Episode #902 Quiz
A Generic WAF Bypass
Date: 2022-12-20 | Length: 1.75 hrs | Episode page at twit.tv
About this episode
Team82 found a generic WAF bypass across Palo Alto, F5, AWS, Cloudflare, and Imperva by exploiting JSON support mismatch: modern SQL engines parse JSON by default, but WAFs often do not. Crafted JSON syntax hid malicious SQL, enabling injection and database exfiltration. Vendors patched their SQL inspection logic.
Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.