Web Application Firewall Bypassing An Approach for Penetration Testers

Web Application Firewall Bypassing An Approach for Penetration Testers

Khalil Bijjou

published in Magdeburger Journal zur Sicherheitsforschung (2019, #17, p. 900-926)

Info

Security experts perform security assessments of web applications in order to identify vulnerabilities that could be exploited by malicious users. Web Application Firewalls add a second layer of protection to web applications in order to mitigate these vulnerabilities. The attempt to bypass Web Application Firewalls is an important aspect of a security assessment and is necessary to ensure accurate results. This thesis describes bypass techniques and offers a systematic approach for security experts on how to bypass Web Application Firewalls based on these techniques. In order to facilitate this approach a tool has been developed. The outcomes of this tool have significantly contributed to finding multiple bypasses. These bypasses will be reported to the particular Web Application Firewall vendors and will presumably improve the security level of these Web Application Firewalls.

BibTeX-Entry für mjs:Bijjou:Bypassing

 1@article{mjs:Bijjou:Bypassing,
 2  year = {2019},
 3  author = {Khalil Bijjou},
 4  title = {Web Application Firewall Bypassing},
 5  subtitle = {An Approach for Penetration Testers},
 6  journaltitle = {Magdeburger Journal zur Sicherheitsforschung},
 7  pages = {900-926},
 8  issn = {2192-4260},
 9  url = {https://d-nb.info/1202428517/34},
10  codeberg = {https://codeberg.org/0xKaishakunin/Publikationen/src/branch/main/MagdeburgerJournalSicherheitsforschung/MJS_061_Bijjou_Bypassing.pdf},
11  language = {EN},
12  issue = {1},
13  volume = {17},
14  urldate = {2019-04-05},
15  keywords = {mjsarticle ,ds19,editor,malware, web application firewalls, penetration testing, bypass techniques, ethical hacking, red team},
16  abstract = {Security experts perform security assessments of web applications in order to identify vulnerabilities that could be exploited by malicious users. Web Application Firewalls add a second layer of protection to web applications in order to mitigate these vulnerabilities. The attempt to bypass Web Application Firewalls is an important aspect of a security assessment and is necessary to ensure accurate results. This thesis describes bypass techniques and offers a systematic approach for security experts on how to bypass Web Application Firewalls based on these techniques. In order to facilitate this approach a tool has been developed. The outcomes of this tool have significantly contributed to finding multiple bypasses. These bypasses will be reported to the particular Web Application Firewall vendors and will presumably improve the security level of these Web Application Firewalls.},
17}

AsciiDoc citation commands

1. citenp:[mjs:Bijjou:Bypassing]
2. cite:[mjs:Bijjou:Bypassing]
3. bibitem[mjs:Bijjou:Bypassing]

LaTeX citation commands

1. \textcite{mjs:Bijjou:Bypassing}
2. \parencite{mjs:Bijjou:Bypassing}
3. \cite{mjs:Bijjou:Bypassing}

generated at Mon May 12 10:48:34 2025