Skip to content

Using tamper capabilities for --base64= injection #4928

@RakSax

Description

@RakSax

injection

hello i have a question

Can tamper be used for parameter in base64?

POST parameter 'resp' is JSON deserializable. Do you want to inject inside? [y/N] y

time based will inject but waf is blocking it

indir


bug

by the way, when we do a scan with --base64="id", the -v parameter doesn't work -- I can't see payload

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions