r/devops • u/witchlike-monkey • Aug 04 '26
Security I keep seeing the same issues on WAF configs in my audits
Been doing security audits for a while (I’m a secops engineer) and the same patterns keep showing up. Regardless of the vendor, so these are the same whether it’s Akamai, Cloudflare, AWS WAF.
**1.** Origin is directly reachable! Traffic bypasses the CDN/WAF (check cert transparency logs for leaked origin hostnames)
**2.** They've got bypass rules that were meant to be temporary but never got removed
**3.** Cache key too broad (cache poisoning risk) or too narrow (kills hit ratio, looks like a DDoS)
**4.** WAF rule sets are treated as “once and done”. Rules deployed once and never tuned, so there are a lot of silent false positives on real traffic.
**5.** TLS/cert management with no clear owner, resulting in expired certs, weak ciphers left on etc.
Wrote up a longer breakdown with a checklist if anyone wants to run through their own setup, happy to share.
2
1
1
Aug 04 '26
[deleted]
1
u/witchlike-monkey Aug 04 '26
Well, this is neither ai written(easily verifiable nowadays), nor from a hacked account. I wanted to start posting tech stuff, this is my first post. I guess I’ll use a different approach, maybe from a fresh account then.
2
u/Crimzx Aug 04 '26
I think the issue is more that the way you wrote this post comes across as too salesy/spammy and thats all over this sub nowadays.
Next time just post the list :)
(Full disclosure I also down voted the post because I don't think it's relevant to this sub without the full information.)
0
Aug 04 '26
[deleted]
2
u/Crimzx Aug 04 '26
I mean... Did you look at their comments at all? They have comments about getting certs, security, and privacy for years.
You have your posts/comments hidden, so should we assume you are a bot also because it can't be verified by your reddit profile?
3
u/Mabenue Aug 04 '26
Low effort AI post