RE: Analyzing WAF before applying WAF Bypass Methods 03-16-2015, 06:31 AM
#5
(03-16-2015, 04:59 AM)D@rk1433 Wrote: So you are expert in sqli mr Brawler right. If you are i will post some challenges here in sqli try to solve them. And yes not cheating. Don't know why you are against me. That tutorial is great and always remain great. Talk to experts and ask them about their opinion on this tut. If that tutorial is garbage then tell your methods here that how you understand waf and bypass them.We all here to learn.Not to fight. Many experts like that tutorial already
What you posted is a glorified "probing" exercise... And it offers zero legitimate methods of WAF bypassing.
Below please find some of the most BASIC methods of bypassing a WAF:
- Inline Comments (/*SELECT * FROM TABLE */)
- Buffer Overflows
- URL/Hex encoding (%73elect)
- Tricking the auto-learning functions by spamming illigitamate traffic from a large numebr of hosts (botnet method)
- Keyword splitting (IE SELSELECTCT * frFROMom TABLE)
- Mixing the case of the chars (SeLEcT)
Even these methods will most likely fail against some of the commercial tools available....
References for greater learning:
http://blog.ptsecurity.com/2009/11/anoth...t-sql.html
http://www.slideshare.net/devteev/method...rewall-eng
http://www.bloombit.com/Articles/2008/05...ction.aspx
http://www.websec.ca/blog/view/Bypassing...ith_SQLMap
http://gnahackteam.wordpress.com/2012/07...g-methods/
http://www.danielmiessler.com/blog/bypas...cookie-jar


![[+]](https://sinister.li/images/modern/collapse_collapsed.png)