stop this technique has been implemented by only allowing whitelisted charset via the Content-Type header or by blocking certain encoding charsets. Although WAF protection mechanisms can normally be bypassed by changing […]

Viewing all articles
Browse latest Browse all 21

Trending Articles