Collected research
Fooling B64_Encode(Payload) on WAFs and filters
WAFs and filters that base64-decode a parameter before pattern matching can be desynchronised from the application that decodes it later. PHP's base64_decode and a Sun Java implementation skip illegal characters, so inserting a '.' into the payload made ModSecurity 2.5.6-1 and NoScript 1.9.9.61 miss an encoded script tag that the backend still decoded and executed.
Record
- Researcher
- Stefano Di Paola
- Published by
- blog.mindedsecurity.com
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Stefano Di Paola, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .