RedTeam
3.Web-Hacking
0.Web-proxy
BurpSuite
Bypass
Waf Bypass

General Tactics

More information ---> https://github.com/0xInfection/Awesome-WAF (opens in a new tab) (VERY GOOD) Guide to bypass many WAF (CloudFlare, aeSecure, ....)

General Option

  • Change User-Agent
    • Powerfull User Agent ---> User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36
  • Use headers to confuse server about IP:
    • Origin
    • X-Forwarded-For
    • ...