-
Notifications
You must be signed in to change notification settings - Fork 52
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
WAF detection #69
Comments
Hi woodruffw, I just tried the tool and it is pretty quick and I want to contribute to WAF detection. |
Please do!
Sent from mobile. Please excuse my brevity.
… On Jan 19, 2020, at 9:32 AM, Karan Bansal ***@***.***> wrote:
Hi woodruffw,
I just tried the tool and it is pretty quick and I want to contribute to WAF detection.
—
You are receiving this because you authored the thread.
Reply to this email directly, view it on GitHub, or unsubscribe.
|
I’d like to jump in on this too! I have some WAF experience from doing manual audits for site clients. I’ll take a look while I’m sitting here in quarantine. |
What are everyone's thoughts on adding nmap to the stack? This would be a great tool and can open the door to other things in the future, yet will also keep this tool simple. EDIT: Answered my own question. I'm going to give this a go with NMAP and see how it works. |
I have a slight preference for not adding That being said, adding it as an optional dependency in the same way that we handle twa -n to run |
Hi woodruffw, |
@MadhuMadhavanSridhar That makes sense. I'm okay with only detecting a few (with cookies) for now -- allowing future contributors to add optional |
It might be interesting to add some Web Application Firewall detection techniques. I don't know much about WAFs, but it looks like there are some common oracles:
999 No Hacking
)Some potential resources:
nmap
script for WAF detection)The text was updated successfully, but these errors were encountered: