Skip to content
KitploitKITPLOIT
HerramientasBlog
Enviar
HerramientasBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

··Feeds·Contacto·Privacidad·© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
Herramientas/GitHubGitHub/alt3kx/wafparan01d3
Defensive ToolsScripting & AutomationConfiguration AuditingWeb SecurityPenetration Testing
GitHubalt3kx/wafparan01d3

wafparan01d3

Quick WAF "paranoid" Doctor Evaluation | WAFPARAN01D3 Tool

Ver Repositorio
246hace 4 añosRevisado por Kitploit

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir

Evaluación rápida del Doctor WAF "paranoico"

wafparano1d3
WAFPARAN01D3

La herramienta de prueba del nivel de paranoia del Web Application Firewall.
— De alt3kx.github.io

Introducción a los niveles de paranoia

En esencia, el nivel de paranoia (PL) le permite definir cuán agresivo es el Core Rule Set.
Referencia: https://coreruleset.org/20211028/working-with-paranoia-levels/

Cómo funciona

  • El script en Python3 wafparan01d3.py toma solicitudes maliciosas utilizando payloads codificados colocados en diferentes partes de las solicitudes HTTP basadas en parámetros GET. Los resultados de la evaluación se registran en el archivo de depuración wafparan01d3.log creado en su máquina.
  • Observe el comportamiento y la respuesta para cada nivel de paranoia del WAF, configurando diferentes ataques o payloads mediante el nivel de configuración predeterminado.
  • La PoC que se presenta a continuación proporciona la instalación y configuración básica desde cero, y reutiliza por sí misma el WAF actualmente implementado mediante la creación de un "Mock" básico que simula el backend.
  • Los payloads predeterminados disponibles se denominaron mysql_gosecure.txt, basados en la investigación "A Scientific Notation Bug in MySQL left AWS WAF Clients Vulnerable to SQL Injection" de gosecure, disponible aquí https://www.gosecure.net/blog/2021/10/19/a-scientific-notation-bug-in-mysql-left-aws-waf-clients-vulnerable-to-sql-injection/, evaluando nuestros WAFs con modsecurity en sus diferentes niveles de paranoia, ya sea en una configuración predeterminada o deshabilitando diferentes reglas/IDs de forma escalonada y rápida.

Enfoque

  • Pentesters: alcance GreyBox con acceso limitado a la máquina Linux del WAF, utilizando una "shell" con privilegios para iniciar/recargar y editar los archivos de configuración de Apache del WAF en entornos DEV/STG/TEST, enviando diferentes payloads.
  • Secutity Officers: tome la mejor decisión para aplicar el nivel de paranoia del WAF a cada solución de su organización.
  • Blueteamers: aplicación de reglas, mejores alertas y menos falsos positivos en su organización.
  • Integrators: realice una resolución de problemas más profunda y defina rápidamente el nivel adecuado de paranoia del WAF, personalizando reglas o creando parches virtuales.

Prueba de concepto: basada en Ubuntu 20.04.3 y OWASP Core Rule Set (CRS) v3.3.2

Referencia: https://www.inmotionhosting.com/support/server/apache/install-modsecurity-apache-module/

Instalación inicial

  1. Actualice los repositorios de software:
root@kitploit:~
$ sudo apt update -y && sudo apt dist-upgrade -y
  1. Instale los paquetes esenciales:
root@kitploit:~
$ sudo apt-get install build-essential -y
  1. Instale apache2 para Ubuntu (si no está instalado):
root@kitploit:~
$ sudo apt-get install apache2 -y
  1. Descargue e instale el módulo ModSecurity de Apache:
root@kitploit:~
$ sudo apt install libapache2-mod-security2 -y
  1. Instale curl para Ubuntu (si no está instalado):
root@kitploit:~
$ sudo apt-get install curl vim gridsite-clients net-tools -y
  1. Reinicie el servicio de Apache:
root@kitploit:~
$ sudo systemctl restart apache2
  1. Asegúrese de que la versión del software instalado sea al menos 2.9.x:
root@kitploit:~
$ sudo apt-cache show libapache2-mod-security2

instalación

Configurar ModSecurity

  1. Copie y renombre el archivo:
root@kitploit:~
$ sudo cp /etc/modsecurity/modsecurity.conf-recommended /etc/modsecurity/modsecurity.conf

A continuación, cambie el modo de detección de ModSecurity. Primero, acceda a la carpeta ejecutando cd /etc/modsecurity
2. Edite el archivo de configuración de ModSecurity con vi, vim, emacs o nano.

root@kitploit:~
$ sudo vim /etc/modsecurity/modsecurity.conf
  1. Cerca de la parte superior del archivo verá SecRuleEngine DetectionOnly. Cambie DetectionOnly a On.

