12-Apr-2023 04:28
If an HTTP header with a newline code inserted is sent, can AWS Managed Rule detect and prevent it?
If so, which AWS Managed Rules are included?
12-Apr-2023 23:28
Hi @Kazuto I'll route this to the PM for the AWS Managed Rules and find out
25-Apr-2023 07:39
Hi Kazuto,
The F5 Rules for AWS WAF - Web exploits OWASP Rules has rules for blocking different HTTP Header Injections. Depending on the HTTP request and how AWS parses and handles it for inspection, the rules in place should block injections in HTTP headers. If you find that something is not blocked as expected, please share with us a sample request and we will check into it further