|
|
|
|
|
by Bnshsysjab
2096 days ago
|
|
I hate these kind of defenses. If your application is vulnerable to sqli, select is one of many tools an attacker can use and you’re pretty much screwed anyway. Instead, use sane tooling, like modern ORMs and parameter izers, with some data sanitation if you’re really paranoid. |
|
You're misunderstanding the market.
The point of Cloudflare WAF isn't to be a main line of defense for HN readers, it's to stop the low effort automated drive-by attacks for websites that were already hosed. Like WAFs that block /wp-admin/* and instead generate a new segment.
I'd be surprised if there was a single person in the world who is going to go "oh right I should replace Cloudflare WAF and my sqli with some parameterized queries!"