Thought this might interest some of you. I wrote a few tamper scripts for sqlmap to help bypass WAFs. These scripts modify the request in a way that will try to evade being detected by the firewall, either by changing the encoding, replacing spaces for other valid characters or just doing weird things to injection.
For more details,
[
websec.ca]
[
websec.mx] (Spanish)
Edited 1 time(s). Last edit at 08/31/2011 04:54AM by Gareth Heyes.