WAF Lab PHP

This site is intentionally vulnerable and built to test WAF behavior in a controlled lab.

P1 - WAF Validation

Baseline WAF detection with request echo and raw body capture.

Open

P1 - XSS

Reflected XSS testing.

Open

P1 - Injection

SQL, command, and NoSQL style injection.

Open

P2 - Auth

Login bypass testing.

Open

P2 - Media

Unsafe file upload testing.

Open

P2 - Traversal

Path traversal testing.

Open

P2 - GraphQL

Minimal GraphQL endpoint with introspection and batching support.

Open

P3 - Protocol

HTTP method tampering and override testing.

Open

P4 - WAF Bypass

Input normalization playground.

Open

P5 - Fuzz

Boundary tests and large payload handling.

Open