Skip to content

Mitigation Bypass

Web applications often implement mitigations like input sanitization, content security policies (CSP), and encoding to prevent XSS. However, attackers can bypass these by leveraging encoding techniques, context-aware payloads, and browser-specific quirks. This section explores common mitigation bypass strategies and how to test them in a controlled environment.


Encoding Techniques to Bypass Filters

Modern XSS filters often use whitelisting or blacklisting to block known malicious patterns. Encoding payloads to evade detection is a common countermeasure.

1. Unicode and Hex Encoding

Filters may not properly decode Unicode or hex sequences. For example:

# Encode a script tag using Unicode
payload="scripte format(informat)"
curl "http://target.com?input=$payload"
This encodes <script>... as &#x73;&#x63;&#x72;&#x69;&#x70;&#x74; to bypass basic filters.

2. HTML Entity Encoding

Some filters fail to escape entities in specific contexts. For example:

<!-- Injected in a script tag -->
<script>document.write(String.fromCharCode(115, 99, 114, 105, 112, 116, 101, 32, 102, 111, 114, 109, 97, 116, 40, 105, 110, 102, 111, 114, 109, 97, 116, 41));</script>
This encodes the string script using String.fromCharCode() to bypass filters that block direct <script> tags.


Context-Aware Payloads

Filters may apply different sanitization rules depending on the injection context (e.g., HTML vs. JavaScript). Exploiting these differences can bypass mitigations.

1. Event Handlers in HTML Attributes

If a filter strips on attributes, use alternative event triggers:

<img src=x onerror=alert(1)>
If onerror is blocked, try:
<a href="javascript:alert(1)">Click me</a>
Or use CSS triggers:
<style>body::before{content:"XSS";}</style>

2. URL Parameter Encoding

When input is URL-encoded, use double encoding to bypass filters:

curl "http://target.com?input=alert%25281%2529"
This decodes to alert(1) after double decoding (%2528 → %28 → ().


Browser-Specific Vulnerabilities

Browsers handle encoding and decoding differently, creating opportunities for bypasses.

1. Unicode Bidi Attacks

Exploit Unicode right-to-left (R2L) formatting to bypass filters:

<script>document.write(String.fromCharCode(8217, 8217, 8217));</script>
This renders as ''' (Unicode U+2019), which may bypass filters that only check ASCII characters.

2. Browser Quirks with eval()

Some browsers allow eval() in certain contexts (e.g., eval(document.cookie)). Test:

eval(document.location.hash.substring(1));
If the hash is sanitized, use javascript: URLs:
<a href="javascript:alert(1)">Click</a>


Testing Mitigation Bypasses

Use tools like xsser, PayloadsAllTheThings, or custom scripts to test:

# Example: Test URL encoding bypass
curl "http://target.com?input=alert%25281%2529"
Monitor responses for unexpected behavior or script execution.


Key takeaways

  • Encoding techniques (Unicode, hex, entity encoding) can bypass filters that fail to decode properly.
  • Context-aware payloads exploit differences in sanitization rules across HTML, JavaScript, and URL contexts.
  • Browser quirks (e.g., Unicode bidi, eval() handling) provide opportunities to bypass CSP or input validation.
  • Always test in authorized environments to avoid unintended consequences.