A bypass technique for WAF using Burp Repeater has been discovered. By encoding payloads into UTF-16, attackers can bypass basic input validation. This technique can potentially evade detection by certain WAF rules. It is recommended for WAF administrators to be aware of this bypass and adjust their rules accordingly to mitigate the risk of attacks using this method.
Bypass WAF using Burp Repeater – Unicode Encoding
Encode payloads into UTF-16 to bypass basic input validation. pic.twitter.com/yOo2GHcXuw
— Gospel Chukwunonso (@cyb3rf034r3ss) February 3, 2025