Web Hack List

Later archive addition

Abusing PHP query string parser to bypass IDS, IPS, and WAF

The article maps PHP’s normalization of query-string parameter names, including whitespace, brackets, null bytes, and encoded underscores, into application-visible keys. That parser differential lets crafted requests evade IDS, IPS, and WAF rules while reaching the intended PHP parameter, demonstrated by bypassing Suricata rules around Drupalgeddon2.

Record

Researcher
@AndreaTheMiddle and theMiddle
Published by
Secjuice
Date

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of @AndreaTheMiddle and theMiddle, first published at the original source. Preserved copies are kept so the citation survives its host.