Tuesday, April 1, 2025

How to test a website being protected by WAF?

Put <script>alert("123")</script> in the URL
E.g. www.abc.com/<script>alert("123")</script>


Different WAF have different block page like the following:



Print Friendly and PDF
Share/Bookmark