Web Hack List

Collected research

Back in Black: Towards Formal, Black Box Analysis of Sanitizers and Filters

Infers a black-box WAF filter or sanitizer from queries alone, using symbolic finite automata to cut the query count about 15 times. Feeding it a grammar of attack strings turns a failed equivalence check into a real bypass, finding SQL injection bypasses in ModSecurity, PHPIDS, WebKnight, WebCastellum and urlscan.

Record

Researcher
George Argyros, Ioannis Stais, Aggelos Kiayias and Angelos D. Keromytis
Published by
ieee-security.org
Format
Whitepaper
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of George Argyros, Ioannis Stais, Aggelos Kiayias and Angelos D. Keromytis, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .