The Big Announcement

  • Post author:
  • Post category:Uncategorized

I have not been this pumped about something in a long time. Jeremiah actually has been pulling me into liking this idea for a very long time. I hated it at first. I mean WAFs, bleh. Plus did we not already try scanners plus WAFs before?

So one thing I failed to realize was that Jeremiah’s approach is a bit different and when combined with WhiteHat Sentinel it is a no brainer.

WAFs generally struggle in a few different areas. The people running them are not web app security experts and trying to apply a default deny policy, while a great idea in theory, is pretty hard in the real world. There is just way too much movement in most applications to pin it down.

What really sold me was when I saw it in action for the first time. From the Sentinel UI we clicked a button that updated the F5 with a rule to block a vulnerability. The rule is automatically generated based on the vulnerability. We then clicked the retest button and the vulnerability was no longer exploitable. Note my careful choice of words – exploitable versus “not there anymore.” The vulnerability certainly still exists in the code but now that the attack is blocked the business can decide if this is a good enough solution or they need to go fix the actual flaw.

From the PCI Section 6.6 perspective this gives the business some great options. I am pretty excited to be part of this. I think we have moved the industry forward today, even if it was just a small step.