
7/12/2019 · John Graham-Cumming
What this post added
This post details a major outage caused by a single, poorly written regular expression in a WAF Managed Rule that led to global CPU exhaustion. It outlines the sequence of events, the impact on services, the challenges in responding due to internal system dependencies (Access service, control panel authentication), and the eventual rollback and re-enabling of the WAF. It also discusses the deployment process for WAF Managed Rules, contrasting it with the more cautious software release process, and includes an appendix on regular expression backtracking.