การยินยอมใช้คุกกี้

COOKIE CONSENT

เราใช้คุกกี้เพื่อปรับปรุงประสบการณ์การใช้งาน วิเคราะห์การเข้าใช้เว็บไซต์ และนำเสนอเนื้อหาที่เกี่ยวข้อง ท่านสามารถเลือกประเภทคุกกี้ที่ยินยอมได้ ดูรายละเอียดเพิ่มเติมใน ประกาศคุกกี้

Application Security

Understanding the New HTTP QUERY Method

FORTSECURE GLOBAL· 2026-09-22🛰 SANS Internet Storm Center
#Application Security#Network Security#HTTP#RFC#Web Security

The introduction of the HTTP QUERY method presents new implications for web application security and traffic inspection.

The Emergence of HTTP QUERY The IETF has introduced the 'QUERY' method as a standardized way to request resources without the side effects associated with POST or the length limitations of GET. As this protocol evolves, security teams must recognize that any new HTTP verb creates potential blind spots in existing security infrastructure. While QUERY aims to improve efficiency in data retrieval, it may not be natively understood by all legacy Web Application Firewalls (WAFs) or intrusion detection systems, potentially leading to bypasses if not configured correctly. ## Securing Against Potential Abuse For security professionals, the goal is to ensure that your infrastructure is prepared for this shift. First, audit your WAF and API gateway configurations to ensure they are explicitly aware of the QUERY method. If your security solution does not recognize this verb, it might drop the request as invalid or, worse, pass it through without inspection. We recommend updating your security policy to treat QUERY requests with the same level of scrutiny as POST or PATCH methods, enforcing strict input validation and authorization checks for every incoming query to prevent injection attacks and unauthorized data access.


แหล่งที่มา: SANS Internet Storm Center เผยแพร่ครั้งแรก: Sat, 19 Sep 2026 04:51:46 GMT บทความต้นฉบับ: อ่านต้นฉบับ

Source Attribution

แหล่งที่มา: SANS Internet Storm Center

เผยแพร่ครั้งแรก: Sat, 19 Sep 2026 04:51:46 GMT

บทความต้นฉบับ: https://isc.sans.edu/diary/rss/33352

อ่านบทความต้นฉบับ ↗
ถูกใจบทความนี้

* Facebook / LinkedIn ไม่อนุญาตให้ใส่ข้อความให้ล่วงหน้า — กดปุ่มจะคัดลอกข้อความให้ก่อน เปิดหน้าแชร์แล้ววาง (paste) ได้เลย พรีวิวการ์ดจะแสดงอัตโนมัติเมื่อวางลิงก์

← กลับไปหน้า Blog