WAFW00F:Web应用防火墙指纹工具。

发送一个正常的HTTP请求,并分析响应;这将确定一些WAF解决方案。
如果不成功,它就发送一些(可能是恶意的)HTTP请求,并使用简单的逻辑来推断它是哪个WAF。
如果这也不成功,它就会分析之前返回的响应,并使用另一种简单的算法来猜测是否有WAF或安全解决方案在主动响应我们的攻击。
使用方法:
wafw00f https://example.org
支持多种WAF检测,让你更容易绕过WAF
wafw00f -l______\( Woof! )\ ____/ )) (_- _______ ( |__||==|_______) .)|__|(' /|\ ( |__|/ ) / | \ . |__|/ | \ |__|WAFW00F : v2.1.0 ~The Web Application Firewall Fingerprinting ToolkitCan test for these WAFs:WAF Name Manufacturer------------ACE XML Gateway CiscoaeSecure aeSecureAireeCDN AireeAirlock Phion/ErgonAlert Logic Alert LogicAliYunDun Alibaba Cloud ComputingAnquanbao AnquanbaoAnYu AnYu TechnologiesApproach ApproachAppWall RadwareArmor Defense ArmorArvanCloud ArvanCloudGeneric MicrosoftASPA Firewall ASPA Engineering Co.Astra Czar SecuritiesAWS Elastic Load Balancer AmazonAzionCDN AzionCDNAzure Front Door MicrosoftBarikode Ethic NinjaBarracuda Barracuda NetworksBekchy Faydata Technologies Inc.Beluga CDN BelugaLocal Traffic Manager F5 NetworksBinarySec BinarySecBitNinja BitNinjaBlockDoS BlockDoSBluedon Bluedon ISTBulletProof Security Pro AITpro SecurityCacheWall VarnishCacheFly CDN CacheFlyComodo cWatch Comodo CyberSecurityCdnNS Application Gateway CdnNs/WdidcNetChinaCache Load Balancer ChinaCacheChuang Yu Shield YunaqCloudbric Penta SecurityCloudflare Cloudflare Inc.Cloudfloor Cloudfloor DNSCloudfront AmazonCrawlProtect Jean-Denis BrunDataPower IBMDenyALL Rohde & Schwarz CyberSecurityDistil Distil NetworksDOSarrest DOSarrest Internet SecurityDotDefender Applicure TechnologiesDynamicWeb Injection Check DynamicWebEdgecast Verizon Digital MediaEisoo Cloud Firewall EisooExpression Engine EllisLabAppSec Manager F5 NetworksAP Manager F5 NetworksFastly Fastly CDNFirePass F5 NetworksFortiWeb FortinetGoDaddy Website Protection GoDaddyGreywizard Grey WizardHuawei Cloud Firewall HuaweiHyperGuard Art of DefenseImunify360 CloudLinuxIncapsula Imperva Inc.IndusGuard IndusfaceInstart DX Instart LogicISA Server MicrosoftJanusec Application Gateway JanusecJiasule JiasuleKona SiteDefender AkamaiKnownSecKeyCDN KeyCDNLimeLight CDN LimeLightLiteSpeed LiteSpeed TechnologiesLua Nginx FLOSSOracle Cloud OracleMalcare InactivMaxCDN MaxCDNMission Control Shield Mission ControlModSecurity SpiderLabsNAXSI NBS SystemsNemesida PentestItNevisProxy AdNovumNetContinuum Barracuda NetworksNetScaler AppFirewall Citrix SystemsNewdefend NewDefendNexusGuard Firewall NexusGuardNinjaFirewall NinTechNetNullDDoS Protection NullDDoSNSFocus NSFocus Global Inc.OnMessage Shield BlackBaudPalo Alto Next Gen Firewall Palo Alto NetworksPerimeterX PerimeterXPentaWAF Global Network ServicespkSecurity IDS pkSecPT Application Firewall Positive TechnologiesPowerCDN PowerCDNProfense ArmorLogicPuhui PuhuiQcloud Tencent CloudQiniu Qiniu CDNReblaze ReblazeRSFirewall RSJoomla!RequestValidationMode MicrosoftSabre Firewall SabreSafe3 Web Firewall Safe3Safedog SafeDogSafeline Chaitin Tech.SecKing SecKingeEye SecureIIS BeyondTrustSecuPress WP Security SecuPressSecureSphere Imperva Inc.Secure Entry United Security ProvidersSEnginx NeusoftServerDefender VP Port80 SoftwareShield Security One Dollar PluginShadow Daemon ZecureSiteGround SiteGroundSiteGuard Sakura Inc.Sitelock TrueShieldSonicWall DellUTM Web Protection SophosSquarespace SquarespaceSquidProxy IDS SquidProxyStackPath StackPathSucuri CloudProxy Sucuri Inc.Tencent Cloud Firewall Tencent TechnologiesTeros Citrix SystemsTrafficshield F5 NetworksTransIP Web Firewall TransIPURLMaster SecurityCheck iFinity/DotNetNukeURLScan MicrosoftUEWaf UCloudVarnish OWASPViettel CloudrityVirusDie VirusDie LLCWallarm Wallarm Inc.WatchGuard WatchGuard TechnologiesWebARX WebARX Security SolutionsWebKnight AQTRONIXWebLand WebLandRayWAF WebRay SolutionsWebSEAL IBMWebTotem WebTotemWest263 CDN West263CDNWordfence DefiantWP Cerber Security Cerber TechWTS360WangZhanBao 360 TechnologiesXLabs Security WAF XLabsXuanwudun XuanwudunYundun YundunYunsuo YunsuoYunjiasu Baidu Cloud ComputingYXLink YxLink TechnologiesZenedge ZenedgeZScaler Accenture
项目地址:https://github.com/EnableSecurity/wafw00f
文章来源: Khan安全团队
seo优化_前端开发_渗透技术








