On this page

Atomicorp WAF Rule 356137

Rule Summary

  • Rule ID: 356137
  • Status: Active
  • Alert message: Atomicorp.com WAF Rules: Potential Open Proxy Abuse - GeoIP Country Code Mismatch of X-Forwarded-For Request Header and Client REMOTE_ADDR
  • Observed CWEs: None documented
  • Revision: 2.2.6
  • Rule severity: Critical (2)
  • Phase: 1 (request headers)
  • Request surfaces: Request headers
  • Rule action: block
  • Logging: inherited from SecDefaultAction

Description

This rule detects behavior identified by its current alert as “Potential Open Proxy Abuse - GeoIP Country Code Mismatch of X-Forwarded-For Request Header and Client REMOTE_ADDR” in the request headers. It evaluates during the request headers phase and applies the configured blocking action.

This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.

No selected related public CVE research notes are currently published.