What it blocks
Blackwall checks each request against the OWASP Core Rule Set, version 4.25.0, at its standard strictness: 159 rules in 7 kinds. A request is stopped when what it matches adds up to an attack, not for one weak sign.
- Malformed requests56 rulesRequests that break the rules of how browsers and servers talk: conflicting lengths, forbidden characters, headers smuggled inside other headers.For example: Two different lengths for the same request (request smuggling).
- Database injection20 rulesDatabase commands typed into a search box, a form or an address, hoping your site passes them straight to its database.For example: ' OR '1'='1 in a login form.
- Script injection26 rulesScript code sent as if it were ordinary text, hoping your site shows it back to other visitors, whose browsers would then run it.For example: <script> in a comment.
- File access8 rulesAddresses that try to climb out of your website's folder, ask for the server's own files, or make your site load a file from somewhere else.For example: ../../etc/passwd in an address.
- Command and code injection45 rulesShell commands or program code sent as input, hoping the server runs it.For example: ; cat /etc/passwd after a file name.
- Attack tools1 rulesRequests that announce themselves as a vulnerability scanner or attack tool.For example: A request whose browser name is sqlmap or nikto.
- Session attacks3 rulesA request that tries to set a visitor's session id from outside the site.For example: A session id passed in a link from another website.
What this list is, and is not
- These are the rule set's rules, not ours. We did not invent a way of detecting attacks; we run a well-known one for you and explain what it reports.
- The rule set has stricter levels that catch more and stop more real visitors. Blackwall uses the standard level for everyone.
- What your site sends back to a visitor is not inspected in this version, only what visitors send to your site.
- No rule set catches everything. What Blackwall does not protect against.