WAF Bypass Techniques Using HTTP Standard and Web Servers’ Behavior - Soroush Dalili
OWASP AppSec EU 2018 Hacker Track - Day 2, talk 5 Although web application firewall (WAF) solutions are very useful to prevent common or automated attacks, most of them are based on blacklist approaches and are still far from perfect. This talk illustrates a number of creative techniques to smuggle and reshape HTTP requests using the strange behaviour of web servers and features such as request encoding or HTTP pipelining. These methods can come in handy when testing a website behind a WAF and can help penetration testers and bug bounty hunters to avoid drama and pain! Knowing these techniques is also beneficial for the defence team in order to design appropriate mitigation techniques. Additionally, it shows why developers should not solely rely on WAFs as the defence mechanism. Finally, an open source Burp Suite extension will be introduced that can be used to assess or bypass a WAF solution using some of the techniques discussed in this talk. The plan is to keep improving this extension with the help of the http.ninja project. Managed by the official OWASP Media Project https://www.owasp.org/index.php/OWASP...

Exploiting Unknown Browsers and Objects - Gareth Heyes

albinowax - HTTP Desync Attacks: Smashing into the Cell Next Door - DEF CON 27 Conference

Billionaire's WARNING: I'm SELLING. The Crash Is Already Here!

Passive-ish Recon Techniques by Tom Hudson

Building an AppSec Program with a Budget of $0: Beyond the OWASP Top 10 - Chris Romeo

Testing and Hacking APIs INON SHKEDY

Web Application Firewalls: Analysis of Detection Logic

n8n Tutorial – Zero to Hero Course

Beyond the OWASP Top 10 - Modern web application bugs - NDC Security 2018

Practical Web Cache Poisoning: Redefining 'Unexploitable'

Something is jamming GPS over Europe. Here's what we found

#NahamCon2024: Modern WAF Bypass Techniques on Large Attack Surfaces

System Design Explained: APIs, Databases, Caching, CDNs, Load Balancing & Production Infra

Keynote: After the AI Hype – What’s Real, and What’s Next - Richard Campbell - 2026

Reverse Proxy vs Load Balancer vs API Gateway: The Real Difference ?

Cracking the Lens: Targeting HTTP's Hidden Attack-Surface

How Do JavaScript Frameworks Impact The Security Of Applications? - Ksenia Peguero

Web Cache Entanglement: Novel Pathways to Poisoning - James Kettle (albinowax)

HTTP Desync Attacks: Request Smuggling Reborn

