Attempts to Bypass CDNs, (Wed, Dec 3rd)
ID: 4c2da38c-4f04-52f4-88bf-63fb62c36f33
STIX ID: report--4c2da38c-4f04-52f4-88bf-63fb62c36f33
Feed Name: SANS ISC Diary
The report observes a recent increase in honeypot-detected HTTP requests that include CDN-associated headers (e.g., Cf-Warp-Tag-Id, X-Fastly-Request-Id, X-Akamai-Transformed, Salesforce IDs, and “Xiao9-” prefixed headers), indicating attempts to bypass CDN protections or mask request origins by forging or leveraging such headers. It outlines the inherent weakness of CDN fronting when origin IPs are exposed, warns against trusting CDN-identifying headers for access control, and notes the activity spike beginning around November 20.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
