Azure's Front Door WAF WTF: IP Restriction Bypass
ID: 26c0989e-41b7-534a-a5fa-958f2f20a293
STIX ID: report--26c0989e-41b7-534a-a5fa-958f2f20a293
Feed Name: TrustedSec blog
This report demonstrates an IP-restriction bypass in Azure Front Door WAF where the default 'RemoteAddr' match variable honors the X-Forwarded-For header, allowing attackers to impersonate allowed IPs and bypass access controls (and any subsequent OWASP rule checks when a custom rule matches). The author provides reproduction steps, brute-force testing details, detection tooling/PowerShell and GraphRunner checks, mitigation guidance (switch to 'SocketAddr' or combine both checks), and a disclosure timeline noting MSRC declined to change the behavior.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
