← All cheat sheets

WAFW00F

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

wafw00f identifies and fingerprints Web Application Firewalls (WAFs).
It sends normal and malicious HTTP requests and analyzes responses
to determine if a WAF is protecting the target web application.

BASIC USAGE#

wafw00f <url>                    # Detect WAF on target
wafw00f https://example.com      # HTTPS target
wafw00f -a <url>                 # Test all WAFs (don't stop at first)

OPTIONS#

wafw00f <url>                    # Target URL
wafw00f -a <url>                 # Check for all WAFs
wafw00f -l                       # List all detectable WAFs
wafw00f -i <file>                # Input file with URLs
wafw00f -o <file>                # Output to file
wafw00f -f <format>              # Output format (csv, json, txt)
wafw00f -p <proxy>               # Use HTTP proxy
wafw00f -t <timeout>             # Request timeout
wafw00f -H <header>              # Add custom header
wafw00f -v                       # Verbose output
wafw00f -vv                      # Very verbose output

EXAMPLES#

# Basic WAF detection
wafw00f https://example.com

# Check for all WAFs (thorough)
wafw00f -a https://example.com

# Scan multiple targets from file
wafw00f -i targets.txt -o results.json -f json

# Use proxy
wafw00f -p http://127.0.0.1:8080 https://example.com

# Verbose scan with custom header
wafw00f -v -H "X-Custom: test" https://example.com

# List all detectable WAFs
wafw00f -l

DETECTABLE WAFs (PARTIAL LIST)#

# Commercial WAFs:
# - Cloudflare
# - AWS WAF (Amazon)
# - Akamai Kona Site Defender
# - Imperva (SecureSphere/Incapsula)
# - F5 BIG-IP ASM
# - Barracuda WAF
# - Citrix NetScaler AppFirewall
# - Fortinet FortiWeb
# - Radware AppWall
# - Sucuri CloudProxy
# - StackPath (previously MaxCDN)

# Open Source WAFs:
# - ModSecurity
# - NAXSI (Nginx)
# - WebKnight (IIS)
# - Shadow Daemon

# CDN/Cloud:
# - Cloudflare
# - Azure Front Door
# - Google Cloud Armor
# - Fastly

INTERPRETING OUTPUT#

# "The site <url> is behind <WAF>"
#   → WAF detected and identified
#
# "Generic Detection results:"
#   → WAF detected but not identified specifically
#
# "No WAF detected"
#   → No WAF found (or WAF is well-hidden)
#
# Note: Some WAFs can be configured to be stealthy

DETECTION TECHNIQUES#

# wafw00f uses multiple methods:
# 1. Analyze response cookies (WAF-specific cookies)
# 2. Check response headers (X-Sucuri, cf-ray, etc.)
# 3. Send malicious payloads (XSS, SQLi strings)
# 4. Compare normal vs. malicious request responses
# 5. Analyze error pages and block pages
# 6. Check for WAF-specific response codes

WAF BYPASS STRATEGIES#

# After identifying the WAF:
# 1. Research known bypass techniques for that WAF
# 2. Try payload encoding (URL, double-URL, Unicode)
# 3. Use HTTP parameter pollution
# 4. Test case variations (SeLeCt, uNiOn)
# 5. Use comments in payloads (/**/SELECT)
# 6. Try alternative HTTP methods
# 7. Use HTTP/2 or HTTP/3 specific techniques

NOTES#

- Python-based tool
- Supports 200+ WAF signatures
- Safe to run (sends minimal traffic)
- Some WAFs may not be detected if well-configured
- Use -a flag for thorough testing
- JSON output useful for automation
- Actively maintained with new WAF signatures
- First step before web application testing