List: websecurity@lists.webappsec.org
From: Rcbarnett
Re: [WEB SECURITY] SQL Smuggling: New methods of SQL Smuggling
Mon, Jan 31, 2011 8:47 PM
the backend server to be vulnerable to SQLi, you only
>> want to check if the CRS identifies your payloads as malicious or not.
>>
>
> Additionally, we setup live proxy demos where we front-ended various web app
> scanning vendor's public buggy apps (AppScan, WebInspect, etc...).
>
> http://www.modsecurity.org/demo/
>
> ModSecurity will not block but will