u0m3 Posted February 11, 2018 Report Posted February 11, 2018 Synopsis: The specification tells parsers to be able to parse two encodings: UTF-8 and UTF-16. Many parsers support a little bit more, but for the demonstration these two are enough. In this article you will meet a variety of XML encodings, and learn how to bypass a WAF with them. WAFs see a white noise instead of the document! Link: https://mohemiv.com/all/evil-xml/ Via: Quote