Top 10 winner
WAF evasion techniques
Imperva normalises a payload before matching it, so mixing a tab with a space inside an svg onload attribute, obfuscating alert through array constructors, or using the rare union distinct select syntax slips XSS and SQL injection past it. A chunked body whose declared chunk length is shorter than the data is skipped by the WAF but processed by the server.
Record
- Researcher
- @phaldrzynski and Paweł Hałdrzyński
- Published by
- blog.isec.pl
- Date
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of @phaldrzynski and Paweł Hałdrzyński, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .