Collected research
WAFFle: Fingerprinting Filter Rules of Web Application Firewalls
WAFFle recovers a web application firewall's filter rules through a timing side channel: blocked and passed requests differ measurably even for transparent WAFs that alter no response. Driving it indirectly through CSRF hides the attacker and evades brute-force limits. Against ModSecurity and PHPIDS over the Internet it classified over 95% of requests from a single request.
Record
- Researcher
- Isabell Schmitt and Sebastian Schinzel
- Published by
- usenix.org
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Isabell Schmitt and Sebastian Schinzel, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .