Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


Analyzing WAF before applying WAF Bypass Methods filter_list
Author
Message
RE: Analyzing WAF before applying WAF Bypass Methods #5
(03-16-2015, 04:59 AM)D@rk1433 Wrote: So you are expert in sqli mr Brawler right. If you are i will post some challenges here in sqli try to solve them. And yes not cheating. Don't know why you are against me. That tutorial is great and always remain great. Talk to experts and ask them about their opinion on this tut. If that tutorial is garbage then tell your methods here that how you understand waf and bypass them.We all here to learn.Not to fight. Many experts like that tutorial already


What you posted is a glorified "probing" exercise... And it offers zero legitimate methods of WAF bypassing.

Below please find some of the most BASIC methods of bypassing a WAF:
  1. Inline Comments (/*SELECT * FROM TABLE */)
  2. Buffer Overflows
  3. URL/Hex encoding (%73elect)
  4. Tricking the auto-learning functions by spamming illigitamate traffic from a large numebr of hosts (botnet method)
  5. Keyword splitting (IE SELSELECTCT * frFROMom TABLE)
  6. Mixing the case of the chars (SeLEcT)

Even these methods will most likely fail against some of the commercial tools available....
References for greater learning:


http://blog.ptsecurity.com/2009/11/anoth...t-sql.html

http://www.slideshare.net/devteev/method...rewall-eng

http://www.bloombit.com/Articles/2008/05...ction.aspx

http://www.websec.ca/blog/view/Bypassing...ith_SQLMap

http://gnahackteam.wordpress.com/2012/07...g-methods/

http://www.danielmiessler.com/blog/bypas...cookie-jar

Reply





Messages In This Thread
RE: Analyzing WAF before applying WAF Bypass Methods - by Brawler - 03-16-2015, 06:31 AM