Published onMarch 27, 2026Bypassing WAF Method Blocks with X-HTTP-Method-OverrideCyber-SecurityBug-BountyWAF-BypassWeb-SecurityHow an OPTIONS request with x-http-method-override can bypass blocked GET/POST methods, and how defenders can shut it down
Published onMarch 23, 2026Bypassing Imperva Incapsula WAF with a Cookie Jar OverflowCyber-SecurityBug-BountyWAF-BypassWeb-SecurityHow a cookie jar overflow attack allowed me to completely bypass Imperva Incapsula's reese84 token validation