Collected research
Response Filter Denial of Service (RFDoS): shut down a website by triggering WAF rule
WAF response-body rules meant to stop SQL error and web shell leakage match plain strings with no special characters: ORA-1234, Dynamic SQL Error, OracleDriver, ---ASL-CONFIG-FILE---. Storing one in a review, username or email makes the WAF 403 that page for every visitor, a denial of service no sanitiser catches. A scan of WordPress ?s= reflection found 0.4-1.5% of 200,000 sites per ccTLD affected, and a byte-range request still retrieves what the rules block.
Record
- Researcher
- @AndreaTheMiddle and Andrea Menin
- Published by
- Sicuranext Blog
- Date
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of @AndreaTheMiddle and Andrea Menin, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .