Picus Security Adds WAF Bypass Method for JSON-Based SQL Injection Attacks
Picus Security has incorporated a new technique into its threat library that bypasses Web Application Firewalls (WAF) using JSON-based SQL injection attacks. This method allows attackers to gain unauthorized access to databases.
Cybersecurity firm Picus Security has updated its threat library with a new method to bypass Web Application Firewalls (WAF). The new threat leverages JSON-based SQL injection attacks, which have proven difficult for many WAFs to detect. SQL injection remains a prevalent web attack vector, ranking third on the OWASP Top Ten list for 2021.
While traditional WAFs are designed to identify and block standard SQL injection attempts by filtering malicious keywords and patterns, recent research indicates that many vendors fail to detect these attacks when payloads are delivered via JSON. This stems from a lack of native JSON syntax support in some WAF products, preventing proper inspection of data formatted in this way.
Picus Security's addition of this bypass technique to its threat library allows organizations to proactively test their security controls against such sophisticated threats. The company offers a platform for simulating these attacks, enabling businesses to identify and remediate vulnerabilities before they can be exploited.
Successful exploitation of JSON-based SQL injection can lead to data theft, data modification, or even the execution of operating system commands on the target server. Picus Security's platform now includes simulations for these attacks, helping organizations strengthen their defenses.