Bypass Cheat Sheets
Technique-first bypass references across 28 classes - the "what's the trick for X" lookups, searchable and copyable.
Bypass Cheat Sheets index
- 403 / Access-control bypass - When a path returns 401/403, try to reach it another way. Path-normalization disagreements between the edge (Nginx/HAProxy/CDN) and the app, plus trusted-header quirks, are the reliable wins on modern stacks.
- WAF evasion (Cloudflare / Akamai / AWS) - Get a payload past signature-based WAFs. The JSON-SQLi and encoding-layer tricks below still bypass major WAFs; stack transforms with the Transform bench on /utils/.
- SSRF filter bypass - Defeat allow-list / blocklist URL validation to reach internal or cloud-metadata endpoints. IP-format tricks and parser confusion are the highest-yield.
- SQLi filter / quote bypass - Get injection working when quotes, spaces or keywords are filtered. Confirm and weaponise with sqlmap's tamper scripts once a candidate responds.
- XSS bypass (by sink) - Modern frameworks (React/Angular/Vue) auto-escape text, so the wins are unescaped attribute/href/src sinks, dangerous APIs, and framework-specific gadgets. Pick by where your input lands and what's filtered.
- SSTI by engine - Detect the engine with the math polyglot, then use the engine-specific chain to RCE. {{7*7}}→49 = Jinja2/Twig family; {{7*'7'}}→7777777 distinguishes Jinja2 from Twig.
- LFI / path-traversal bypass - Read files when naive traversal is filtered, then escalate. PHP filter chains are the modern, upload-free path to RCE; null-byte truncation is legacy (flagged below).
- Rate-limit bypass - Get more attempts than the limiter intends - essential for brute-force, OTP and coupon/voucher abuse.
- CORS misconfiguration - Find an origin the server will trust with credentials. Confirm with the CSP/CORS checks on /utils/.
- LLM guardrail / prompt-filter bypass - Get an instruction past an LLM's safety/instruction filter. Guardrails are probabilistic classifiers, not a boundary - obfuscation, context-shifting, and indirect delivery defeat them. Frame findings around the downstream sink or tool the injection reaches, not the filtered word itself. For authorized AI-scope testing only.
- JWT header / key tricks - The payload is a distraction. The header is the attack: alg, kid, jku, x5u, and whether the server fetches a key you control.
- OAuth redirect_uri / flow tricks - Allowlists that are string-prefix checks, leftover implicit flow, and open redirects on an allowed origin.
- MFA skip / race / tamper - The UI is not the enforcement point. Hit the session issuer, the mobile API, and the OTP counter.
- CSP bypass gadgets - You already have a reflection. These are why it still executes.
- Cache key / deception bypass - Make the CDN store a response the next user should never see, or store your poison under a popular key.
- Double encoding / unicode - WAF decodes once, app decodes twice. Or the WAF is ASCII-brained and the app is UTF-8.
- Host / forwarded header - Password reset, cache, and absolute URL generation. Try every forwarded header the proxy might trust.
- Cloud metadata SSRF - You already have a server-side fetch. These are the destinations and the header gadgets for IMDS.
- Frame-ancestors / XFO gaps - The sensitive page is the one that matters. Marketing sites are almost always framable and almost never in scope as a finding.
- Request body parsing differences - Compare how the edge and application handle a documented request when its body is valid, malformed, duplicated, or sent with an alternate supported media type. Use only harmless fields and owned records.
- Upload validation boundaries - Assess whether uploads are constrained by extension, content signature, storage location, retrieval headers, and authorization. Use tiny inert fixtures and an account you control; never upload executable or active content.
- GraphQL authorization and batching - UI hide is not schema hide. Aliases, batch, and node(id) skip the screen the designer drew.
- XXE parser still fetches - Prove the parser resolves an external identifier with a canary. Do not file-read or hit metadata first.
- HTTP desync probes - Front-end vs origin disagreement on CL vs TE. Detect with a harmless timeout or echo. Do not poison other users.
- Limit and uniqueness races - If it should happen once, send it twice in one RTT. Two sessions you own.
- SAML ACS and wrapping - Test on an IdP/SP pair you control or a program test tenant. Signature wrapping and Recipient mismatch are parser bugs.
- CSRF token and Origin gaps - Cookie-auth state change without a token the browser cannot set. SameSite=Lax is not the whole story.
- IDOR object and verb swap - Two accounts. Every verb. Hidden fields and batch IDs are the usual miss.