<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-732257695511948254.post3787314701620451515..comments</id><updated>2009-06-18T03:01:59.949-07:00</updated><category term='hpp'/><category term='virtualization'/><category term='java'/><category term='tool'/><category term='joomla'/><category term='confidence'/><category term='vmware'/><category term='snagg'/><category term='security'/><category term='blackfire'/><category term='mac os x'/><category term='tomcat'/><category term='hacking'/><category term='exploit acquisition program'/><category term='cloud'/><category term='bug bounty program'/><category term='sql injection'/><category term='vasto'/><category term='forensics'/><category term='oracle'/><category term='black hat'/><category term='iphone'/><category term='daath'/><category term='disclosure'/><category term='typo3'/><category term='owasp'/><category term='ikki'/><category term='xss'/><category term='syscan'/><category term='ms access'/><category term='exploit'/><category term='vulnerability acquisition program'/><title type='text'>Comments on Nibble Security: HPP and WAF</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://blog.nibblesec.org/feeds/3787314701620451515/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/732257695511948254/3787314701620451515/comments/default'/><link rel='alternate' type='text/html' href='http://blog.nibblesec.org/2009/06/hpp-and-wafs.html'/><author><name>Claudio Criscione</name><uri>http://www.blogger.com/profile/12202628660778574382</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>2</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-732257695511948254.post-7040918809116759350</id><published>2009-06-18T03:01:59.949-07:00</published><updated>2009-06-18T03:01:59.949-07:00</updated><title type='text'>We all know that whitelisting is not always possib...</title><content type='html'>We all know that whitelisting is not always possible due to time/money constraints, even if it’s the best way to protect our applications. Unfortunately, WAFs are very commonly used as out of the box solutions, using generic rules and blacklists. &lt;br /&gt;&lt;br /&gt;Anyway, I see your point and I frankly support the idea of providing multiple lines of defense.&lt;br /&gt;&lt;br /&gt;Cheers. Luca.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/732257695511948254/3787314701620451515/comments/default/7040918809116759350'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/732257695511948254/3787314701620451515/comments/default/7040918809116759350'/><link rel='alternate' type='text/html' href='http://blog.nibblesec.org/2009/06/hpp-and-wafs.html?showComment=1245319319949#c7040918809116759350' title=''/><author><name>Luca Carettoni</name><uri>http://www.blogger.com/profile/09957564681262364569</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://1.bp.blogspot.com/_5TMxqPSTp9k/SXnAA-dClZI/AAAAAAAAA1s/80j8Ko3ETb4/S220/lucacarettoni_small.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.nibblesec.org/2009/06/hpp-and-wafs.html' ref='tag:blogger.com,1999:blog-732257695511948254.post-3787314701620451515' source='http://www.blogger.com/feeds/732257695511948254/posts/default/3787314701620451515' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-871964520'/></entry><entry><id>tag:blogger.com,1999:blog-732257695511948254.post-4115996223185345057</id><published>2009-06-18T00:24:25.355-07:00</published><updated>2009-06-18T00:24:25.355-07:00</updated><title type='text'>As written in the whitepaper the best practice to ...</title><content type='html'>As written in the whitepaper the best practice to deliver protection from RFI attack is having 2 levels:&lt;br /&gt;* zero-day protection&lt;br /&gt;* positive security protection&lt;br /&gt;&lt;br /&gt;The zero-day protection rules can be bypassed by the HPP but the positive security protection contains rules that can detect the example that you gave in your blog.&lt;br /&gt;&lt;br /&gt;ModSecurity RFI positive security rule would say – if value in parameter “par” is not from allowed predefined values and value is URL - trigger RFI attack. &lt;br /&gt;&lt;br /&gt;e.g. ‘par’ allows 1-4 digits&lt;br /&gt;&lt;br /&gt;SecRule &amp;quot;ARGS:par&amp;quot; !^\d{1,4}$ &amp;quot;chain,t:urlDecodeUni,t:htmlEntityDecode,t:lowercase,deny,phase:2,msg:&amp;#39;Remote File Inclusion&amp;#39; &amp;quot;&lt;br /&gt;SecRule &amp;quot;ARGS:par&amp;quot; (ht|f)tps?://&lt;br /&gt;&lt;br /&gt;Or Katz</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/732257695511948254/3787314701620451515/comments/default/4115996223185345057'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/732257695511948254/3787314701620451515/comments/default/4115996223185345057'/><link rel='alternate' type='text/html' href='http://blog.nibblesec.org/2009/06/hpp-and-wafs.html?showComment=1245309865355#c4115996223185345057' title=''/><author><name>Or</name><uri>http://www.blogger.com/profile/16214055072579620536</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.nibblesec.org/2009/06/hpp-and-wafs.html' ref='tag:blogger.com,1999:blog-732257695511948254.post-3787314701620451515' source='http://www.blogger.com/feeds/732257695511948254/posts/default/3787314701620451515' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1884565937'/></entry></feed>
