Later archive addition
Abusing PHP query string parser to bypass IDS, IPS, and WAF
The article maps PHP’s normalization of query-string parameter names, including whitespace, brackets, null bytes, and encoded underscores, into application-visible keys. That parser differential lets crafted requests evade IDS, IPS, and WAF rules while reaching the intended PHP parameter, demonstrated by bypassing Suricata rules around Drupalgeddon2.
Record
- Researcher
- @AndreaTheMiddle and theMiddle
- Published by
- Secjuice
- Date
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of @AndreaTheMiddle and theMiddle, first published at the original source. Preserved copies are kept so the citation survives its host.