Not just anti-IDS also anti-proxy, anti-app-firewall, etc.
Using HTTP HEAD method instead of GET
URL Encoding the attack
Using double slashes (//cgi-bin//script) old technique
Reverse traversing attacks /cgi-bin/blabla/../script.pl
Self reference directories: /cgi-bin/./././script.pl
Premature request ending : GET Premature request ending : GET
/%20HTTP/1.0%0d%0aHeader:%20/../../cgi-bin/some.cgi HTTP/1.0\r\n\r\n
Hiding as parameters (encoding the ?)