Web Hack List

Collected research

Break the Wall from Bottom: Automated Discovery of Protocol-Level Evasion Vulnerabilities in Web Application Firewalls

WAF Manis fuzzes grammar-derived malformed HTTP requests to find parsing disagreements between a web application firewall and the backend framework: duplicate Content-Type headers, malformed multipart boundaries, encoded parameters, and transfer-encoding tricks. The 311 cases found let an attacker hide any payload from 14 WAFs.

Record

Researcher
Qi Wang, Jianjun Chen, Zheyu Jiang, Run Guo, Ximeng Liu, Chao Zhang and Haixin Duan
Published by
jianjunchen.com
Format
Whitepaper
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Qi Wang, Jianjun Chen, Zheyu Jiang, Run Guo, Ximeng Liu, Chao Zhang and Haixin Duan, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .