The tweet discusses the use of JSON-Based SQL to bypass a Web Application Firewall (WAF) for SQL Injection. The specific WAF vendor is not mentioned in the tweet. JSON-Based SQL injections involve manipulating JSON objects to execute SQL injection attacks, evading WAF protections. This technique can be used to exploit vulnerabilities in web applications that process JSON data. For more details on this bypass, refer to the tweet link provided by @Claroty / N.Moshe. This technique highlights the importance of thorough testing and securing web applications against SQL injection attacks.
Abusing JSON-Based SQL to bypass WAF.https://t.co/HAuXoE63Qx
by @Claroty / N.Moshe#SQLI #Pentest #WebApplicationSecurity
— R4ven4rc (@R4ven4rc) October 28, 2024