Closed c2xusnpq6 closed 3 years ago
1) Base64 encoding should not need any tampering as WAF/IPS in between will not decode arbitrary base64-encoded parameter values
2) Will disable the possibility to use --base64
and --tamper
If you base64 encode id=' OR '1' LIKE '1
, it will show all the record, so there must be injectable?...
And I'm going to need both --base64
and --tamper between,equaltolike
to do that..
needed this, pls... ^^'' @stamparm
--tamper bug?
i need
equaltolike
to bypass the filter...