wafep
Web Application Firewall Evaluation Project
...The WAFEP application serves as both the "attacker" website and the "target" website, and thus, should ideally be used in twin instances - one BEHIND the WAF (the defender/target website), and another before the WAF (the attacker website).
The payloads can be executed manually through the WAFEP attacker website instance by activating one test case at a time, or automatically, by using a crawling mechanism such as the one implemented in ZAP, Burpsuite, etc.
*Note*
The target website should be configured in the attacker website FIRST, by accessing: /wafep/config/change-target.jsp