Last month, I presented a workshop on Web Application Firewall (WAF) bypasses at Québec's Hackfest security conference.
The workshop gather examples I came accross in various assesments of the last few years. Testers (including myself) tend to go for the more complex techniques. I am hoping it will help put the spotlight on ideas that are not encoding related.