{"repo":"slicingmelon/gobypass403","free":true,"listed":false,"github":"https://github.com/slicingmelon/gobypass403","clone":"git clone https://github.com/slicingmelon/gobypass403.git","description":"A powerful WAF (HTTP 403/401) and URL parser bypass tool developed in Go, designed to preserve exact URL paths and structures during testing.","language":"Go","stars":52,"topics":["403-bypass","cli","golang","path-traversal","penetration-testing","waf-bypass","websecurity","access-control-bypass","acl-bypass"],"license":"MIT","category":"security-tools","readme_excerpt":"GoByPASS403 A powerful WAF (HTTP 403/401) and URL parser bypass tool developed in Go, designed to preserve exact URL paths and structures during testing. Unlike Go's standard libraries, the tool enables true raw HTTP requests without any encoding or normalization, ensuring complete control over the request structure. This functionality is powered by a full-stack HTTP client, independent of Go's internals, and a custom URL parser. Author slicingmelon --- - GoByPASS403 - Features - Installation - Precompiled Binaries (Recommended) - Build Locally - Standard Build - GoReleaser - Usage - Standard WAF 403/401 Bypass - Find CDN Bypasses Using A List Of Hosts - Screenshots - Bypass Modules - 1. char\\ encode - 2. mid\\ paths - 3. end\\ paths - 4. path\\ prefix - 5. http\\ methods - 6. case\\ substitution - 7. nginx\\ bypasses - 8. haproxy\\ bypasses - CVE-2021-40346: HTTP Request Smuggling via Integer Overflow - CVE-2023-45539: URL Fragment ACL Bypass - 9. unicode\\ path\\ normalization - 10. unicode\\ path\\ truncation - 11. headers\\ scheme - 12. headers\\ ip - 13. headers\\ port - 14. headers\\ url - 15. headers\\ host - Findings - Findings Summary - Full Findings Database - Reproducing Findings - Curl PoC Commands - Debug Token System - Token Structure - Debug Token Usage - Token Storage and Access - Changelog - Motivation - Credits Features - Raw URL Preservation : Unlike other Go tools that use the standard net/url package which automatically normalizes and encodes URLs, GoBypass403 preserves ","default_branch":null,"files":null,"tree":[],"storefront":"/r/slicingmelon","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/slicingmelon/gobypass403/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}