WAF-A-MoLE takes an initial payload and inserts it in the payload Pool, which manages a priority queue ordered by the WAF confidence score over each payload. During each iteration, the head of the payload Pool is passed to the Fuzzer, where it gets randomly mutated, by applying one of the available mutation operators. Mutation operators Mutations operators are all semantics-preserving and they leverage the expressive power of the target grammar. Below are the SQL mutation operators available in the current version of WAF-A-MoLE. Mutation|Example Case Swapping|admin’ OR 1=1# ⇒ admin’ oR 1=1# Whitespace Substitution|admin’ OR 1=1# ⇒ admin’\t\rOR\n1=1# Comment Injection|admin’ OR 1=1# ⇒ admin’/*<I>/OR 1=1# Comment Rewriting|admin’/</I>/OR 1=1# ⇒ admin’/xyz*/OR 1=1#abc Integer Encoding|admin’ OR 1=1# ⇒ admin’ OR 0x1=(SELECT 1)# Operator Swapping|admin’ OR 1=1# ⇒ admin’ OR 1 LIKE 1# Logical Invariant|admin’ OR 1=1# ⇒ admin’ OR 1=1 AND 0<1# Number Shuffling|admin’ OR 1=1# ⇒ admin’ OR 2=2# How to Contribute Questions, bug reports and pull requests are always welcome. In particular, if you are interested in expanding this project, we are currently interested in the following contributions: