I much prefer
- external security monitoring (there are many vendors) - automated testing in pre production using skipfish/w3af/whatever - static code analysis - penetration testing - responsible disclosure programmes - hackdays
I much prefer
- external security monitoring (there are many vendors) - automated testing in pre production using skipfish/w3af/whatever - static code analysis - penetration testing - responsible disclosure programmes - hackdays
A lot of companies have difficulties getting app. patches applied quickly due to test cycles, so applying a WAF rule to block known issues (this one for example) can be a fast, low risk way of reducing the risk.
We were able to issue a virtual patching signature for our clients in less than 2 hrs after the disclosure.
Plus, our generic SQL injection signatures were already blocking this attack even without it.
That gives our clients more time to test and deploy patches without worrying about being compromised in the middle.
I agree, a direct targetted attack against your site they won't help (much). But for stopping a lot of robotic, automated hacking attempts they certainly have their place.