upvote
Look, any WAF that blocks a document like

    <!DOCTYPE html>
    <html lang="en">
    <body>
    <p>/etc/hosts is a file on Unix hosts</p>
is pretty clearly broken. And you can't meaningfully measure product metrics like impact for fundamentally broken products.
reply
> is pretty clearly broken

agree

> And you can't meaningfully measure product metrics like impact for fundamentally broken products

disagree

reply
I have a WAF that blocks everything. It's obviously fundamentally broken, but in terms of product metrics like impact, it's incredible! It stops 100% of attacks!
reply