What it blocks
Blackwall looks at every request to your website and stops the ones that add up to an attack. Not for one weak sign: for what the request is actually trying to do.
- Malformed requestsRequests that break the rules of how browsers and servers talk: conflicting lengths, forbidden characters, headers smuggled inside other headers.For example: Two different lengths for the same request (request smuggling).
- Database injectionDatabase commands typed into a search box, a form or an address, hoping your site passes them straight to its database.For example: ' OR '1'='1 in a login form.
- Script injectionScript code sent as if it were ordinary text, hoping your site shows it back to other visitors, whose browsers would then run it.For example: <script> in a comment.
- File accessAddresses that try to climb out of your website's folder, ask for the server's own files, or make your site load a file from somewhere else.For example: ../../etc/passwd in an address.
- Command and code injectionShell commands or program code sent as input, hoping the server runs it.For example: ; cat /etc/passwd after a file name.
- Attack toolsRequests that announce themselves as a vulnerability scanner or attack tool.For example: A request whose browser name is sqlmap or nikto.
- Session attacksA request that tries to set a visitor's session id from outside the site.For example: A session id passed in a link from another website.
Questions about what it covers are answered in Help.