BSides Cape Town 2024

Ethan

My name is Ethan Havinga, I recently finished high school and was lucky enough to join an internship at MWR CyberSec where I now work fulltime as a Cybersecurity Consultant with a focus in the web application security space.

I enjoy delving deep into obscure and often overlooked topics, I find that you often find the coolest things in the topics people tend to miss. In my free time I am somewhat of a reader, and enjoy the odd book on historical texts specifically that of religious philosophy.


What is your LinkedIn profile URL?

https://za.linkedin.com/in/ethan-havinga-973a21222

What is your blog or portfolio URL?

https://ethanh.co.za


Session

12-07
10:30
45min
Breaking the Barrier: Exploring modern WAFs.
Ethan

In an era where web threats evolve as quickly as the technologies we deploy, the temptation to rely on Web Application Firewalls (WAFs) to mitigate holes in a web application's security is high. But how effective are these digital shields? Could they be more prone to error than we think? This talk will uncover the gaps within our WAF defenses, examining a variety of WAF bypass techniques, both complex and simple. By showcasing these potential weaknesses, we can get a better understanding of the state of modern WAFs so that teams know what to expect when choosing to fall back on WAFs for "protection".

Track 2