The tweet is asking if someone manually fuzzed XSS payloads to bypass a WAF, and requests good resources for WAF bypass techniques. It implies interest in techniques to bypass Web Application Firewalls specifically for Cross-Site Scripting (XSS) vulnerabilities, but does not provide any specific payload or vendor information. To respond, one could share common methods and resources for WAF bypass focused on XSS, such as encoding tricks, unusual payload structures, and using WAF testing tools.
For more insights, check out the original tweet here: https://twitter.com/11divk/status/1965396642015883421
Subscribe for the latest news: