Remix.run Logo
SonOfLilit a day ago

You're being downvoted because WAFs work exactly like this, and it's intentional and their vendors think this is a good thing. A WAF vendor would say that a WAF parsing JSON makes it weaker.

immibis a day ago | parent [-]

They're being downvoted because they're saying the author is incorrect when the author is actually correct.

0xbadcafebee a day ago | parent [-]

It's frightening that so many people are convinced the author is correct, when the author never proved they were correct.

The author just collected a bunch of correlations and then decided what the cause was. I've been doing this kind of work for many, many years. Just because it looks like it's caused by one thing, doesn't mean it is.

Correlation is not causation. That's not just a pithy quip, there's a reason why it's important to actually find causation.

SonOfLilit a day ago | parent | next [-]

Having had three opportunities in my life to diagnose this exact problem and then successfully resolve it by turning off the WAF rule (see my top level comment) - I don't know you or your work history, but trust me, the author is much closer to the truth here than you are.

edit: Also, someone commented here "it was an irrelevant cf WAF rule, we disabled it". Assuming honesty, seems to confirm that the author was indeed right.

immibis 9 hours ago | parent | prev [-]

It's more like I saw a big ball fall down and make a hole in the floor and concluded it must be heavy.