Ekultek / WhatWaf

Detect and bypass web application firewalls and protection systems
Other
2.55k stars 434 forks source link

Unknown Firewall (f70250860) #1502

Closed WhatWaf-Firewalls closed 1 year ago

WhatWaf-Firewalls commented 2 years ago

WhatWaf version: 2.0.3 Running context: /usr/local/bin/whatwaf -u **************************************** Fingerprint:

<!--
GET http://192.168.19.14 HTTP/1.1
Status code: 403
Content-Type: text/html
Connection: close
Content-Length: 1143
-->
<html><head>
<meta content="text/html; charset=utf-8" http-equiv="Content-Type"/>
<title>D盾_拦截提示</title>
<style type="text/css">
A {TEXT-DECORATION: none}
A:link {COLOR: #095899}
A:visited {COLOR: #074476}
A:hover {COLOR: #FF6600}
body,td,th {font-size: 12px;}
</style></head><body>
<table align="center" cellpadding="0" cellspacing="0" style="border: 1px outset #000;" width="400">
<tr><td bgcolor="#333333" height="24" style="border-left-width: 25px;
border-left-style: solid; border-left-color: #A80000; color: #FFF;">  
D盾_拦截提示
</td></tr><tr>
<td align="center" bgcolor="#F9F9F9" height="92" style="font-size:14px; padding:20px;" valign="middle">

[禁] id:"<font color="red">14AND 1=1 UNION ALL SELECT 1,NULL,1,'&lt;script&gt;alert(\"666\")&lt;/script&gt;',table_name FROM information_schema.tables WHERE 2&gt;1--/**/; EXEC xp_cmdshell('cat ../../../etc/passwd')</font>"

</td></tr><tr>
<td align="right" bgcolor="#CCCCCC" height="24">
<a href="#" onclick="history.back()">返回</a> |
<a href="#" onclick="window.location=window.location">当前网页</a> |
<a href="/">首页</a> 
</td></tr></table></body></html>