Home / Companies / Azion / Blog / Post Details
Content Deep Dive

Recent WAF Bypass Attack Doesn't Affect Azion's WAF

Blog post from Azion

Post Details
Company
Date Published
Author
Andrew Johnson and Marcos Carvalho and Rafael Rigues
Word Count
668
Company Posts That Month
3
Language
English
Hacker News Points
-
Post removed?
No
Summary

Web Application Firewalls (WAFs) are essential for protecting web applications from malicious attacks like SQL Injection (SQLi) and Cross-Site Scripting (XSS), but cybercriminals continually seek methods to bypass these defenses. Team82 from Claroty unveiled a technique that exploits the slow adoption of JSON support by many WAFs, allowing SQL injection payloads incorporating JSON syntax to bypass some security measures. This method was presented at the Black Hat Europe 2022 conference and poses particular risks for OT and IoT platforms transitioning to cloud-based systems. However, Azion's WAF successfully blocked all attempts using its standard rules and proprietary scoring algorithm, demonstrating its robustness against such bypass techniques. Azion's approach relies on smart rulesets that detect abnormal characters in requests, providing consistent protection against vulnerabilities without frequent updates. The findings underscore the importance of proactive security testing, as demonstrated by Team82's responsible disclosure, which enhances industry-wide security standards.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.