
3/11/2014 · Simon Moore
What this post added
Introduced and detailed two specific WAF rules (WP0001 and 100000) to mitigate WordPress pingback attacks and attacks using mutating query strings. WP0001 blocks the pingback mechanism via xmlrpc.php, and 100000 blocks mutating query strings that neutralize caches. This demonstrates the WAF's capability to protect against application-layer DDoS attacks leveraging specific WordPress features.