Linux Today: Linux News On Internet Time.





More on LinuxToday


Vulnerabilities in open source WAF ModSecurity

Jun 19, 2012, 05:00 (0 Talkback[s])
(Other stories by Ivan Ristic)

During our research of web application firewall evasion issues, we uncovered a flaw in ModSecurity that may lead to complete bypass of the installed rules, in the cases when ModSecurity is deployed to protect the backends where impedance mismatch is not mitigated. Additionally, a separate flaw in ModSecurity CRS makes the content type checks ineffective, allowing for bypass attacks, when deployed to protect the backends where impedance mismatch is not mitigated.

Complete Story

Related Stories: