Web Hack List

Collected research

AWS WAF Clients Left Vulnerable to SQL Injection Due to Unorthodox MSSQL Design Choice

MSSQL accepts stacked statements with no semicolon and no whitespace between them, which AWS WAF's SQL parser treated as invalid and let through. Appending an exec() payload to an injectable parameter bypassed the WAF for UNION-based login bypass, password rewrites and enabling xp_cmdshell for remote code execution. Microsoft called the parsing by design; AWS fixed the WAF.

Record

Researcher
Marc Olivier Bergeron and @GoSecure_Inc
Published by
GoSecure
Date
Topic
Injection

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Marc Olivier Bergeron and @GoSecure_Inc, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .