Does anyone have first hand experience with a WAF that did that?
Does anyone have first hand experience with a WAF that did that?
In our case, we block the impossible combos and rate-limit the ones commonly used by botnets.
Blocking based on whether the UA has "Linux" in it is just dumb, though.
Old-school non-computerized discrimination (i.e. racism) work exactly the same way.
You know what else is a terrible idea? Blocking IP ports in firewalls, or MAC based filtering, yet both of these are ubiquitous practices. Don't think something is not happening because you think is a bad idea. Other people, usually the ones in charge will often disagree.
Especially if you’re facing an attack from a common UserAgent with all the other variables changing. And the admin likely thought “Linux users don’t use this service.”
If you're behind a MITM web proxy at work, try going to Lowes.com - there's a chance you'll get blocked by their Akamai filter for putting headers back in the "wrong" (there is no wrong) way.