One of the barriers that prevent SQLi from occurring is WAF or Web Application Firewall.

In WAF, there is a series of patterns or signatures that check all requests to the web application server. If the request matches one of the existing signatures, it blocks the request or removes the threatening part.

We explain the different ways of bypassing WAF in different situations, and also explain at the end the features of some of the functional Tampers of the SQLMap tool.