websecurity@lists.webappsec.org

The Web Security Mailing List

View all threads

Related work for WAF fingerprinting

SS
Sebastian Schinzel
Mon, Jun 27, 2011 4:03 PM

Dear all,

Does anyone know any other tools, methods, articles (in particular academic ones)
that deal with fingerprinting Web Application Firewalls (WAF)?

So far, I know WAFW00F, which fingerprints WAF products.
http://code.google.com/p/waffit/

Any other pointers?

Thanks,
Sebastian


Sebastian Schinzel, M.Sc.

Lehrstuhl für Informatik 1
IT-Sicherheitsinfrastrukturen

Am Wolfmantel 46
91058 Erlangen

Twitter: http://twitter.com/seecurity
Tel.: +49 (0) 9131 / 85-69911
Fax: +49 (0) 9131 / 85-25319
Web: http://www1.cs.fau.de/
Email: sebastian.schinzel@cs.fau.de

Dear all, Does anyone know any other tools, methods, articles (in particular academic ones) that deal with fingerprinting Web Application Firewalls (WAF)? So far, I know WAFW00F, which fingerprints WAF products. http://code.google.com/p/waffit/ Any other pointers? Thanks, Sebastian --- Sebastian Schinzel, M.Sc. Lehrstuhl für Informatik 1 IT-Sicherheitsinfrastrukturen Am Wolfmantel 46 91058 Erlangen Twitter: http://twitter.com/seecurity Tel.: +49 (0) 9131 / 85-69911 Fax: +49 (0) 9131 / 85-25319 Web: http://www1.cs.fau.de/ Email: sebastian.schinzel@cs.fau.de
YL
Yuping Li
Tue, Jun 28, 2011 4:40 AM

Hi

Maybe nmap dev group has come up a script that can accomplish this work, you
may check it out.

Regards.

On Tue, Jun 28, 2011 at 12:03 AM, Sebastian Schinzel ssc@seecurity.orgwrote:

Dear all,

Does anyone know any other tools, methods, articles (in particular academic
ones)
that deal with fingerprinting Web Application Firewalls (WAF)?

So far, I know WAFW00F, which fingerprints WAF products.
http://code.google.com/p/waffit/

Any other pointers?

Thanks,
Sebastian


Sebastian Schinzel, M.Sc.

Lehrstuhl für Informatik 1
IT-Sicherheitsinfrastrukturen

Am Wolfmantel 46
91058 Erlangen

Twitter:        http://twitter.com/seecurity
Tel.:          +49 (0) 9131 / 85-69911
Fax:            +49 (0) 9131 / 85-25319
Web:    http://www1.cs.fau.de/
Email:  sebastian.schinzel@cs.fau.de


The Web Security Mailing List

WebSecurity RSS Feed
http://www.webappsec.org/rss/websecurity.rss

Join WASC on LinkedIn http://www.linkedin.com/e/gis/83336/4B20E4374DBA

WASC on Twitter
http://twitter.com/wascupdates

websecurity@lists.webappsec.org
http://lists.webappsec.org/mailman/listinfo/websecurity_lists.webappsec.org

Hi Maybe nmap dev group has come up a script that can accomplish this work, you may check it out. Regards. On Tue, Jun 28, 2011 at 12:03 AM, Sebastian Schinzel <ssc@seecurity.org>wrote: > Dear all, > > Does anyone know any other tools, methods, articles (in particular academic > ones) > that deal with fingerprinting Web Application Firewalls (WAF)? > > So far, I know WAFW00F, which fingerprints WAF products. > http://code.google.com/p/waffit/ > > Any other pointers? > > Thanks, > Sebastian > > --- > Sebastian Schinzel, M.Sc. > > Lehrstuhl für Informatik 1 > IT-Sicherheitsinfrastrukturen > > Am Wolfmantel 46 > 91058 Erlangen > > Twitter: http://twitter.com/seecurity > Tel.: +49 (0) 9131 / 85-69911 > Fax: +49 (0) 9131 / 85-25319 > Web: http://www1.cs.fau.de/ > Email: sebastian.schinzel@cs.fau.de > > > _______________________________________________ > The Web Security Mailing List > > WebSecurity RSS Feed > http://www.webappsec.org/rss/websecurity.rss > > Join WASC on LinkedIn http://www.linkedin.com/e/gis/83336/4B20E4374DBA > > WASC on Twitter > http://twitter.com/wascupdates > > websecurity@lists.webappsec.org > http://lists.webappsec.org/mailman/listinfo/websecurity_lists.webappsec.org >