Today I’ve been playing around with SQLMap’s tamper scripts which allow you to bypass protections on a WAF by altering / encoding the injected data.