Home / Companies / Azion / Blog / March 2023

March 2023 Summaries

1 posts from Azion

Filter
Month: Year:
Post Summaries Back to Blog
Web Application Firewalls (WAFs) play a crucial role in safeguarding web-based applications from cyberattacks, though they are often targeted by cybercriminals seeking to bypass their defenses. In December 2022, Team82 from Claroty discovered a bypass affecting several popular WAFs, though Azion's WAF remained unaffected. Recently, researchers at Praetorian identified another bypass vulnerability, specifically a "CRLF Injection Attack," which targets Akamai's WAF by exploiting improper filtering of HTTP response headers, allowing attackers to inject compressed data to evade detection. This technique, considered novel due to its combination of CRLF injection and data compression to bypass WAF rules, highlights potential vulnerabilities across different WAF products. However, Azion's WAF was tested against this vulnerability and successfully blocked the attacks using its standard rules and scoring algorithm, demonstrating its robustness in protecting against zero-day threats without the need for additional configurations.
Mar 23, 2023 755 words in the original blog post.