logo

Researchers Detailed Modern WAF Bypass Techniques With Burp Suite Plugin

ID: 174edde1-3d5c-5738-9771-11797358da34

STIX ID: report--174edde1-3d5c-5738-9771-11797358da34

Feed Name: cybersecurityNews.com

Threat Score
60/100

Date Published: 2024-05-28

Date Updated: 2026-04-21

Author: Guru Baran

...
...

Security researcher Shubham Shah details practical methods for bypassing Web Application Firewalls (WAFs), highlighting a common weakness where WAFs only inspect a limited portion of request bodies and demonstrating a Burp Suite plugin (nowafpls) that automates padding to place payloads beyond inspection limits. The report also describes supporting tools and tactics—IP Rotate, Fireprox, ShadowClone, H2C smuggling, and proxying via shared certificates—that increase scale and IP variability for large-scale scanning and evasion, underscoring the need for defenders to reassess WAF deployments and inspection limits.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.