Collected research
AWS WAF Bypass: invalid JSON object and unicode escape sequences
AWS WAF can only inspect a request body as plain text or JSON, and its default handling of a body it considers invalid JSON is to let the request through unexamined. Repeating a JSON key with a harmless value first and the payload second therefore evades body rules while the application keeps the last value.
Record
- Researcher
- @AndreaTheMiddle and Andrea Menin
- Published by
- Sicuranext Blog
- Date
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of @AndreaTheMiddle and Andrea Menin, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .