wafw00f
Web Application Firewall detection tool
TLDR
Detect WAF
SYNOPSIS
wafw00f [-l] [-a] [-v] [options] url
DESCRIPTION
wafw00f is a security tool that identifies Web Application Firewalls (WAFs) protecting websites. It works by sending specially crafted HTTP requests and analyzing the responses for signatures and behaviors characteristic of specific WAF products.
The tool can detect a wide range of commercial and open-source WAFs including Cloudflare, AWS WAF, Akamai, F5 BIG-IP, ModSecurity, Imperva, Sucuri, and many others. In its default mode it stops after identifying the first WAF, while the all-detection mode tests against every known WAF fingerprint for thorough analysis.
Multiple URLs can be tested in batch from an input file, and proxy support allows routing traffic through interception tools like Burp Suite. The tool is designed for authorized penetration testing and security assessments to help identify protection measures before deeper testing.
PARAMETERS
-l, --list
List known WAFs.-a, --findall
Test all WAFs.-i FILE
Input file.-o FILE
Output file.-v, --verbose
Verbose output.-t TEST
Specific test.-p PROXY
Use proxy.
DETECTED WAFS
Cloudflare, AWS WAF, Akamai, F5 BIG-IP, ModSecurity, Imperva, Sucuri, Fortinet, and many more.
CAVEATS
For authorized testing only. Some WAFs may block detection. False positives possible.
HISTORY
wafw00f was created for web application security testing. It helps penetration testers identify protection measures.
