Advertisement
Help Keep Boards Alive. Support us by going ad free today. See here: https://subscriptions.boards.ie/.
If we do not hit our goal we will be forced to close the site.

Current status: https://keepboardsalive.com/

Annual subs are best for most impact. If you are still undecided on going Ad Free - you can also donate using the Paypal Donate option. All contribution helps. Thank you.
https://www.boards.ie/group/1878-subscribers-forum

Private Group for paid up members of Boards.ie. Join the club.

86% of PHP-based apps contain at least one XSS vulnerability

  • 04-12-2015 04:25PM
    #1
    Closed Accounts Posts: 1,322 ✭✭✭


    Does anyone out there use or employ virtual patching , Does anyone disagree with the principles as an aswer to these types of mass vulns . Teams i can understand can be delayed in getting to most of the edge or DMZ nested systems , but based on what they are and what they do should industry not be pushed to have virt patching forced via PCI DSS ? Im thinking it a handy way to delay the update pushes and to have a virtual hammer drop for detected attcks ?, until they can get to those systems ?

    http://www.net-security.org/secworld.php?id=19189


Comments

  • Closed Accounts Posts: 18,966 ✭✭✭✭syklops


    dbit wrote: »
    Does anyone out there use or employ virtual patching , Does anyone disagree with the principles as an aswer to these types of mass vulns . Teams i can understand can be delayed in getting to most of the edge or DMZ nested systems , but based on what they are and what they do should industry not be pushed to have virt patching forced via PCI DSS ? Im thinking it a handy way to delay the update pushes and to have a virtual hammer drop for detected attcks ?, until they can get to those systems ?

    http://www.net-security.org/secworld.php?id=19189

    I use and employ WAFs if thats any help?


  • Closed Accounts Posts: 1,322 ✭✭✭dbit


    WAFS are they actually capable of scanning an OS and its subset of applications and thus bring down a vale of virtual patching inline shrowded over all the instances found within and stop exploits against vulnerable applcaitions ? And im not just talking about the web apps them selves , I mean every peice of software in each instance ?


Advertisement