Web Application Firewalls: Analysis of Detection Logic
by Vladimir Ivanov The presentation will highlight the core of Web Application Firewall (WAF): detection logic, with an accent on regular expressions detection mechanism. The security of 6 trending opensource WAFs (OWASP CRS 2,3 - ModSecurity, Comodo WAF, PHPIDS, QuickDefense, Libinjection) will be called into question. Static Application Security Testing (SAST) tool for Regular Expressions analysis will be released, which aims to finds security flaws in the cunning syntax of regular expressions. Using the proposed "regex security cheatsheet", rules from popular WAFs will be examined. Logical flaws in regular expressions will be demonstrated by applying author's bughunting experience and best practices. Unexpected by regexp's primary logic vectors will be discovered for Cross-Site Scripting and SQL-Injection attacks (MySQL, MSSQL, Oracle) using advanced fuzz testing techniques. Obtained from fuzz testing framework attack vectors will be clustered and represented via look-up tables. Such tables can be used by both attackers and defenders in order to understand the purpose of characters in various parts of attack vector, which are allowed by appropriate browsers or databases. More than 15 new bypass vectors will be described, with an indication of over 300 potential weakness in regular expression detection logic of WAFs.

Breaking Hardware-Enforced Security With Hypervisors

Game of Chromes: Owning the Web with Zombie Chrome Extensions

WAF Bypass Techniques Using HTTP Standard and Web Servers’ Behavior - Soroush Dalili

Zig 2026: No-AI Policy, $670K Foundation, Left GitHub & Why Zig Isn’t 1.0 - Andrew Kelley Explains

Using Undocumented CPU Behavior to See Into Kernel Mode and Break KASLR in the Process

n8n Tutorial – Zero to Hero Course

Billionaire's WARNING: I'm SELLING. The Crash Is Already Here!

HEIST: HTTP Encrypted Information can be Stolen Through TCP-Windows

System Design Explained: APIs, Databases, Caching, CDNs, Load Balancing & Production Infra

Attacking AI - Jason Haddix - NDC Security 2026

Keynote: After the AI Hype – What’s Real, and What’s Next - Richard Campbell - 2026

Introduction to the OWASP ModSecurity Core Rule Set | Christian Folini | Nullcon Webinar

Mateusz Olejarka - REST API, pentester's perspective

Creator of C++: Bell Labs, Negative Overhead Abstraction, Mistakes | Bjarne Stroustrup

The World's Most Important Machine

Practical Web Cache Poisoning: Redefining 'Unexploitable'

NestJS Full Course in 2026 | How Senior Engineers Build Backends with AI

Broadpwn: Remotely Compromising Android and iOS via a Bug in Broadcom's Wi-Fi Chipsets

Using An Expanded Cyber Kill Chain Model to Increase Attack Resiliency

