TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

PortSwigger Research

Introducing the URL validation bypass cheat sheet

2024-09-03 · Read original ↗

ATT&CK techniques detected

2 predictions
T1027Obfuscated Files or Information
95%
“encoding : - intruder ' s percent encoding : this option encodes a payload string by replacing certain characters with one to four escape sequences that represent the utf - 8 encoding of the character. it excludes burp suite intruder ' s default characters and is enabled by defau…”
T1027Obfuscated Files or Information
40%
“numerous payloads that exploit unicode string normalization. for instance, the normalization of the following characters results in an empty string : - zerowidthspace, negativeverythinspace, negativethinspace, negativemediumspace, negativethickspace - word joiner ( u + 2060 ) ( &…”

Summary

URL validation bypasses are the root cause of numerous vulnerabilities including many instances of SSRF, CORS misconfiguration, and open redirection. These work by using ambiguous URLs to trigger URL