Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

An Interesting XSS-Bypassing WAF

Summary

A web pentest case study on landing XSS past a WAF: after standard payloads were blocked, the tester studied the filter logic and crafted a custom payload that slipped through, plus mitigation advice.
Published
Collected

original ↗

Related coverage

back