{"id":13844333,"url":"https://github.com/BlackFan/content-type-research","last_synced_at":"2025-07-11T22:31:39.716Z","repository":{"id":40642833,"uuid":"288361092","full_name":"BlackFan/content-type-research","owner":"BlackFan","description":"Content-Type Research","archived":false,"fork":false,"pushed_at":"2024-02-08T08:15:34.000Z","size":40,"stargazers_count":431,"open_issues_count":1,"forks_count":49,"subscribers_count":20,"default_branch":"master","last_synced_at":"2024-03-14T15:56:27.092Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"","language":null,"has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/BlackFan.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2020-08-18T05:14:31.000Z","updated_at":"2024-08-04T17:28:52.861Z","dependencies_parsed_at":"2024-08-04T17:38:54.043Z","dependency_job_id":null,"html_url":"https://github.com/BlackFan/content-type-research","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/BlackFan%2Fcontent-type-research","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/BlackFan%2Fcontent-type-research/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/BlackFan%2Fcontent-type-research/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/BlackFan%2Fcontent-type-research/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/BlackFan","download_url":"https://codeload.github.com/BlackFan/content-type-research/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":225763331,"owners_count":17520439,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-04T17:02:40.511Z","updated_at":"2025-07-11T22:31:39.701Z","avatar_url":"https://github.com/BlackFan.png","language":null,"funding_links":[],"categories":["Others"],"sub_categories":[],"readme":"# Content-Type Research\n\n## XSS\n\n[Content-Type that can be used for XSS and some related tricks](XSS.md)\n\n## CSRF\n\n\u003e **All frameworks were analyzed with disabled default token-based CSRF protection**\n\nExamples of incorrect Content-Type parsing that can be used for CSRF.  \nFor example, the ability to send an HTTP request that will be interpreted as JSON without a CORS preflight request.  \nCan be used in combination with attacks requiring boolean or array in HTTP request (PHP Type Juggling, NoSQL Injection, Prototype Pollution, ...)\n\n**Interesting results**\n * [Difference of Content-Type processing in browsers](Browsers.md)\n * [Laravel JSON Content-Type parsing](ct-tricks/Laravel.md)\n * [Laminas, Mezzio, Zend Framework JSON Content-Type parsing](ct-tricks/Mezzio.md)\n * [Wordpress JSON Content-Type parsing](ct-tricks/Wordpress.md)\n\n## WAF Bypass\n\n### Basic Idea\n\n| HTTP Request                                                                                      | Application         | WAF                                   | Result                     |\n|---------------------------------------------------------------------------------------------------|---------------------|---------------------------------------|----------------------------|\n| Content-Type: application/x-www-form-urlencoded\u003cbr\u003e\u003cbr\u003eq=' union select '1                        | ' union select 1'   | ' union select 1'                     | :heavy_minus_sign: Blocked |\n| Content-Type: application/json\u003cbr\u003e\u003cbr\u003e{\"q\":\"' \\u0075nion \\u0073elect '1\"}                         | ' union select 1'   | ' union select 1'                     | :heavy_minus_sign: Blocked |\n| Content-Type: application/x-www-form-urlencoded;/json\u003cbr\u003e\u003cbr\u003e{\"q\":\"' \\u0075nion \\u0073elect '1\"}  | ' union select 1'   | {\"q\":\"' \\u0075nion \\u0073elect '1\"}   | :heavy_check_mark: Bypass  |\n\n**Interesting results**\n * [PHP multipart boundary parsing](ct-tricks/PHP.md)\n * [Laravel JSON Content-Type parsing](ct-tricks/Laravel.md)\n * [Symfony JSON/XML Content-Type parsing](ct-tricks/Symfony.md)\n * [Laminas, Mezzio, Zend Framework JSON Content-Type parsing](ct-tricks/Mezzio.md)\n * [Flask JSON Content-Type parsing](ct-tricks/Flask.md)\n * [CherryPy multipart \u0026 JSON Content-Type parsing](ct-tricks/CherryPy.md)\n * [Express multer multipart Content-Type parsing](ct-tricks/Express_multer.md)\n * [Rails multipart \u0026 JSON Content-Type parsing](ct-tricks/Rails.md)\n\n## Programming languages / Frameworks\n\n| Name | CSRF friendly | WAF Bypass friendly |\n|------|---------------|---------------------|\n| [PHP](ct-tricks/PHP.md)                                   |                    | :heavy_check_mark: |\n| [Laravel](ct-tricks/Laravel.md)                           | :heavy_check_mark: | :heavy_check_mark: |\n| [Symfony](ct-tricks/Symfony.md)                           |                    | :heavy_check_mark: |\n| [Laminas, Mezzio, Zend](ct-tricks/Mezzio.md)              | :heavy_check_mark: | :heavy_check_mark: |\n| [Yii](ct-tricks/Yii.md)                                   | :question:         |                    |\n| [Wordpress](ct-tricks/Wordpress.md)                       | :question:         | :question:         |\n| [CakePHP](ct-tricks/CakePHP.md)                           | :question:         | :question:         |\n| [CodeIgniter](ct-tricks/CodeIgniter.md)                   | :question:         | :question:         |\n| [Django](ct-tricks/Django.md)                             | :question:         | :heavy_check_mark: |\n| [Flask](ct-tricks/Flask.md)                               |                    | :heavy_check_mark: |\n| [CherryPy](ct-tricks/CherryPy.md)                         |                    | :heavy_check_mark: |\n| [Express body-parser](ct-tricks/Express_body-parser.md)   |                    |                    |\n| [Express multer](ct-tricks/Express_multer.md)             |                    | :heavy_check_mark: |\n| [Rails](ct-tricks/Rails.md)                               |                    | :heavy_check_mark: |\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FBlackFan%2Fcontent-type-research","html_url":"https://awesome.ecosyste.ms/projects/github.com%2FBlackFan%2Fcontent-type-research","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FBlackFan%2Fcontent-type-research/lists"}