Web Application Security
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: Can HTTP Request Smuggling be blocked by Web Application Firewalls? Jun 22 2005 06:20AM
Andrew van der Stock (vanderaj greebo net)
Amit,

I feel that the WAF in this case would increase the likelihood of a
HTTP smuggling attack as it participates in the flow, and more than
likely interprets HTTP requests differently than pretty much
everything else out there. If they RST'd dodgy connections and left
alone all others, th...

[ more ]  
 

Privacy Statement
Copyright 2010, SecurityFocus