upvote
>guess you're putting in a WAF, like it or not.

Install the WAF crap, and then feed every request through rot13(). Everyone is happy!

reply
Up until you need to exercise the insurance policy and the court room "experts" come down on you like a ton of bricks.
reply
now you've banned several different arbitrary strings!
reply
Good luck debugging why the string "/rgp/cnffjq" causes your request to be rejected :)
reply