killchain-compendium/Exploits/Web/Bypass JS Filters.md

309 B

Client Filters

  • Circumvent client side filters via
    • Disable javascript
    • Use curl
curl -X POST -F "submit=<value>" -F "<file-parameter>=@<path-to-file>" <site>
* Intercept and modify incoming page via Burpsuite
* Intercept and modify upload of already loaded page via Burpsuite