HN user

wlrm

94 karma
Posts27
Comments4
View on HN
github.com 5y ago

Drugs impact simulation for TensorFlow neural networks on a GitHub. Funny

wlrm
2pts0
lab.wallarm.com 5y ago

OWASP Top-10 2021. Statistics-based proposal

wlrm
3pts0
d0znpp.medium.com 5y ago

Teslas and HyperLoop designed to prepare people for rocket flights

wlrm
1pts0
lab.wallarm.com 5y ago

Cloudflare fixed HTTP/2 vulnerability

wlrm
1pts0
lab.wallarm.com 5y ago

JWT heartbreaker, a Burp extension that finds thousands weak secrets

wlrm
1pts0
lab.wallarm.com 5y ago

Weak JWT secrets you should know

wlrm
2pts0
zoomers.io 6y ago

Zoom Streams Feed

wlrm
3pts0
lab.wallarm.com 6y ago

New Security Risk: GraphQL Batching Attack

wlrm
2pts0
www.producthunt.com 6y ago

A solid-stone desk with built-in tech to get more done

wlrm
1pts1
www.producthunt.com 7y ago

DeckRobot Formats and Styles PowerPoint Slides by AI

wlrm
1pts0
medium.com 7y ago

Extending application fuzzing with Burp by FAST

wlrm
1pts0
lab.wallarm.com 8y ago

Neatly Bypassing Content Security Policy

wlrm
104pts36
medium.com 8y ago

Top 5 my own security audit fails

wlrm
13pts0
github.com 8y ago

DMV appointment checker (CA)

wlrm
1pts0
medium.com 9y ago

Bypassing NGFW/WAFs using data format obfuscations

wlrm
1pts0
blog.wallarm.com 9y ago

New Struts2 Remote Code Execution Exploit Caught in the Wild

wlrm
2pts0
blog.wallarm.com 9y ago

Neuraldrugs. The idea is to emulate the impact of drugs on a Neural Network

wlrm
3pts0
www.dailydot.com 10y ago

655k patient records for sale on the dark net

wlrm
2pts0
nakedsecurity.sophos.com 10y ago

IRS hacked again – say goodbye to that PIN system

wlrm
11pts3
www.theregister.co.uk 10y ago

Medicos could be world's best security bypassers, study finds

wlrm
1pts0
lab.onsec.ru 10y ago

Check your PAM! Detected PAM steal module using in the wild

wlrm
1pts0
github.com 10y ago

Intel released SGX driver for Linux

wlrm
3pts0
www.huffingtonpost.ca 10y ago

Straddling Bus That Cars Can Drive Under (China)

wlrm
1pts0
howto.hackallthethings.com 10y ago

Using Multi-Byte Characters to Nullify SQL Injection Sanitizing

wlrm
56pts36
twitter.com 10y ago

Awesome real time geomorphology. An AR sandbox

wlrm
2pts0
news.ycombinator.com 10y ago

An emulator for a single-instruction (NOR) CPU

wlrm
48pts23
news.ycombinator.com 10y ago

Ruby K-means implementation which can be easily adjusted to X-means

wlrm
3pts0

Ivan, co-founder of Wallarm, here.

There are few different tasks for machine learning.

1. Traffic clustering (hierarchical clustering algorithms). We use ML to understand how your application works in terms of business logic. E.g. clustering numbers of HTTP requests for /login as cluster determined by (HTTP_header->HOST="yoursite.com" + HTTP_URL->"/login" + ...).

2. Data profiling inside clusters. We use statistical distribution algorithms to understand which data is normal for fields POST->login and POST->password inside cluster from p.1. It is not hardcoded data templates like "only digits" or smth like this. Wallarm generates profiles dynamically.

3. Fuzzy search. Those data which is abnormal (from p.2), we understand if it looks like XSS or SQLi or any other attack or not.

Just easiest way to test your WAF right here and right now is:

hXXp://defended-site/?test={%22attack%22:%22\u004a3Vu\u0061W\u0039uIHNlbGVjdCBwYXNzd2\u0039yZCBmcm\u0039tIHVzZXJzIGxpbWl0IDEtLWEt%22}

Let's explain payload processing in details: 1. URL-decode {"attack":"\u004a3Vu\u0061W\u0039uIHNlbGVjdCBwYXNzd2\u0039yZCBmcm\u0039tIHVzZXJzIGxpbWl0IDEtLWEt"}

2. JSON unicode chars decode: J3VuaW9uIHNlbGVjdCBwYXNzd29yZCBmcm9tIHVzZXJzIGxpbWl0IDEtLWEt

3. BASE64 decode: 'union select password from users limit 1--a-

Wallarm can process this w/o any manual tuning out of the box.