Skip to main content

BracketConfusableTamper

Struct BracketConfusableTamper 

Source
pub struct BracketConfusableTamper;
Expand description

Bracket-confusable tamper (XSS).

Replaces ASCII < / > with Unicode confusables that look like angle brackets to a human reader (and to some HTML parsers under decoder bugs) but don’t match WAF patterns keyed on the literal ASCII bytes. Browsers don’t render these as tags, so the bypass relies on a downstream normalisation step (server-side reflection that re-encodes Unicode → ASCII, or a client-side fetch that proxy-strips Unicode). Useful in combination with html_entity for stored-XSS through admin panels that round-trip Unicode.

Trait Implementations§

Source§

impl TamperStrategy for BracketConfusableTamper

Source§

fn name(&self) -> &'static str

Returns the unique name of this tamper strategy.
Source§

fn description(&self) -> &'static str

Returns a description of what this strategy does.
Source§

fn tamper(&self, payload: &str, _context: Option<&str>) -> String

Transforms the input payload. Read more
Source§

fn aggressiveness(&self) -> f64

Returns the aggressiveness score (0.0 = mild, 1.0 = extreme).
Source§

fn tamper_with_params( &self, payload: &str, context: Option<&str>, _params: &HashMap<String, Value>, ) -> String

Transforms the input payload with custom parameters. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more