wafw00f

Command-line tool that identifies and fingerprints web application firewalls in front of a site.

These buttons open the developer's own site, repository or store listing in a new tab. wares.gg does not host downloads.

About wafw00f

WAFW00F detects whether a website is protected by a web application firewall and, where possible, identifies which product it is. It sends a normal HTTP request and analyzes the response, then falls back to sending more aggressive probes to trigger and fingerprint WAF behavior when the first pass is inconclusive.

It is a Python command-line tool used during reconnaissance in security assessments, and ships with a Docker image. It is intended only for testing systems you are authorized to assess.

Strengths

  • Detects and fingerprints many WAF products
  • Escalating probes when passive detection fails
  • Docker image available

Limitations

  • Command-line only
  • Intended only for authorized testing

Details

Pricing
FreeFree and open source.
License
Open source, license not stated
Developer
Enable Security
Platforms
Windows, macOS, Linux, Command line
How it runs
Downloadable app
Account
Not required
Works offline
Yes
Best suited for
Identifying WAFs during authorized web assessments
Last verified
Added
Provenance
Facts checked against the developer's own pages and store listings, 1 sources on file.

Similar software

Related functionality, not necessarily a direct replacement.

Report a wrong fact or a dead link on this listing