releases

Acunetix Web Vulnerability Scanner Product Releases

acunetix how to

Technical tips and videos about Acunetix WVS and Web Security

news

Acunetix Company and Web Security news, & Press Releases

events

Acunetix Webinars and Training around the world

web security zone

Everything you need to know about Web Security

Home » articles, news

Implementing a web application firewall only is not enough to secure web applications

Submitted by Robert Abela on May 14, 2009 – 7:15 pmNo Comment

As demonstrated during an OWASP Europe 2009 presentation, WAF’s (web application firewalls) also have vulnerabilities.  Sandro Gauci (founder and CSO for EnableSecurity) and Wendel Henrique (member of SpiderLabs) showed how an attacker can easily identify and bypass several well known web application firewalls using XSS (Cross site scripting) attacks, the same types of exploits WAF’s should be protecting web applications from.  WAF’s can now be exploited using automated tools, to gain direct access to a web application.

As Wendel Henrique explained, a WAF can help, but securing web applications is much more important.  Apart from that, implementing a WAF can cost a lot of time and money, and there is also the need to make network configuration changes.  On the opposite, scanning a web application with a web vulnerability scanner such as Acunetix WVS, helps you secure your web application without the need of web security expertise, and it saves you time.

Therefore as a conclusion, we can see that although a WAF adds an extra layer of protection, one should never rely on web application firewalls only, and should always ensure that web applications are secure.

You can read more about the OWASP Europe 2009 presentation on Web Application Firewalls vulnerabilities from the following link: http://www.darkreading.com/security/app-security/showArticle.jhtml?articleID=217400819&cid=RSSfeed

Bookmark and Share

Leave a comment!

Add your comment below, or trackback from your own site. You can also subscribe to these comments via RSS.

Be nice. Keep it clean. Stay on topic. No spam.

You can use these tags:
<a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

This is a Gravatar-enabled weblog. To get your own globally-recognized-avatar, please register at Gravatar.