Parameterised SQL queries would have blocked it outright also.
Parameterised queries however don’t need an annual fee and a team of security engineers to babysit it.
Parameterised queries however don’t need an annual fee and a team of security engineers to babysit it.
Cloudflare, AWS, GCP etc offerings are basically just one click and for smaller sites will be free.
And over the years there have been many security flaws in how SQL libraries actually handle parameterisation.
Eliminating false positives is a significant effort.
Despite all of that we just found a SQL injection that existed for years somehow. Luckily the WAF blocked attempts to exploit it until we could issue a fix.
Defence in depth is the win here.