Preventing Application Attacks
Rapidity is the essence of war: take advantage of the enemy’s unreadiness, make your way by unexpected routes, and attack unguarded spots.
—Sun Tzu in The Art of War
Attackers use a variety of methods to bypass web application input validation and access control mechanisms. The recipes in this chapter show you the most common attack methods and outline various countermeasures for each one. Each recipe includes reference material taken from the Mitre Common Attack Pattern Enumeration and Classification (CAPEC) project: http://capec.mitre.org/.
- OWASP ModSecurity Core Rule Set (CRS)
- ARGS variable
- ARGS_NAMES variable
- REQUEST_HEADERS variable
- @validateByteRange operator
18.104.22.168 - - [15/Apr/2012:16:55:36 +0900] "GET /index.php?option=com_ganalytics&controller=../opt/lampp/logs/ ...