wafw00f
Command-line tool that identifies and fingerprints web application firewalls in front of a site.
These buttons open the developer's own site, repository or store listing in a new tab. wares.gg does not host downloads.
About wafw00f
WAFW00F detects whether a website is protected by a web application firewall and, where possible, identifies which product it is. It sends a normal HTTP request and analyzes the response, then falls back to sending more aggressive probes to trigger and fingerprint WAF behavior when the first pass is inconclusive.
It is a Python command-line tool used during reconnaissance in security assessments, and ships with a Docker image. It is intended only for testing systems you are authorized to assess.
Strengths
- Detects and fingerprints many WAF products
- Escalating probes when passive detection fails
- Docker image available
Limitations
- Command-line only
- Intended only for authorized testing
Details
- Pricing
- FreeFree and open source.
- License
- Open source, license not stated
- Developer
- Enable Security
- Platforms
- Windows, macOS, Linux, Command line
- How it runs
- Downloadable app
- Account
- Not required
- Works offline
- Yes
- Best suited for
- Identifying WAFs during authorized web assessments
- Categories
- Network tools, Security tools, Website testing
- Last verified
- Added
- Provenance
- Facts checked against the developer's own pages and store listings, 1 sources on file.
Similar software
Related functionality, not necessarily a direct replacement.
WhatWeb
Command-line web scanner that fingerprints the technologies running on a website.
Nikto
Web server scanner for risky files, outdated software and misconfigurations.
HackerTarget WhatWeb Scan
An online scan that runs WhatWeb and Wappalyzer to fingerprint the technologies behind a website.
Nuclei
A fast vulnerability scanner driven by YAML templates contributed by thousands of security researchers.
BunkerWeb
An open-source web application firewall that runs as a reverse proxy in front of your web services.
SafeLine
A self-hosted web application firewall and reverse proxy that protects web apps from attacks.