Clk
Dec 14, 2022Altostratus
Wildcard Parameter signature attack
Hi,
I have a wildcard * Parameter and it's not found signature attack.
Tried to make an SQL injection with only the wildcard Parameter and the request didn't show the violation, but when adding the parmater name the attacked signature was blocked.
Is the wildcard Parameter not blocking signature attack?
Thank you for your answers.
The problem was in the Parameter data type, it was in Email type ( i figured that this is the default entity when new policy is created).
In Email type there's no signature enforce.