Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
WAF-A-MoLE — A guided mutation-based fuzzer for ML-based Web Application Firewalls | Kitploit
Tools/GitHubGitHub/avalz/waf-a-mole
WAF BypassWeb SecurityFuzzingMachine LearningAdversarial Attack
GitHubavalz/waf-a-mole

WAF-A-MoLE

A guided mutation-based fuzzer for ML-based Web Application Firewalls

View Repository
20533202 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

WAF-A-MoLE

A guided mutation-based fuzzer for ML-based Web Application Firewalls, inspired by AFL and based on the FuzzingBook by Andreas Zeller et al.

Given an input SQL injection query, it tries to produce a semantic invariant query that is able to bypass the target WAF. You can use this tool for assessing the robustness of your product by letting WAF-A-MoLE explore the solution space to find dangerous "blind spots" left uncovered by the target classifier.

Python Version License Documentation Status

Architecture

WAF-A-MoLE Architecture

WAF-A-MoLE takes an initial payload and inserts it in the payload Pool, which manages a priority queue ordered by the WAF confidence score over each payload.

During each iteration, the head of the payload Pool is passed to the Fuzzer, where it gets randomly mutated, by applying one of the available mutation operators.

Mutation operators

Mutations operators are all semantics-preserving and they leverage the high expressive power of the SQL language (in this version, MySQL).

Below are the mutation operators available in the current version of WAF-A-MoLE.

MutationExample
Case Swappingadmin' OR 1=1# ⇒ admin' oR 1=1#
Whitespace Substitutionadmin' OR 1=1# ⇒ admin'\t\rOR\n1=1#
Comment Injectionadmin' OR 1=1# ⇒ admin'/**/OR 1=1#
Comment Rewritingadmin'/**/OR 1=1# ⇒ admin'/*xyz*/OR 1=1#abc
Integer Encodingadmin' OR 1=1# ⇒ admin' OR 0x1=(SELECT 1)#
Operator Swappingadmin' OR 1=1# ⇒ admin' OR 1 LIKE 1#
Logical Invariantadmin' OR 1=1# ⇒ admin' OR 1=1 AND 0<1#
Number Shufflingadmin' OR 1=1# ⇒ admin' OR 2=2#

How to cite us

WAF-A-MoLE implements the methodology presented in "WAF-A-MoLE: Evading Web Application Firewalls through Adversarial Machine Learning". A pre-print of our article can also be found on arXiv.

If you want to cite us, please use the following (BibTeX) reference:

@inproceedings{demetrio20wafamole,
  title={WAF-A-MoLE: evading web application firewalls through adversarial machine learning},
  author={Demetrio, Luca and Valenza, Andrea and Costa, Gabriele and Lagorio, Giovanni},
  booktitle={Proceedings of the 35th Annual ACM Symposium on Applied Computing},
  pages={1745--1752},
  year={2020}
}

Running WAF-A-MoLE

Prerequisites

  • numpy
  • keras
  • scikit-learn
  • joblib
  • sqlparse
  • networkx
  • Click

Setup

pip install -r requirements.txt

Sample Usage

You can evaluate the robustness of your own WAF, or try WAF-A-MoLE against some example classifiers. In the first case, have a look at the Model class. Your custom model needs to implement this class in order to be evaluated by WAF-A-MoLE. We already provide wrappers for sci-kit learn and keras classifiers that can be extend to fit your feature extraction phase (if any).

Help

wafamole --help

Usage: wafamole [OPTIONS] COMMAND [ARGS]...

Options:
  --help  Show this message and exit.

Commands:
  evade  Launch WAF-A-MoLE against a target classifier.

wafamole evade --help

Usage: wafamole evade [OPTIONS] MODEL_PATH PAYLOAD

  Launch WAF-A-MoLE against a target classifier.

Options:
  -T, --model-type TEXT     Type of classifier to load
  -t, --timeout INTEGER     Timeout when evading the model
  -r, --max-rounds INTEGER  Maximum number of fuzzing rounds
  -s, --round-size INTEGER  Fuzzing step size for each round (parallel fuzzing
                            steps)
  --threshold FLOAT         Classification threshold of the target WAF [0.5]
  --random-engine TEXT      Use random transformations instead of evolution
                            engine. Set the number of trials
  --output-path TEXT        Location were to save the results of the random
                            engine. NOT USED WITH REGULAR EVOLUTION ENGINE
  --help                    Show this message and exit.

Evading example models

We provide some pre-trained models you can have fun with, located in wafamole/models/custom/example_models. The classifiers we used are listed in the table below.

Classifier nameAlgorithm
WafBrainRecurrent Neural Network
ML-Based-WAFNon-Linear SVM
ML-Based-WAFStochastic Gradient Descent
ML-Based-WAFAdaBoost
Token-basedNaive Bayes
Token-basedRandom Forest
Token-basedLinear SVM
Token-basedGaussian SVM
SQLiGoT - Directed ProportionalGaussian SVM
SQLiGoT - Directed UnproportionalGaussian SVM
SQLiGoT - Undirected ProportionalGaussian SVM
SQLiGoT - Undirected UnproportionalGaussian SVM

In addition to ML-based WAF, WAF-a-MoLE supports also rule-based WAFs. Specifically, it provides a wrapper for the ModSecurity WAF equipped with the OWASP Core Rule Set (CRS), based on the pymodsecurity project.

WAF-BRAIN - Recurrent Neural Newtork

Bypass the pre-trained WAF-Brain classifier using a admin' OR 1=1# equivalent.

wafamole evade --model-type waf-brain wafamole/models/custom/example_models/waf-brain.h5  "admin' OR 1=1#"

ML-Based-WAF - Non-Linear SVM (with original WAF-A-MoLE dataset)

Bypass the pre-trained ML-Based-WAF SVM classifier using a admin' OR 1=1# equivalent.

wafamole evade --model-type mlbasedwaf wafamole/models/custom/example_models/mlbasedwaf_svc.dump  "admin' OR 1=1#"

ML-Based-WAF - Non-Linear SVM (with SQLiV5/SQLiV3 datasets)

Bypass the pre-trained ML-Based-WAF SVM classifier using a admin' OR 1=1# equivalent. Note that SQLiV5 is a dataset sourced from Kaggle expanded with a series of queries generated by WAF-A-MoLE itself, as a proof of concept that WAF-A-MoLE queries can enhance the robustness of a WAF with retraining. Use mlbasedwaf_svc_sqliv3.dump to bypass the WAF trained with the original Kaggle dataset (SQLiV3).

wafamole evade --model-type mlbasedwaf wafamole/models/custom/example_models/mlbasedwaf_svc_sqliv5.dump  "admin' OR 1=1#"

ML-Based-WAF - Stochastic Gradient Descent (SGD)

Bypass the pre-trained ML-Based-WAF SGD classifier using a admin' OR 1=1# equivalent.

wafamole evade --model-type mlbasedwaf wafamole/models/custom/example_models/mlbasedwaf_sgd.dump  "admin' OR 1=1#"
Download Tool