My WAF went W00F!

We have finally made it this week into Mathieu Dessus'slist of fingerprinted WAFs. Wow! You're probably wondering by now what is this list and why should you care about it? Well, let me tell you all about it. Dessus created a tool that tries to detect what kind of web application firewall is used for protecting an application. It does that by sending an attack vector and testing response and comparing it with the default behavior demonstrated by the different ...

We have finally made it this week into Mathieu Dessus'slist of fingerprinted WAFs. Wow!

You're probably wondering by now what is this list and why should you care about it? Well, let me tell you all about it.

Dessus created a tool that tries to detect what kind of web application firewall is used for protecting an application. It does that by sending an attack vector and testing response and comparing it with the default behavior demonstrated by the different WAFs to which Dessus had access. One could argue about the effectiveness of such technique in real world where people tend to change the default behavior of their devices but my point is totally different here.

We at Imperva are actively engaged in various efforts aimed at providing a standard baseline for testing the security of a WAF. In none of them fingerprinting has been raised as issue. Why is that? Because fingerprinting is a relic of the past. It's a tribute to the dark ages of security by obscurity when people used "obfuscation" instead of encryption and relied on their adversary not knowing the exact brand of web server they are using.

There were times when it made some sense. Hacking was mostly a manual process carried out by a few chosen ones, bandwidth for attackers was scarce and computing resources were very costly. Hacking in general was an expensive time consuming process and therefore attackers were first trying to "fingerprint" the targeted system and apply only those attack vectors that may seem relevant to it.

Nowadays, hacking looks completely different. Bandwidth and computing resources available for the simplest of home setups are abundant. Attack tools exist that would scan a server for thousands of vulnerabilities in a matter of seconds. Moreover, hacking today is completely industrialized and for the most parts it does not involve manual intervention during the attack phase. Hackers abuse hundreds of thousands of zombies, hooked up to a bot net in order to automatically scan and attack their targets. Adding fingerprinting capabilities and conditional execution only complicates the attack code, making it less robust, with no real value for the attacker.

Yes, from time to time individual hackers come up with new methods to bypass security devices. Sometimes they just manage to bypass a device, not even caring what type of device it is. Sometimes they get direct access to a device and manage to come up with specific evasion techniques. Once they have the new technique, it is quickly incorporated into the entire scan database and used during massive scans regardless of whether it is required or not.

To sum things up, I do appreciate researchers taking their time to test the security provided by different WAF solutions. I just wish they would focus their efforts on today's challenges rather than yesterday's.

- Amichai


Read Full Article

Written on Monday, 02 November 2009 10:15 by

Viewed 15 times so far.
Like this? Tweet it to your followers!

Rate this article

Latest articles from

Latest 'tweets' from GovernmentSecurity

  • News Update: Cyber war is coming, the impact could be huge: CBS News reports that cyber.. http://bit.ly/1tx1kr | #Security Link Monday, 09 November 2009 07:35
  • News Update: Tenable Network #Security Podcast - Episode 11: Welcome to the Tenable Netw.. http://bit.ly/2Iqd6G | Security Link Monday, 09 November 2009 07:35
  • News Update: Consent will be required for cookies in Europe: EDITORIAL: A law that dema.. http://bit.ly/3JYgip | #Security Link Monday, 09 November 2009 07:35
  • News Update: CBS 60 Minutes tackles cyber-terrorism: Could hackers get into the compute.. http://bit.ly/2d5Y21 | #Security Link Monday, 09 November 2009 07:35
  • Blog Update: We have launched the new GovernmentSecurity.org: We decided to launch th.. http://bit.ly/2G1SSF | #Security Link Saturday, 07 November 2009 17:38
blog comments powered by Disqus

Site Search

Disqus Tools