Closed ShelbyJenkins closed 2 years ago
Looking into this right now and seems like StackPath WAF has changed their blockpage. Detecting this would require changes to the regexes in the stackpath plugin. On a MR in 30.
I pushed same fixes #166:
$ wafw00f http://jshel.be -a
______
/ \
( W00f! )
\ ____/
,, __ 404 Hack Not Found
|`-.__ / / __ __
/" _/ /_/ \ \ / /
*===* / \ \_/ / 405 Not Allowed
/ )__// \ /
/| / /---` 403 Forbidden
\\/` \ | / _ \
`\ /_\\_ 502 Bad Gateway / / \ \ 500 Internal Error
`_____``-` /_/ \_\
~ WAFW00F : v2.2.0 ~
The Web Application Firewall Fingerprinting Toolkit
[*] Checking http://jshel.be
[+] The site http://jshel.be is behind Fastly (Fastly CDN) and/or StackPath (StackPath) WAF.
[+] Generic Detection results:
[*] The site http://jshel.be seems to be behind a WAF or some sort of security solution
[~] Reason: The response was different when the request wasn't made from a browser.
Normal response code is "200", while the response code to a modified request is "403"
[~] Number of requests: 4
Fixed in #166.
Describe the bug When running wafw00f on sites I own that are protected by StackPath's WAF, wafw00f does not detect the StackPath WAF.
To Reproduce wafw00f jshel.be -> shows up as generic wafw00f milliseconds-matter.me -> shows up as Fastly wafw00f stackpath.com -> shows up as generic
Desktop (please complete the following information):
Debug output Paste the output that you get when passing
-vv
to wafw00f. Example:Additional context The milliseconds-matter site has StackPath WAF in monitor mode. The jshel.be site has it in protect mode. This is a really cool app! I work at StackPath, and am happy to help in any way I can!
Also, I'm not sure if it matters, but there are WAFs/Manufacturers on your list reselling the StackPath WAF.