Advanced levelPremium

DoS via WAF body size — exhausting the inspection budget on Cloudflare/Akamai

How to abuse the body inspection limit in WAFs (Cloudflare 100kb, Akamai 32kb) to drain the inspection budget and force a bypass — useful both for evasion and for controlled DoS.

Gorka El BochiMay 11, 202613 min

Quick answer

When a WAF receives a body larger than it can inspect, it has two options: fail-open (pass it without inspection, the juicy case) or fail-closed (block it). But there's a third, far less documented behavior: if the attacker can force the server's response to land in the cache with a malicious payload reflected in a cookie, you turn the oversize bypass into a persistent per-victim DoS — every future request from the victim carries the cookie payload, the WAF blocks it, and the app is inaccessible to them for the cookie's TTL (1 day to 1 month). Combined with XSS for remote delivery → mass DoS + selective targeting.


1. The core concept

Setup: a WAF (Cloudflare/Akamai/AWS) protects a site. The WAF has an inspection limit:

WAFInspection limit
Cloudflare Free~8 KB
Cloudflare Pro/Businesslow default, up to 1 MB with support
Cloudflare Enterprise128 KB
AWS WAF (ALB)8 KB
AWS WAF (CloudFront)16-64 KB
Akamai~16-32 KB typically
Imperva/Incapsulaconfigurable, default ~24 KB

If the body exceeds that limit and the WAF is configured with fail-open (default in Cloudflare/AWS WAF) → the inspection is skipped, the origin receives the full request.

This, on its own, is already a bypass for classic SQLi/XSS. The DoS-via-WAF twist: if the payload is reflected in a cookie that the app returns in the Set-Cookie, the user's future requests carry that cookie and the WAF does inspect them (Headers/Cookies typically have another limit, usually lower). Once a malicious cookie is detected → the WAF blocks → the app is inaccessible.


2. The attack's components

ComponentFunction
POST endpoint with tolerated paddingPayload carrier (body inspection bypass)
Parameter the server reflects into a cookiePersistence vector
Missing CSRF protectionAllows delivery via the attacker's HTML
WAF that inspects cookies on every requestThe engine of the subsequent DoS
Long cookie TTLDuration of the per-victim DoS

Real-world: parameters like tracking_id, last_search, marketing_source, user_preference that the app stores in a persistent cookie for analytics or personalization.


Keep reading the full chain

The remaining part includes the step-by-step PoC, exploitation code and the full chain that led to impact. Available to subscribers.

Free · no account

The checklist I run on every new target

47 checks ordered by cost: first what can get you in trouble, then the cheap stuff, and finally the expensive stuff — which is where the big bounties are. I'll send it to your inbox right now.

Unsubscribe in one click, from any email.

Practice this in a lab

Dos Via Waf Size

Solve

Keep learning · free account

Save your progress, unlock advanced payloads and rank your flags.

Create account

Related articles

2,482

hunters training

62

labs from real hacks

1,629

completions

$14,790

paid out for these bugs

11 flags captured this week·Real hacks from HackerOne · YesWeHack · Bugcrowd·No commitment·Free Academy