Dojo Logo
Python3

WAF Bypass - Casefolding

drag_indicator
info
drag_indicator
inputs
drag_indicator
inspect

WAF Bypass - Casefolding

Description

The firewall will detect and block script tags.

Goal

Abuse the sanitization process to perform cross-site scripting (XSS) by breaking context and calling this blind XSS file: "https://xss0r.com/resources/x.txt".

Credits Original DOJO Lab concept by https://x.com/Brumens2https://x.com/Brumens2

Hints

Solution

drag_indicator
waf
INPUT
OUTPUT
drag_indicator
code
drag_indicator
result