Lab Mode Only โ€” Never test without explicit written permission.

cortisol is a lightweight, offensive security CLI tool designed to stress-test web application firewalls (WAFs) by exploiting inconsistencies in URL normalization logic. It helps red teams and penetration testers identify potential bypasses for common protections against SQLi, XSS, SSRF, and Path Traversal โ€” especially when WAFs decode payloads only once, while the backend decodes them multiple times.

Inspired by real-world bug bounty findings like:

/api/v1/%2e%2e/%2e%2e/config?id=1%252bUNION%252bSELECT%252bsecrets--

cortisol automates the generation and testing of multi-encoded payloads to detect behavioral differences in WAF vs. application responses.


๐Ÿ” How It Worksโ€ฆ

Similar Posts

Loading similar posts...

Keyboard Shortcuts

Navigation
Next / previous item
j/k
Open post
oorEnter
Preview post
v
Post Actions
Love post
a
Like post
l
Dislike post
d
Undo reaction
u
Recommendations
Add interest / feed
Enter
Not interested
x
Go to
Home
gh
Interests
gi
Feeds
gf
Likes
gl
History
gy
Changelog
gc
Settings
gs
Browse
gb
Search
/
General
Show this help
?
Submit feedback
!
Close modal / unfocus
Esc

Press ? anytime to show this help