denimgroup / threadfix

ThreadFix is a software vulnerability management platform. This GitHub site is far out of date. Please go to www.threadfix.it for up-to-date information.
339 stars 127 forks source link

Verify proper encoding when creating WAF rules (previously GC#340) #72

Open dorindareyna opened 10 years ago

dorindareyna commented 10 years ago

Reported by dancorn...@gmail.com, Aug 27, 2013 Need to run through the WAF rule generators and make sure we are properly encoding user-supplied data for the rule format (XML, newline-based text file, etc)

Most of this is

dorindareyna commented 10 years ago

Comment by mcoll...@denimgroup.com on Sep 25, 2013

Paring down

macacollins commented 10 years ago

I'm taking this out of the current milestone until we have a better WAF testbed.