Bypassing Akamai’s Web Application Firewall Using an Injected Content-Encoding Header

Bypassing Akamai’s Web Application Firewall Using an Injected Content-Encoding Header

During a recent Chariot customer pilot we identified an interesting method to bypass the cross-site scripting (XSS) filtering functionality within the Akamai Web Application Firewall (WAF) solution. Chariot had identified a Carriage ...