|
|
|
|
|
by ejcx
2098 days ago
|
|
(I work at Cloudflare and manage the Product Security team, so...disclaimer). WAFs definitely help. No WAF is perfect, but having an additional layer to make exploitation harder, and having a tool designed to block specific attacks (like when a new CVE is issued for a CMS) is powerful. Not to mention that WAFs are a requirement in regulated industries. PCI mandates it. And your SOC2 + ISO auditors probably will ask about it too. |
|
A good set of filters deters casual abusers and can amplify the signal from a skilled attack, but ultimately they tend to fail.