client9 / client9/libinjection
libinjection bypasses
Open
- Dominant language
- C
- Stars
- 1k
- Forks
- 282
- PR merge metrics
- No merged PRs in 30d
Description
Hello Nick,
I'm terribly sorry for not contacting you directly before my Blackhat talk came out.
I was introducing sql fuzzer, which (among others) allows to easily find libinjection bypasses. Please check out the BH slides and my github for more info:
> https://www.blackhat.com/docs/us-16/materials/us-16-Ivanov-Web-Application-Firewalls-Analysis-Of-Detection-Logic.pdf
As a result, you may want to update `fingerprints.txt` with new tokens, or even change tokenizer mechanism a bit (symbols such as `*, !, <, some others` are parsed and treated wrong).
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.