|
|
|
|
|
by jesprenj
875 days ago
|
|
AFAIUC, the reason for the word blacklist here lies in the fact that some applications have WAFs or similar software that detect malicious requests and since passwords are sent in plaintext to the WAF, they are detected as malicious exploitation attempts, if they imitate SQL injections, although your parent comment did not give any concrete examples. |
|
For instance, TRUNCATE isn't even in the list