Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
waf-tester — A program for testing WAF functionality | Kitploit
Tools/GitHubGitHub/kpomin57/waf-tester
Vulnerability ScannersIDS/IPS EvasionAPI Security TestingWAF BypassWeb SecurityPenetration TestingMisconfigurationLearning & Education
GitHubkpomin57/waf-tester

waf-tester

A program for testing WAF functionality

View Repository
2610154 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

🛡️ WAF Tester

Enterprise WAF Evaluation Tool — Real attack payloads. Real results. Compliance-ready reports.

WAF Tester evaluates Web Application Firewalls by sending real attack payloads to a user-supplied URL and reporting whether they are blocked. Available as a Windows desktop app (Electron) and a Python CLI that runs anywhere.

WAF Tester Screenshot


⚠️ Legal Disclaimer

This tool is intended for authorized security testing only. Only use it against systems you own or have explicit written permission to test. Unauthorized testing of third-party systems may violate the Computer Fraud and Abuse Act (CFAA) and equivalent laws in your jurisdiction. The authors assume no liability for misuse.


Features

Test Coverage — 90 Tests Across 6 Suites

SuiteTestsWhat It Covers
OWASP / CWE Core44SQL injection (12 variants), XSS (10 variants), path traversal, command injection, XXE, SSRF, Log4Shell, SSTI, open redirect
Rate Limiting3Burst flood (30 concurrent), sequential flood, X-Forwarded-For IP rotation bypass
Bot Detection10sqlmap, Nikto, Nmap, Scrapy, Masscan, HeadlessChrome, python-requests, curl, empty UA, missing Accept headers
Bypass Attempts15Double URL-encoding, Unicode fullwidth, null bytes, case variation, comment obfuscation, CRLF injection, host header injection, method override, path tricks
API Security10GraphQL introspection/batch/enumeration, JWT none-algorithm & algorithm confusion, mass assignment, HTTP verb tampering, BOLA, content-type confusion
Business Logic8Negative quantity, zero-price submission, admin endpoint access, HTTP parameter pollution, account enumeration, excessive data exposure, forced browsing, privilege escalation

Compliance Mapping

Every test is tagged to one or more compliance frameworks:

  • OWASP Top 10 2021 (A01–A10)
  • CWE (Common Weakness Enumeration)
  • NIST 800-53 (SI-10, AC-3, SC-5, IA-5, etc.)
  • PCI-DSS 4.0 (Requirement 6.4)

Detection Intelligence

  • Baseline comparison — fetches a clean GET before tests run, then compares every response to reduce false positives
  • Confidence scoring — results rated HIGH, LIKELY, or UNCERTAIN rather than binary pass/fail
  • Multi-signal evaluation — status codes, WAF keyword detection, and response length divergence all factor into the verdict

Authentication Support

  • Bearer token
  • API key (custom header name)
  • Cookie / session token
  • Basic Auth (username + password)

Windows Desktop App (Electron)

Prerequisites

  • Node.js 18 or later

Run from Source

git clone https://github.com/kpomin57/waf-tester.git
cd waf-tester
npm install
npm start

Build Windows Installer

npm run build

Output appears in dist/ as both an NSIS installer and a portable .exe. No prerequisites needed on the target machine — Electron bundles its own runtime.


Python CLI Version

A single-file Python version that runs anywhere Python is available — Linux servers, CI/CD pipelines, Docker containers, WSL, or any environment where the Windows .exe is not an option.

Prerequisites

pip install rich requests

Basic Usage

python waf_tester.py --url https://target.example.com

Runs all 90 tests, prompts for authorization confirmation, prints color-coded results to the terminal, and saves both a JSON and HTML report to the current directory.

Options

FlagDescriptionDefault
--urlTarget URL (required)—
--suitesComma-separated suites to runall
--auth-typenone / bearer / apikey / cookie / basicnone
--auth-valueToken, cookie string, or API key value—
--auth-headerHeader name for API key authX-API-Key
--auth-userUsername for Basic Auth—
--auth-passPassword for Basic Auth—
--no-baselineDisable baseline comparisonoff
--no-rotate-uaDisable User-Agent rotationoff
--waf-headerSend X-WAF-Tester identification headeroff
--outputterminal, json, html (comma-separated)all three
--output-dirDirectory to save report files.
--timeoutPer-request timeout in seconds10
--proxyProxy URL for all requests (e.g. http://127.0.0.1:8080)off
--confirmSkip the authorization confirmation promptoff

Examples

# Run all suites
python waf_tester.py --url https://app.example.com

# Run OWASP and API suites only
python waf_tester.py --url https://app.example.com --suites owasp,api

# Bearer token auth
python waf_tester.py --url https://app.example.com/api \
  --auth-type bearer --auth-value eyJhbGciOiJIUzI1NiJ9...

# API key auth
python waf_tester.py --url https://app.example.com/api \
  --auth-type apikey --auth-header X-API-Key --auth-value mykey123

# Save reports to a folder, skip confirmation (CI/CD)
python waf_tester.py --url https://app.example.com \
  --output-dir ./reports --confirm

# Terminal output only — no files saved
python waf_tester.py --url https://app.example.com --output terminal

# Route traffic through Burp Suite
python waf_tester.py --url https://app.example.com --proxy http://127.0.0.1:8080

Running in Docker

docker run --rm -v $(pwd)/reports:/reports \
  python:3.12-slim sh -c \
  "pip install rich requests -q && python waf_tester.py \
   --url https://target.example.com \
   --output-dir /reports --confirm"

Running in CI/CD (GitHub Actions)

- name: WAF Evaluation
  run: |
    pip install rich requests
    python waf_tester.py \
      --url ${{ secrets.WAF_TARGET_URL }} \
      --suites owasp,api,bypass \
      --output json \
      --output-dir ./reports \
      --confirm

- name: Upload report
  uses: actions/upload-artifact@v3
  with:
    name: waf-report
    path: reports/

Burp Suite Integration

The Python CLI can route all test traffic through Burp Suite, giving you a full HTTP history of every payload WAF Tester sends. This is useful for manual inspection of requests and responses, fine-tuning payloads, troubleshooting unexpected WAF behavior, and using Burp's own scanner or repeater on interesting findings.

How it works

Burp Suite runs a local proxy listener (default 127.0.0.1:8080). When you point WAF Tester's proxy environment variables at that address, every request the tool makes passes through Burp before reaching the target. You see each payload in Burp's HTTP history with the full request and response — status code, headers, body — exactly as the WAF saw it.

Setup

1. Start Burp Suite and confirm the proxy listener is active:

Open Burp → Proxy → Proxy Settings → confirm listener is on 127.0.0.1:8080 (or note your port if different).

2. Export Burp's CA certificate and trust it (one-time setup):

WAF Tester connects to HTTPS targets, so Burp needs to intercept TLS. Go to Burp → Proxy → Proxy Settings → Import/Export CA Certificate → Export as DER. Install it as a trusted root CA on your system, or set the environment variable below to skip verification (fine for lab use, not production).

3. Run WAF Tester with --proxy:

python waf_tester.py --url https://target.example.com --proxy http://127.0.0.1:8080

On Windows:

python waf_tester.py --url https://target.example.com --proxy http://127.0.0.1:8080

You can also still use environment variables if you prefer:

HTTPS_PROXY=http://127.0.0.1:8080 HTTP_PROXY=http://127.0.0.1:8080 \
python waf_tester.py --url https://target.example.com

4. Turn off Burp's interception:

Download Tool