๐Ÿงช Cortisol โ€” WAF Bypass & Normalization Stress Tester (for Red Teams)
dev.toยท3dยท
Discuss: DEV
๐Ÿ•ต๏ธPenetration Testing
Preview
Report Post

Lab Mode Only โ€” Never test without explicit written permission.

cortisol is a lightweight, offensive security CLI tool designed to stress-test web application firewalls (WAFs) by exploiting inconsistencies in URL normalization logic. It helps red teams and penetration testers identify potential bypasses for common protections against SQLi, XSS, SSRF, and Path Traversal โ€” especially when WAFs decode payloads only once, while the backend decodes them multiple times.

Inspired by real-world bug bounty findings like:

/api/v1/%2e%2e/%2e%2e/config?id=1%252bUNION%252bSELECT%252bsecrets--

cortisol automates the generation and testing of multi-encoded payloads to detect behavioral differences in WAF vs. application responses.


๐Ÿ” How It Worksโ€ฆ

Similar Posts

Loading similar posts...