The Web Application Firewall Fingerprinting Tool. Sends a normal HTTP request and analyses the response; this identifies a number of WAF solutions. If that is not successful, it sends a number of (potentially malicious) HTTP requests and uses simple logic to deduce which WAF it is. If that is also not successful, it analyses the responses previously returned and uses another simple algorithm to guess if a WAF or security solution is actively responding to our attacks. For further details, check out the source code on our main repository.
Features
- Sends a normal HTTP request and analyses the response; this identifies a number of WAF solutions
- Web Application Firewall Fingerprinting Tool
- WAFW00F allows one to identify and fingerprint Web Application Firewall (WAF) products protecting a website
- It sends a number of (potentially malicious) HTTP requests and uses simple logic to deduce which WAF it is
- It analyses the responses previously returned and uses another simple algorithm to guess if a WAF or security solution is actively responding to our attacks
Categories
Web Application Firewalls (WAF)License
BSD LicenseFollow WAFW00F
Other Useful Business Software
Build Securely on AWS with Proven Frameworks
Moving to the cloud brings new challenges. How can you manage a larger attack surface while ensuring great network performance? Turn to Fortinet’s Tested Reference Architectures, blueprints for designing and securing cloud environments built by cybersecurity experts. Learn more and explore use cases in this white paper.
Rate This Project
Login To Rate This Project
User Reviews
Be the first to post a review of WAFW00F!