When it comes to securing Web sites and applications, many people rely on network-based controls to, presumably, keep everything in check. Be it next-generation firewalls, intrusion prevention systems, or dedicated WAFs, the assumption is that everything is safe and sound at the Web layer as long as one of these controls is in place. Based on the Web security vulnerabilities that I see in my work, I’m not convinced that it’s all that simple.

The post Protecting Web applications with network controls – Is it effective? appeared first on algosec.