Exploit Public-Facing Application
WAF Alert Alert Source: AWS WAF / Cloudflare WAFAlert Time: 2023-10-27 08:45:22 UTCSeverity: CriticalApplication: Public Customer Portal (customer.ourcompany.com)Alert Title: “SQL Injection Attempt Bypassing Authentication”Alert ID: WAF-ALERT-45678 Alert Details: WAF Rule: SQLi_Bypass_Attempt_1 Source IP: 45.134.225[.]67 (DigitalOcean, Netherlands) HTTP Method: POST Target URL: /api/v1/auth/login User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Request Headers: – Content-Type: application/json – X-Forwarded-For: 45.134.225[.]67 Request Body/Payload: { … Read more