<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-7122745763234660283.post7276035970145501352..comments</id><updated>2010-05-10T00:50:56.590-07:00</updated><category term='jQuery'/><category term='Web Attacks'/><category term='Advisory'/><category term='Applet Security'/><category term='Http Request Splitting'/><category term='Application Security'/><category term='Http Parameter Pollution'/><category term='malware'/><category term='Cross Site Scripting'/><category term='Dom Xss'/><category term='DOMinator'/><category term='WWeb Security'/><category term='Banking'/><category term='Java'/><category term='Information Disclosure'/><category term='Omniture'/><category term='Spring MVC'/><category term='Expression Language Injection'/><category term='Java Security'/><category term='twitter'/><category term='Sharepoint'/><category term='Web Security'/><category term='Client Side HTTP Parameter Pollution'/><category term='JNLP Security'/><category term='JSON'/><category term='Liferay'/><category term='Same Origin Policy'/><category term='Arbitrary Code Execution'/><title type='text'>Comments on Minded Security Blog: Fooling B64_Encode(Payload) on WAFs and filters</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://blog.mindedsecurity.com/feeds/7276035970145501352/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/7276035970145501352/comments/default'/><link rel='alternate' type='text/html' href='http://blog.mindedsecurity.com/2010/04/fooling-b64encodepayload-on-wafs-and.html'/><author><name>Minded Security</name><uri>http://www.blogger.com/profile/01503616812076743415</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>6</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-7122745763234660283.post-4222255309319584018</id><published>2010-04-23T04:49:40.081-07:00</published><updated>2010-04-23T04:49:40.081-07:00</updated><title type='text'>The final of the history: 
it seems that ModSecuri...</title><content type='html'>The final of the history: &lt;br /&gt;it seems that ModSecurity people agreed about the too strict implementation of Apache APR base64 decoder.&lt;br /&gt;So probably they will give us two B64 decoders:&lt;br /&gt;strict and flexible.. &lt;br /&gt;&lt;br /&gt;I&amp;#39;m very proud and satisfied now! :)&lt;br /&gt;@Brian, thanks for the interesting discussion on this topic.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/7276035970145501352/comments/default/4222255309319584018'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/7276035970145501352/comments/default/4222255309319584018'/><link rel='alternate' type='text/html' href='http://blog.mindedsecurity.com/2010/04/fooling-b64encodepayload-on-wafs-and.html?showComment=1272023380081#c4222255309319584018' title=''/><author><name>Minded Security</name><uri>http://www.blogger.com/profile/01503616812076743415</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.mindedsecurity.com/2010/04/fooling-b64encodepayload-on-wafs-and.html' ref='tag:blogger.com,1999:blog-7122745763234660283.post-7276035970145501352' source='http://www.blogger.com/feeds/7122745763234660283/posts/default/7276035970145501352' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1570645034'/></entry><entry><id>tag:blogger.com,1999:blog-7122745763234660283.post-4750125145879424041</id><published>2010-04-22T04:31:26.398-07:00</published><updated>2010-04-22T04:31:26.398-07:00</updated><title type='text'>http://www.ietf.org/rfc/rfc2045.txt
Page 25:
Any c...</title><content type='html'>http://www.ietf.org/rfc/rfc2045.txt&lt;br /&gt;Page 25:&lt;br /&gt;Any characters outside of the base64 alphabet are to be ignored in base64-encoded data.&lt;br /&gt;...&lt;br /&gt;That&amp;#39;s about the rfc implementation.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/7276035970145501352/comments/default/4750125145879424041'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/7276035970145501352/comments/default/4750125145879424041'/><link rel='alternate' type='text/html' href='http://blog.mindedsecurity.com/2010/04/fooling-b64encodepayload-on-wafs-and.html?showComment=1271935886398#c4750125145879424041' title=''/><author><name>Minded Security</name><uri>http://www.blogger.com/profile/01503616812076743415</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.mindedsecurity.com/2010/04/fooling-b64encodepayload-on-wafs-and.html' ref='tag:blogger.com,1999:blog-7122745763234660283.post-7276035970145501352' source='http://www.blogger.com/feeds/7122745763234660283/posts/default/7276035970145501352' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1570645034'/></entry><entry><id>tag:blogger.com,1999:blog-7122745763234660283.post-3243971626819148751</id><published>2010-04-22T01:17:13.999-07:00</published><updated>2010-04-22T01:17:13.999-07:00</updated><title type='text'>Brian, I didn&amp;#39;t see your comment sorry.
