Researchers Detailed Modern WAF Bypass Techniques With Burp Suite Plugin
ID: 174edde1-3d5c-5738-9771-11797358da34
STIX ID: report--174edde1-3d5c-5738-9771-11797358da34
Feed Name: cybersecurityNews.com
Security researcher Shubham Shah details practical methods for bypassing Web Application Firewalls (WAFs), highlighting a common weakness where WAFs only inspect a limited portion of request bodies and demonstrating a Burp Suite plugin (nowafpls) that automates padding to place payloads beyond inspection limits. The report also describes supporting tools and tactics—IP Rotate, Fireprox, ShadowClone, H2C smuggling, and proxying via shared certificates—that increase scale and IP variability for large-scale scanning and evasion, underscoring the need for defenders to reassess WAF deployments and inspection limits.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
