websecurity@lists.webappsec.org

The Web Security Mailing List

View all threads

Re: [WEB SECURITY] Abusing the Host header for cache&password reset poisoning

MO
Martin O'Neal
Wed, May 1, 2013 10:14 AM

This is where a WAF does its job very well,
in particular if it supports virtual patching.

Actually, this is one of the very few occasions where I think that a WAF offers some value.

Martin...

> This is where a WAF does its job very well, > in particular if it supports virtual patching. Actually, this is one of the very few occasions where I think that a WAF offers some value. Martin...