Subscribe to RSS - Signatures

Signatures

New WAF bypass method take advantage of comment anti-evasion

Submitted by Ofer Shezaf on 3 November 2009 - 6:07pm
Share/Save

A new blog post by Dmitry Evteev shows how an obscure MySQL syntax can be used to bypass ModSecurity signatures. The interesting thing is that the new technique actually takes advantage of a ModSecurity anti-evasion measure. ModSecurity rule set ignore MySQL comments in order to detect attacks that is split using a comment: