wallarm/gotestwaf

Detect JSON bypass

rholden3 opened this issue · 2 comments

I was wondering if it would be possible to add support to test for the recently discovered JSON bypass

https://claroty.com/team82/research/js-on-security-off-abusing-json-based-sql-to-bypass-waf

Hi!

Thanks for your suggestion! We will add these test cases in one of the next releases.

After looking at the existing payloads, it seems that similar payloads are already present in the testcases, e.g. here.