Bypassing WAFs Using Oversized Requests
ID: e8dcfd20-9768-55eb-aba8-c0ecd7cc415e
STIX ID: report--e8dcfd20-9768-55eb-aba8-c0ecd7cc415e
Feed Name: Black Hills Infosec Blog
Threat Score
TL;DR — This research article demonstrates an "oversized request bypass" evasion: by sending large amounts of extra data in a POST body, many WAFs (depending on default size limits and modes) may stop inspecting the request and allow malicious payloads (e.g., SQL injection) to reach the backend; the author tests common WAFs, documents default behaviors and size thresholds, and provides hardening recommendations for each vendor.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
