Track: Track 1 (Hall 6)

  • Surviving WAF Bypass: Building Stronger Authentication Defenses for WordPress Websites 🇬🇧

    This session begins with a difficult practical lesson: a WordPress site can remain exposed (or even compromised) despite operating behind a web application firewall. The WAF filters traffic using network and request-level signals, but attackers who evade those rules still reach the login system, where different weaknesses become available.

    The talk analyzes the authentication layer from an attacker’s perspective. It covers low-and-slow brute-force attempts, username spraying, distributed login activity, automated security scanners, suspicious login paths, and request patterns that remain below generic WAF thresholds. It also examines why applying one policy to every account is dangerous: an administrator, editor, customer, and subscriber do not present the same risk or justify the same authentication friction.

    Participants will see how stronger defenses can be structured around role-specific attempt limits, temporary lockouts, rate controls, two-factor authentication, step-up challenges, IP and network restrictions, travel anomalies, and explicit allow, challenge, or block decisions.

    The session concludes with the importance of recording every authentication attempt with enough context to reconstruct incidents, identify attack patterns, and distinguish successful defense from merely assumed protection.

    Haim Michael