Web Hack List

Top 10 winner

WAF evasion techniques

Imperva normalises a payload before matching it, so mixing a tab with a space inside an svg onload attribute, obfuscating alert through array constructors, or using the rare union distinct select syntax slips XSS and SQL injection past it. A chunked body whose declared chunk length is shorter than the data is skipped by the WAF but processed by the server.

Record

Researcher
@phaldrzynski and Paweł Hałdrzyński
Published by
blog.isec.pl
Date
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of @phaldrzynski and Paweł Hałdrzyński, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .