2025-07-10

<p>The Azure Front Door Web Application Firewall (WAF) has an "IP restriction" option that can be bypassed with the inclusion of an HTTP header. What's worse? This is actually expected behavior. Figure 1 - WHY???…</p>

Show more