On this page
Atomicorp WAF Rule 356137
Rule Summary
- Rule ID: 356137
- Status: Active
- Alert message: Atomicorp.com WAF Rules: Potential Open Proxy Abuse - GeoIP Country Code Mismatch of X-Forwarded-For Request Header and Client REMOTE_ADDR
- Observed CWEs: None documented
- Revision: 2.2.6
- Rule severity: Critical (2)
- Phase: 1 (request headers)
- Request surfaces: Request headers
- Rule action: block
- Logging: inherited from SecDefaultAction
Description
This rule detects behavior identified by its current alert as “Potential Open Proxy Abuse - GeoIP Country Code Mismatch of X-Forwarded-For Request Header and Client REMOTE_ADDR” in the request headers. It evaluates during the request headers phase and applies the configured blocking action.
Selected Related CVEs
This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.
No selected related public CVE research notes are currently published.