Videos

Published on January 25th, 2016 📆 | 3491 Views ⚑

0

50 Shades of WAF – Exemplified at Barracuda & Sucuri


iSpeech.org



At DeepSec 2015 Ashar Javed took a swing at web application firewalls (WAF): "This talk will present 50 (25*2) bypasses of Barracuda and Sucuri's WAF default signatures that deal with Cross-Site Scripting (XSS). 150,000 organizations worldwide including Fortune 1000 companies are using Barracuda while around 10,000 web applications are behind Sucuri's cloud-based WAF. The XSS bypasses we will present in this talk are also applicable to other WAFs. All bypasses were responsibly reported to the vendors and most of them were fixed. Further, we will show XSS in Barracuda's admin interface and in their web application. Finally, we will present one unfixed bypass of Barracuda and Sucuri and will see how quickly vendors will react to fix it, given it will make thousands of sites vulnerable."

Likes: 0

Viewed:

source





Tagged with:



Comments are closed.