Light

Episode #902 Quiz

A Generic WAF Bypass
Date: 2022-12-20 | Length: 1.75 hrs | Episode page at twit.tv

About this episode

Team82 found a generic WAF bypass across Palo Alto, F5, AWS, Cloudflare, and Imperva by exploiting JSON support mismatch: modern SQL engines parse JSON by default, but WAFs often do not. Crafted JSON syntax hid malicious SQL, enabling injection and database exfiltration. Vendors patched their SQL inspection logic.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: According to the episode, what was the key parsing mismatch that made Team82’s generic WAF bypass work against multiple vendors’ products?
Question 2: Which specific JSON operator did Team82 say threw the WAFs into loops and enabled the bypass?
Question 3: Which set of vendors was explicitly named as having WAF products affected by Team82’s discovery?
Question 4: What did the episode say Elon’s attempt to block all the bots did to Twitter’s legitimate users?
Question 5: According to the episode, what was the end-of-next-year deadline associated with GitHub submitters?
Cancel