boolean-based-sql-injection

1 article
Sort: New Top Best
clear filter
0
bug-bounty

A bug bounty hunter documents two SQL injection vulnerabilities discovered in a private program, both protected by WAF (Web Application Firewall) that blocks requests randomly. The author develops Python scripts that exploit timing and retry logic to overcome WAF blocking mechanisms—one using repeated requests when WAF returns maintenance errors, and another using multiple retries to differentiate between WAF-generated and server-generated error responses.

mahmoudsec.blogspot.com · devanshbatham/Awesome-Bugbounty-Writeups · 5 hours ago · details