Web Waf Detection

Web Application Firewall fingerprinting — Cloudflare, AWS WAF, Akamai, Imperva, etc.

purpleailab 93dd61e 1.2 KB Updated

File contents

WAF Detection & Fingerprinting

Identify any front-end shield (Cloudflare, AWS WAF, Akamai, Imperva, etc.) so exploit can choose appropriate evasion (encoding, payload obfuscation, alternate transport). A multi-proxy/CDN stack is also the recognition signal for HTTP request smuggling — note this for handoff.

Tooling

# wafw00f
wafw00f https://<target>

# Manual detection via response patterns
curl -s "https://<target>/?id=1' OR '1'='1" -I | grep -iE '(server|x-cdn|cf-ray|x-sucuri|x-aws)'

Known WAF Indicators

WAF Signal
Cloudflare CF-RAY header, __cfduid cookie
AWS WAF x-amzn-requestid header
Akamai AkamaiGHost server header
Imperva X-CDN header, incap_ses cookie
Sucuri X-Sucuri-ID header
F5 BIG-IP BIGipServer cookie

Multi-Proxy / Smuggling Signal

If the response chain shows TWO different Server: strings on subsequent requests, or a CDN front in front of an origin server with different framing, note this in the handoff under "Frontend stack" — it is the recognition signal for HTTP request smuggling routing in exploit.

purpleailab/decepticon/tree/main/packages/decepticon/decepticon/skills/standard/recon/web-recon/waf-detection commit 93dd61e7ca

Frequently asked questions

npx skillmds@latest add purpleailab/web-waf-detection