WAFW00F – Fingerprint & Identify Web Application Firewall (WAF) Products

Use Netsparker


WAFW00F is a Python tool to help you fingerprint and identify Web Application Firewall (WAF) products. It is an active reconnaissance tool as it actually connects to the web server, but it starts out with a normal HTTP response and escalates as necessary.

WAFW00F - Fingerprint & Identify Web Application Firewall (WAF) Products

You can override or include your own headers, it has SOCKS and HTTP proxy support and detects a whole bunch of WAF products from hosted solutions like CloudFlare and Incapsula to server side solutions like ModSecurity.

How does it work?

To do its magic, WAFW00F does the following:

  • Sends a normal HTTP request and analyses the response; this identifies a number of WAF solutions
  • If that is not successful, it sends a number of (potentially malicious) HTTP requests and uses simple logic to deduce which WAF it is
  • If that is also not successful, it analyses the responses previously returned and uses another simple algorithm to guess if a WAF or security solution is actively responding to our attacks

What does it detect?

It detects a number of WAFs. To view which WAFs it is able to detect run WAFW00F with the -l option. At the time of writing the output is as follows:

  • Anquanbao
  • Juniper WebApp Secure
  • IBM Web Application Security
  • Cisco ACE XML Gateway
  • F5 BIG-IP APM
  • 360WangZhanBao
  • ModSecurity (OWASP CRS)
  • PowerCDN
  • Safedog
  • F5 FirePass
  • DenyALL WAF
  • Trustwave ModSecurity
  • CloudFlare
  • Imperva SecureSphere
  • Incapsula WAF
  • Citrix NetScaler
  • F5 BIG-IP LTM
  • Art of Defence HyperGuard
  • Aqtronix WebKnight
  • Teros WAF
  • eEye Digital Security SecureIIS
  • BinarySec
  • IBM DataPower
  • Microsoft ISA Server
  • NetContinuum
  • NSFocus
  • ChinaCache-CDN
  • West263CDN
  • InfoGuard Airlock
  • Barracuda Application Firewall
  • F5 BIG-IP ASM
  • Profense
  • Mission Control Application Shield
  • Microsoft URLScan
  • Applicure dotDefender
  • USP Secure Entry Server
  • F5 Trafficshield

You can download here:

wafw00f-v0.9.4.zip

Or read more here.

Posted in: Hacking Tools, Networking Hacking

, ,


Latest Posts:


BDFProxy - Patch Binaries via MITM - BackdoorFactory + mitmProxy BDFProxy – Patch Binaries via MiTM – BackdoorFactory + mitmproxy
BDFProxy allows you to patch binaries via MiTM with The Backdoor Factory combined with mitmproxy enabling on the fly patching of binary downloads
Domained - Multi Tool Subdomain Enumeration Domained – Multi Tool Subdomain Enumeration
Domained is a multi tool subdomain enumeration tool that uses several subdomain enumeration tools and wordlists to create a unique list of subdomains.
Acunetix Vulnerability Scanner For Linux Now Available Acunetix Vulnerability Scanner For Linux Now Available
Acunetix Vulnerability Scanner For Linux is now available, now you get all of the functionality of Acunetix, with all of the dependability of Linux.
Gerix WiFi Cracker - Wireless 802.11 Hacking Tool With GUI Gerix WiFi Cracker – Wireless 802.11 Hacking Tool With GUI
Gerix WiFi cracker is an easy to use Wireless 802.11 Hacking Tool with a GUI, it was originally made to run on BackTrack and this version has been updated for Kali (2018.1).
Malcom - Malware Communication Analyzer Malcom – Malware Communication Analyzer
Malcom is a Malware Communication Analyzer designed to analyze a system's network communication using graphical representations of network traffic.
WepAttack - WLAN 802.11 WEP Key Hacking Tool WepAttack – WLAN 802.11 WEP Key Hacking Tool
WepAttack is a WLAN open source Linux WEP key hacking tool for breaking 802.11 WEP keys using a wordlist based dictionary attack.


Comments are closed.