i was messing around with this penetration testing project lately... got stuck dealing with this super tough WAF... like, it was blocking pretty much every classic XSS payload i threw at it. tried all sorts of weird encoding tricks, played with event handlers, even dabbled in some DOM-based stuff... but this WAF? it’s like it saw everything coming! kinda frustrating...
anyway, heres my question... are there still some creative tricks out there for bypassing modern WAFs... like cloudflare, aws WAF, or akamai? stuff that actually works in the real world? i wanna know...
anyway, heres my question... are there still some creative tricks out there for bypassing modern WAFs... like cloudflare, aws WAF, or akamai? stuff that actually works in the real world? i wanna know...
