Skip to content

Ask some questions #12

@m4ra7h0n

Description

@m4ra7h0n

Hello RyanJarv,
May i ask some questions, at this article https://blog.apnic.net/2022/05/19/bypassing-cdn-wafs-with-alternate-domain-routing/ you talked about to exploit, you have to know origin's ip. But if the origin is s3, such as m4ra7h0nawsbucket.s3.amazon.com, can this also be considered as knowing the ip of orign?

What's the sharing ip? How can i configure the cloudfront to use sharing ip? My s3 bucket configure this to allow the cloudfront GetObject, but it must the E4WXVQBM5CX0A distribution. In this situation, if anyone can bypass the
cloudfront waf?

image

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions