❌

Reading view

There are new articles available, click to refresh the page.

Bypassing WAFs Using Oversized Requests

Many web application firewalls (WAFs) can be bypassed by simply sending large amounts of extra data in the request body along with your payload. Most WAFs will only process requests up to a certain size limit. How the WAF is configured to handle these large requests determines exploitability, but some common WAFs will allow it by default.

The post Bypassing WAFs Using Oversized Requests appeared first on Black Hills Information Security, Inc..

The FBI takes down a huge botnet but doesn’t end the problem

PUBLIC DEFENDER By Brian Livingston The US Defense Criminal Investigative Service (DCIS) and the FBI served a search warrant on a 22-year-old man in Oregon on August 6, 2025, shutting down one of the largest malware botnets ever seen. The bot operation extorted money from websites that didn’t want to be attacked. For instance, the […]

Poking Holes in the Firewall: Egress Testing With AllPorts.Exposed

Beau Bullock // If you have been even remotely in touch with technology in the past thirty years you have probably heard of this thing called a β€œfirewall”. If not, […]

The post Poking Holes in the Firewall: Egress Testing With AllPorts.Exposed appeared first on Black Hills Information Security, Inc..

The New Security Fundamentals – Kill Your AV

John StrandΒ // AV is Dead Long Live Whitelisting. We have been discovering more and more of our tests bypass AV controls with ease.Β Β We have yet to see any iteration or […]

The post The New Security Fundamentals – Kill Your AV appeared first on Black Hills Information Security, Inc..

❌