Web Hack List

Collected research

AWS WAF Bypass: invalid JSON object and unicode escape sequences

AWS WAF can only inspect a request body as plain text or JSON, and its default handling of a body it considers invalid JSON is to let the request through unexamined. Repeating a JSON key with a harmless value first and the payload second therefore evades body rules while the application keeps the last value.

Record

Researcher
@AndreaTheMiddle and Andrea Menin
Published by
Sicuranext Blog
Date
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of @AndreaTheMiddle and Andrea Menin, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .