|
|
|
|
|
by Retr0id
564 days ago
|
|
I disagree that the WAF situation is comparable. The curl report (incorrectly) describes missing bounds checks leading to buffer overflows. If the curl project said "buffer overflows are ok because our code gets compiled with ASLR and NX", then that would be comparable to saying SQLi and XSS are non-issues due to a WAF. Fortunately, that's not what they said. |
|