Lua-Nginx WAFs Bypass#3316
Conversation
Lua-Nginx WAFs doesn't support processing for more than 100 parameters. https://www.youtube.com/watch?v=JUvro7cqidY
|
We don't accept merge requests without standard header that can be found in all sqlmap python files. As a matter of recognition we can add you to the |
Update header.
|
After a second look: A) I am a known BOFH and I don't like the quality of this code. There are many things that would require a rewriting (I can do this, but you have to take a look at B). |
|
That's fine, I will change the tamper header and you can modify the code whatever it takes. This is the page where the vulnerability is being talked about: Thank you so much! |
|
Done the modifications at my side. First I'll merge your version completely into the HEAD and then do the after-commit in a minute |
|
@j4ckmln please pull the latest revision and try to run it with |
|
Thank you! This is an example about the modifications result: This must be the result: Example: |
|
How have you run it? I guess with When I am running with a regular |
|
p.s. I'll fix the URI case (which I guess you've tried), but need to know if that was really the case at your place |
|
With latest revision your usage case should work too (with custom injection marking inside the URI itself (e.g. |
|
Yes, that was the problem. |
Lua-Nginx WAFs doesn't support processing for more than 100 parameters.
https://www.youtube.com/watch?v=JUvro7cqidY