client9 / client9/libinjection

libinjection bypasses

Open
#111 4 comments 0 reactions 0 assignees View on GitHub
Dominant language
C
Stars
1k
Forks
282
PR merge metrics
No merged PRs in 30d

Description

Hello Nick,

I'm terribly sorry for not contacting you directly before my Blackhat talk came out.

I was introducing sql fuzzer, which (among others) allows to easily find libinjection bypasses. Please check out the BH slides and my github for more info:

> https://www.blackhat.com/docs/us-16/materials/us-16-Ivanov-Web-Application-Firewalls-Analysis-Of-Detection-Logic.pdf

As a result, you may want to update `fingerprints.txt` with new tokens, or even change tokenizer mechanism a bit (symbols such as `*, !, <, some others` are parsed and treated wrong).

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.