The tweet discusses a practical issue related to WAF (Web Application Firewall) bypasses and solvers. It highlights the asymmetric effort involved in dealing with WAFs: a solver, which is a method or tool designed to evade or solve a WAF's logic, might stop working suddenly if the WAF's logic changes. However, a bypass that exploits a root vulnerability in the application would not be affected by changes in the WAF's logic. Instead, only fixing the root vulnerability would prevent the bypass, meaning that bypasses are more stable and reliable compared to solvers which depend on the current WAF logic.
Original tweet: https://twitter.com/ijdfkkk/status/2033155535021682974
Subscribe for the latest news: