Encoding-Based Filter Evasion
Encoding-based filter evasion changes the representation of input so that a weak filter misses content that is later decoded by the application.
Mechanism
The application or intermediary may normalize input at a different stage than the security control, creating a mismatch between what the filter sees and what the application interprets.
Indicators to watch
Requests that decode differently across layers, repeated normalization failures, double-encoding patterns, and WAF/application disagreement.
Concept diagram
Defensive controls
Normalize before validation, validate after canonicalization, use context-aware parsing, and keep security controls aligned with application decoding behavior.
Recommended security control
WAF normalization + application logs
Use inert strings and a test application when studying parser differences.
Defense tool
The administrator has not attached a tool yet. This slot will show “Build Soon” until a link or file is configured.
All attack descriptions are for defensive education. Test scanning, traffic generation, interception, wireless testing, and vulnerable applications only on systems and networks you own or are explicitly authorized to assess.