<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WAF Bypass on 보안 연구 노트</title><link>https://blog.mingon.dev/tags/waf-bypass/</link><description>Recent content in WAF Bypass on 보안 연구 노트</description><generator>Hugo -- gohugo.io</generator><language>ko-KR</language><lastBuildDate>Sun, 07 Jun 2026 17:00:00 +0900</lastBuildDate><atom:link href="https://blog.mingon.dev/tags/waf-bypass/index.xml" rel="self" type="application/rss+xml"/><item><title>[Write-up] PortSwigger - Reflected XSS with event handlers and href attributes blocked</title><link>https://blog.mingon.dev/write-up/portswigger/xss/write-up-portswigger---reflected-xss-with-event-handlers-and-href-attributes-blocked/</link><pubDate>Sun, 07 Jun 2026 17:00:00 +0900</pubDate><guid>https://blog.mingon.dev/write-up/portswigger/xss/write-up-portswigger---reflected-xss-with-event-handlers-and-href-attributes-blocked/</guid><description>이벤트 핸들러와 href 속성이 차단된 환경에서 SVG animate로 링크의 href를 동적으로 javascript URL로 바꾸는 풀이</description></item><item><title>[Write-up] PortSwigger - Reflected XSS with some SVG markup allowed</title><link>https://blog.mingon.dev/write-up/portswigger/xss/write-up-portswigger---reflected-xss-with-some-svg-markup-allowed/</link><pubDate>Thu, 04 Jun 2026 18:00:00 +0900</pubDate><guid>https://blog.mingon.dev/write-up/portswigger/xss/write-up-portswigger---reflected-xss-with-some-svg-markup-allowed/</guid><description>일반적인 태그와 이벤트를 차단하는 WAF에서 허용된 SVG animateTransform 요소와 onbegin 이벤트를 찾는 Reflected XSS 풀이</description></item><item><title>[Write-up] PortSwigger - Reflected XSS into HTML context with all tags blocked except custom ones</title><link>https://blog.mingon.dev/write-up/portswigger/xss/write-up-portswigger---reflected-xss-into-html-context-with-all-tags-blocked-except-custom-ones/</link><pubDate>Thu, 04 Jun 2026 15:00:00 +0900</pubDate><guid>https://blog.mingon.dev/write-up/portswigger/xss/write-up-portswigger---reflected-xss-into-html-context-with-all-tags-blocked-except-custom-ones/</guid><description>표준 HTML 태그가 모두 차단된 환경에서 포커스 가능한 커스텀 요소와 URL fragment를 이용하는 Reflected XSS 풀이</description></item><item><title>[Write-up] PortSwigger - Reflected XSS into HTML context with most tags and attributes blocked</title><link>https://blog.mingon.dev/write-up/portswigger/xss/write-up-portswigger---reflected-xss-into-html-context-with-most-tags-and-attributes-blocked/</link><pubDate>Thu, 04 Jun 2026 12:00:00 +0900</pubDate><guid>https://blog.mingon.dev/write-up/portswigger/xss/write-up-portswigger---reflected-xss-into-html-context-with-most-tags-and-attributes-blocked/</guid><description>WAF가 허용하는 body 태그와 onresize 이벤트를 열거하고 iframe 크기 변경으로 자동 실행하는 Reflected XSS 풀이</description></item><item><title>[Write-up] PortSwigger - SQL injection with filter bypass via XML encoding</title><link>https://blog.mingon.dev/write-up/portswigger/sql-injection/write-up-portswigger---sql-injection-with-filter-bypass-via-xml-encoding/</link><pubDate>Thu, 21 May 2026 19:00:00 +0900</pubDate><guid>https://blog.mingon.dev/write-up/portswigger/sql-injection/write-up-portswigger---sql-injection-with-filter-bypass-via-xml-encoding/</guid><description>XML 입력을 파싱하기 전에 SQL 키워드를 차단하는 WAF를, 문자 엔티티 인코딩(파싱 불일치)으로 우회해 UNION 공격으로 administrator 계정 정보를 탈취하는 풀이</description></item></channel></rss>