| name | performing-web-application-firewall-bypass |
| description | Bypass Web Application Firewall protections using encoding techniques, HTTP method manipulation, parameter pollution, and payload obfuscation to deliver SQL injection, XSS, and other attack payloads past WAF detection rules. Use when working with performing web application firewall bypass. |
| domain | cybersecurity |
| tags | ["waf-bypass","waf-evasion","sql-injection","xss","payload-obfuscation","encoding-bypass","web-security"] |
| subdomain | web-application-security |
| version | 1.0 |
| author | oyi77 |
| license | Apache-2.0 |
| nist_csf | ["PR.PS-01","ID.RA-01","PR.DS-10","DE.CM-01"] |
Performing Web Application Firewall Bypass
Overview
Cybersecurity skill for performing web application firewall bypass. Follows industry best practices and security standards.
When to Use
Trigger phrases:
-
"performing web application firewall bypass"
-
"Bypass Web Application Firewall protections using encoding techniques, HTTP meth"
-
When confirmed vulnerabilities are blocked by WAF signature-based detection
-
During penetration testing where WAF prevents exploitation of known issues
-
When evaluating WAF rule effectiveness against evasion techniques
-
During red team engagements requiring bypass of perimeter security controls
-
When testing custom WAF rules for completeness and bypass resistance
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- Burp Suite Professional with SQLMap integration
- wafw00f for WAF fingerprinting and identification
- SQLMap with tamper scripts for automated WAF bypass
- Understanding of WAF detection mechanisms (signature, regex, behavioral)
- Collection of encoding and obfuscation techniques per attack type
- Knowledge of HTTP protocol nuances exploitable for evasion
Workflow
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> dict:
return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}