Web Hack List

Collected research

Fooling B64_Encode(Payload) on WAFs and filters

WAFs and filters that base64-decode a parameter before pattern matching can be desynchronised from the application that decodes it later. PHP's base64_decode and a Sun Java implementation skip illegal characters, so inserting a '.' into the payload made ModSecurity 2.5.6-1 and NoScript 1.9.9.61 miss an encoded script tag that the backend still decoded and executed.

Record

Researcher
Stefano Di Paola
Published by
blog.mindedsecurity.com
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Stefano Di Paola, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .