WAFW00F
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
wafw00f identifies and fingerprints Web Application Firewalls (WAFs). It sends normal and malicious HTTP requests and analyzes responses to determine if a WAF is protecting the target web application.
BASIC USAGE#
wafw00f <url> # Detect WAF on target wafw00f https://example.com # HTTPS target wafw00f -a <url> # Test all WAFs (don't stop at first)
OPTIONS#
wafw00f <url> # Target URL wafw00f -a <url> # Check for all WAFs wafw00f -l # List all detectable WAFs wafw00f -i <file> # Input file with URLs wafw00f -o <file> # Output to file wafw00f -f <format> # Output format (csv, json, txt) wafw00f -p <proxy> # Use HTTP proxy wafw00f -t <timeout> # Request timeout wafw00f -H <header> # Add custom header wafw00f -v # Verbose output wafw00f -vv # Very verbose output
EXAMPLES#
# Basic WAF detection wafw00f https://example.com # Check for all WAFs (thorough) wafw00f -a https://example.com # Scan multiple targets from file wafw00f -i targets.txt -o results.json -f json # Use proxy wafw00f -p http://127.0.0.1:8080 https://example.com # Verbose scan with custom header wafw00f -v -H "X-Custom: test" https://example.com # List all detectable WAFs wafw00f -l
DETECTABLE WAFs (PARTIAL LIST)#
# Commercial WAFs: # - Cloudflare # - AWS WAF (Amazon) # - Akamai Kona Site Defender # - Imperva (SecureSphere/Incapsula) # - F5 BIG-IP ASM # - Barracuda WAF # - Citrix NetScaler AppFirewall # - Fortinet FortiWeb # - Radware AppWall # - Sucuri CloudProxy # - StackPath (previously MaxCDN) # Open Source WAFs: # - ModSecurity # - NAXSI (Nginx) # - WebKnight (IIS) # - Shadow Daemon # CDN/Cloud: # - Cloudflare # - Azure Front Door # - Google Cloud Armor # - Fastly
INTERPRETING OUTPUT#
# "The site <url> is behind <WAF>" # → WAF detected and identified # # "Generic Detection results:" # → WAF detected but not identified specifically # # "No WAF detected" # → No WAF found (or WAF is well-hidden) # # Note: Some WAFs can be configured to be stealthy
DETECTION TECHNIQUES#
# wafw00f uses multiple methods: # 1. Analyze response cookies (WAF-specific cookies) # 2. Check response headers (X-Sucuri, cf-ray, etc.) # 3. Send malicious payloads (XSS, SQLi strings) # 4. Compare normal vs. malicious request responses # 5. Analyze error pages and block pages # 6. Check for WAF-specific response codes
WAF BYPASS STRATEGIES#
# After identifying the WAF: # 1. Research known bypass techniques for that WAF # 2. Try payload encoding (URL, double-URL, Unicode) # 3. Use HTTP parameter pollution # 4. Test case variations (SeLeCt, uNiOn) # 5. Use comments in payloads (/**/SELECT) # 6. Try alternative HTTP methods # 7. Use HTTP/2 or HTTP/3 specific techniques
NOTES#
- Python-based tool - Supports 200+ WAF signatures - Safe to run (sends minimal traffic) - Some WAFs may not be detected if well-configured - Use -a flag for thorough testing - JSON output useful for automation - Actively maintained with new WAF signatures - First step before web application testing