nuclei icon indicating copy to clipboard operation
nuclei copied to clipboard

Please support obfuscated encoding and kuo z for http posts

Open hktalent opened this issue 5 months ago • 5 comments

For http post data, the ability of WAF has been enhanced

  1. If it is not Chunked or Multipart at present, perform Chunked and Multipart obfuscation encoding.
  2. It is already Chunked, perform Transfer-Encoding: compress-deflate encoding
  3. It is already Multipart. If it is regular form data, you can try to use Chunked for encoding.
  4. Of course, there is also the encoding of the url path
  5. Send data using IBM037 and utf7 encoding

I believe there are many coding methods to bypass WAF. ​ @tarunKoyalwar build_request.go

I originally wanted to try to participate, contribute, and complete this work. But I found that my energy was limited

hktalent avatar Feb 02 '24 01:02 hktalent