Web Hack List

Later archive addition

Web Application Firewall bypass with Bash variables

The article demonstrates evading command-injection filters by using Bash parameter expansion and built-in environment variables to synthesize blocked characters and commands. Payloads that contain no obvious spaces or forbidden strings are reconstructed by the shell after a web application firewall has approved them.

Record

Researcher
@AndreaTheMiddle and theMiddle
Published by
Secjuice
Date

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of @AndreaTheMiddle and theMiddle, first published at the original source. Preserved copies are kept so the citation survives its host.