Closed GoogleCodeExporter closed 9 years ago
The generic attacks used by skipfish should be already be sufficient to bypass
some naive filters; but in general, IPS/WAF evasion does not seem to be a
particularly useful core functionality of a web scanner.
It's always preferred to test applications with IPS/WAF disabled (or the
scanner whitelisted); otherwise, with any tool, you are likely to miss actual
implementation problems because that specific IPS/WAF is tested with and
designed to block that particular tool.
Original comment by lcam...@gmail.com
on 27 May 2011 at 3:16
Original issue reported on code.google.com by
Charlie....@gmail.com
on 27 May 2011 at 2:46