Web Hack List

Collected research

Response Filter Denial of Service (RFDoS): shut down a website by triggering WAF rule

WAF response-body rules meant to stop SQL error and web shell leakage match plain strings with no special characters: ORA-1234, Dynamic SQL Error, OracleDriver, ---ASL-CONFIG-FILE---. Storing one in a review, username or email makes the WAF 403 that page for every visitor, a denial of service no sanitiser catches. A scan of WordPress ?s= reflection found 0.4-1.5% of 200,000 sites per ccTLD affected, and a byte-range request still retrieves what the rules block.

Record

Researcher
@AndreaTheMiddle and Andrea Menin
Published by
Sicuranext Blog
Date
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of @AndreaTheMiddle and Andrea Menin, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .