Technical Forum
Ask questions. Discover Answers.
cancel
Showing results for 
Search instead for 
Did you mean: 

Does AWS Managed Ruled support HTTP header injection?

Kazuto
Nimbostratus
Nimbostratus

If an HTTP header with a newline code inserted is sent, can AWS Managed Rule detect and prevent it?

If so, which AWS Managed Rules are included?

2 REPLIES 2

buulam
Community Manager
Community Manager

Hi @Kazuto I'll route this to the PM for the AWS Managed Rules and find out

~~~~~~~~~~~~~~~~~~
@buulam / YouTube.com/DevCentral

Joel_Cohen
F5 Employee
F5 Employee

Hi Kazuto,

The F5 Rules for AWS WAF - Web exploits OWASP Rules has rules for blocking different HTTP Header Injections. Depending on the HTTP request and how AWS parses and handles it for inspection, the rules in place should block injections in HTTP headers. If you find that something is not blocked as expected, please share with us a sample request and we will check into it further