You&amp;#3...</title><content type='html'>Brian, I didn&amp;#39;t see your comment sorry.&lt;br /&gt;You&amp;#39;re stating that companies should not rely on modsecurity b64 decoder and that they should add a positive rule?&lt;br /&gt;&lt;br /&gt;It seems to me a choice for them as well as it is a choice implementing controls on application after the payload is decoded on the correct layer..</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/7276035970145501352/comments/default/3243971626819148751'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/7276035970145501352/comments/default/3243971626819148751'/><link rel='alternate' type='text/html' href='http://blog.mindedsecurity.com/2010/04/fooling-b64encodepayload-on-wafs-and.html?showComment=1271924233999#c3243971626819148751' title=''/><author><name>Minded Security</name><uri>http://www.blogger.com/profile/01503616812076743415</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.mindedsecurity.com/2010/04/fooling-b64encodepayload-on-wafs-and.html' ref='tag:blogger.com,1999:blog-7122745763234660283.post-7276035970145501352' source='http://www.blogger.com/feeds/7122745763234660283/posts/default/7276035970145501352' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1570645034'/></entry><entry><id>tag:blogger.com,1999:blog-7122745763234660283.post-7989093308468780395</id><published>2010-04-22T01:09:36.374-07:00</published><updated>2010-04-22T01:09:36.374-07:00</updated><title type='text'>@thornmaker, thanks.

Altough Noscript actually fi...</title><content type='html'>@thornmaker, thanks.&lt;br /&gt;&lt;br /&gt;Altough Noscript actually fixed it, it seems they&amp;#39;re not going to fix it.&lt;br /&gt;http://blog.modsecurity.org/2010/04/impedance-mismatch-and-base64.html &lt;br /&gt;Their suggestion is about using a positive rule. &lt;br /&gt;I wrote about it 5 years ago (http://www.wisec.it/sectou.php?id=438064b3e5ea4 ) and I still don&amp;#39;t see it using correctly on WAFs. &lt;br /&gt;&lt;br /&gt;My suggestion still remains in implementing good secureSDLC.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/7276035970145501352/comments/default/7989093308468780395'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/7276035970145501352/comments/default/7989093308468780395'/><link rel='alternate' type='text/html' href='http://blog.mindedsecurity.com/2010/04/fooling-b64encodepayload-on-wafs-and.html?showComment=1271923776374#c7989093308468780395' title=''/><author><name>Stefano Di Paola</name><uri>http://www.blogger.com/profile/18241677936736054546</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.mindedsecurity.com/2010/04/fooling-b64encodepayload-on-wafs-and.html' ref='tag:blogger.com,1999:blog-7122745763234660283.post-7276035970145501352' source='http://www.blogger.com/feeds/7122745763234660283/posts/default/7276035970145501352' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-157727315'/></entry><entry><id>tag:blogger.com,1999:blog-7122745763234660283.post-4760691800550071712</id><published>2010-04-22T00:55:13.315-07:00</published><updated>2010-04-22T00:55:13.315-07:00</updated><title type='text'>Yes, endless variations.  Please see my response h...</title><content type='html'>Yes, endless variations.  Please see my response here:&lt;br /&gt;&lt;br /&gt;http://blog.modsecurity.org/2010/04/impedance-mismatch-and-base64.html</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/7276035970145501352/comments/default/4760691800550071712'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/7276035970145501352/comments/default/4760691800550071712'/><link rel='alternate' type='text/html' href='http://blog.mindedsecurity.com/2010/04/fooling-b64encodepayload-on-wafs-and.html?showComment=1271922913315#c4760691800550071712' title=''/><author><name>Brian Rectanus</name><uri>http://www.blogger.com/profile/04579246411400625873</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.mindedsecurity.com/2010/04/fooling-b64encodepayload-on-wafs-and.html' ref='tag:blogger.com,1999:blog-7122745763234660283.post-7276035970145501352' source='http://www.blogger.com/feeds/7122745763234660283/posts/default/7276035970145501352' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-383225679'/></entry><entry><id>tag:blogger.com,1999:blog-7122745763234660283.post-187698141962643109</id><published>2010-04-21T20:52:31.919-07:00</published><updated>2010-04-21T20:52:31.919-07:00</updated><title type='text'>Nice write up!  I&amp;#39;ve often wondered why base64...</title><content type='html'>Nice write up!  I&amp;#39;ve often wondered why base64 decoding is so forgiving.  I suppose a good WAF will have to consider all possible variations... ugh.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/7276035970145501352/comments/default/187698141962643109'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/7276035970145501352/comments/default/187698141962643109'/><link rel='alternate' type='text/html' href='http://blog.mindedsecurity.com/2010/04/fooling-b64encodepayload-on-wafs-and.html?showComment=1271908351919#c187698141962643109' title=''/><author><name>thornmaker</name><uri>http://p42.us</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.mindedsecurity.com/2010/04/fooling-b64encodepayload-on-wafs-and.html' ref='tag:blogger.com,1999:blog-7122745763234660283.post-7276035970145501352' source='http://www.blogger.com/feeds/7122745763234660283/posts/default/7276035970145501352' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1036427584'/></entry></feed>
