simple ways to cheat the waf and go on using the scanner

本文介绍了一种使用GNU tcpx代理修改扫描器数据包的方法,以绕过Web应用防火墙(WAF),实现对网站安全性的有效测试。通过调整代理返回至扫描器的包,可以将HTTP-302重定向响应更改为HTTP-200 OK响应,使不支持302响应的测试工具得以继续工作;同时,修改发送的数据包,改变扫描器的独特标识,有助于规避某些WAF的识别机制。

For some "evil" purpose,we may need to test some web-site's security.To bypass the WAF,we may need do a little things on the scanner's detect packet.

Luckily,we have the great GNU tcp proxy code in hands,so we can archive our aim easily.
Its thought is like this:

scanner<-----(modify server response)proxy program(modify scanner's packet)------->web-site

1) by modifying the proxy's return packet to scanner,we can change the web server's HTTP-302-redirect reponse to HTTP-200-OK response.So we can go on using some good web-test-tool which may don't support the 302 response well;

2) by modifying the proxy's sending packet,we can also change the scanner's unique identification.It will help us bypass some WAF's stupid identifying technique.

Isn't easy?
the code can be downloaded from:
https://github.com/thomas1390/tool/tree/master/web%20scan%20diy%20it%20a%20little
any good suggestion, tell me,and thank you.

By the way,its behavior is like the famous fiddler,but fiddler will have to break many times when every packet arrives,which may don't apply to the scanner technique.

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值