Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I don't believe reasonable defaults are possible for that use case. I mean, some anomalies are sure interesting. But I don't care about people trying to exploit MS exchange on my Linux boxes... Everyone runs something different, so unless a lot of profiles are provided that you can turn on/off, what would a reasonable default even be?


That’s my point. Though, maybe there is something to be said for blocking things like OWA vulnerabilities as compared to generic xss/sqli detection rules.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: