Application Layer FirewallsSaumil Shah, Net-SquareTCS APPSECWEEK - 4.9.2009
# who am iSaumil ShahCEO Net-square.Hacker, Speaker, Trainer, Author.M.S. Computer SciencePurdue University.Google: "saumil"LinkedIn: saumilshah
Agenda
Application Layer AttacksInput TamperingSQL InjectionLDAP, XPATH, XQuery InjectionCross Site Scripting (XSS)Exception HandlingSession ManipulationBuffer OverflowHTTP Parameter Pollution (HPP)...and many more
Attacking the applicationNetbanking Loginsaumiluseridxyz' or 3=3 --passwordlogin
It is not easy to fix broken applications
Application Layer Firewalls(WAF)
What do WAFs do?
What do WAFs do?
Types of WAFs
Comparison
Shall we see a demo?
WAFs cure the symptoms, not the illness.
THANK YOUwww.net-square.comsaumil@net-square.comsecure . automate . innovate

Application Layer Firewalls