Web Hack List

Collected research

WAF bypasses via 0days

Content-Type parsing differences between ModSecurity CRS and the backend let an attacker present a form-urlencoded body as XML or JSON, hiding the injection inside an XML comment that the firewall skips. Multipart quirks, an empty part and a bare newline body terminator, plus a second charset parameter selecting UTF-7, give further complete rule bypasses.

Record

Researcher
terjanq and @terjanq
Published by
Medium
Date
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of terjanq and @terjanq, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .