WAFs cannot detect parameters filled with opaque data such as base64. Consequently, We've tuned our WAF to be more strong checking these inputs.
Note : in order to find login endpoint, do not use brute-force,or guessing, they won't work.
Hint : base64(jsonobject)
Action | Rating | Author team |
---|---|---|
Read writeup |
5.0
|
Balsn |
Read writeup |
3.7
|
0e85dc6eaf |
Read writeup |
4.0
|
irGeeks |