Azion's WAF Is Not Vulnerable to the CRLF Injection Bypass
Blog post from Azion
Web Application Firewalls (WAFs) play a crucial role in safeguarding web-based applications from cyberattacks, though they are often targeted by cybercriminals seeking to bypass their defenses. In December 2022, Team82 from Claroty discovered a bypass affecting several popular WAFs, though Azion's WAF remained unaffected. Recently, researchers at Praetorian identified another bypass vulnerability, specifically a "CRLF Injection Attack," which targets Akamai's WAF by exploiting improper filtering of HTTP response headers, allowing attackers to inject compressed data to evade detection. This technique, considered novel due to its combination of CRLF injection and data compression to bypass WAF rules, highlights potential vulnerabilities across different WAF products. However, Azion's WAF was tested against this vulnerability and successfully blocked the attacks using its standard rules and scoring algorithm, demonstrating its robustness in protecting against zero-day threats without the need for additional configurations.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.