Valor original: SecRuleEngine DetectionOnly
Nuevo valor: SecRuleEngine On

modsec

  1. Guarde los cambios.
  2. Reinicie Apache:
root@kitploit:~
$ sudo systemctl restart apache2

Descargar OWASP Core Rule Set

  1. Descargue el último CRS desde CoreRuleSet.org/installation
root@kitploit:~
$ cd ~
$ wget https://github.com/coreruleset/coreruleset/archive/refs/tags/v3.3.2.zip
  1. Verifique la suma de verificación; asegúrese de que coincida con la disponible públicamente aquí: https://coreruleset.org/installation/
root@kitploit:~
$ sha1sum v3.3.2.zip && echo ProvidedChecksum
88f336ba32a89922cade11a4b8e986f2e46a97cf  v3.3.2.zip
ProvidedChecksum 

checksum

  1. Descomprima el archivo zip.
root@kitploit:~
$ unzip v3.3.2.zip
  1. Mueva el archivo de configuración de CRS desde el nuevo directorio a su directorio de ModSecurity:
root@kitploit:~
$ sudo mv coreruleset-3.3.2/crs-setup.conf.example /etc/modsecurity/crs/crs-setup.conf
  • (Opcional pero recomendado) Mueva el directorio de reglas desde el nuevo directorio a su directorio de ModSecurity:
root@kitploit:~
$ sudo mv coreruleset-3.3.2/rules/ /etc/modsecurity/crs/
  1. Edite su archivo security2.conf de Apache para asegurarse de que cargará las reglas de ModSecurity:
root@kitploit:~
$ sudo vim /etc/apache2/mods-enabled/security2.conf
root@kitploit:~
<IfModule security2_module>
        # Default Debian dir for modsecurity's persistent data
        SecDataDir /var/cache/modsecurity

        # Include all the *.conf files in /etc/modsecurity.
        # Keeping your local configuration in that directory
        # will allow for an easy upgrade of THIS file and
        # make your life easier
        IncludeOptional /etc/modsecurity/crs-setup.conf
        IncludeOptional /etc/modsecurity/rules/*.conf

        # Include OWASP ModSecurity CRS rules if installed
        #IncludeOptional /usr/share/modsecurity-crs/*.load
</IfModule>

secmodule

  1. Asegúrese de que tanto los archivos de configuración predeterminados de ModSecurity como los nuevos de CRS estén listados. La primera línea con la ruta del archivo conf puede ya estar incluida. La segunda ruta debe ser el lugar donde haya movido el directorio /rules.
  2. Edite /etc/apache2/apache2.conf
root@kitploit:~
$ sudo vim /etc/apache2/apache2.conf

Copie y pegue el siguiente código y guárdelo.

root@kitploit:~
# Include list of ports to listen on
Include ports.conf

Include /etc/modsecurity/modsecurity.conf
Include /etc/modsecurity/crs/crs-setup.conf
Include /etc/modsecurity/crs/rules/*.conf

ports

Cargar módulos de Apache: Rewrite y Proxy

  1. Copie los siguientes módulos. Habilite los módulos Proxy y Rewrite.
root@kitploit:~
$ cd /etc/apache2
$ sudo cp mods-available/proxy_http.load mods-enabled
$ sudo cp mods-available/proxy.load mods-enabled/
$ sudo cp mods-available/rewrite.load mods-enabled/
  1. Reinicie Apache
root@kitploit:~
$ sudo systemctl restart apache2

Agregar Virtualhosts para probar "Mocks"

  1. Agregue puertos; edite /etc/apache2/ports.conf
root@kitploit:~
$ sudo vim /etc/apache2/ports.conf

Copie y pegue el siguiente código y guárdelo.

root@kitploit:~
# If you just change the port or add more ports here, you will likely also
# have to change the VirtualHost statement in
# /etc/apache2/sites-enabled/000-default.conf

Listen 8080
Listen 18080

<IfModule ssl_module>
        Listen 443
</IfModule>

<IfModule mod_gnutls.c>
        Listen 443
</IfModule>

ports2

  1. Vaya a /etc/apache2/sites-enabled y cree el archivo 001-test.conf
root@kitploit:~
$ cd /etc/apache2/sites-enabled/
$ sudo touch 001-test.conf
$ sudo vim 001-test.conf

Copie y pegue el siguiente código y guárdelo.

root@kitploit:~
<VirtualHost *:8080>
        ServerName test.domain:8080

        SecRuleEngine On

        ErrorLog ${APACHE_LOG_DIR}/test_error.log
        CustomLog ${APACHE_LOG_DIR}/test_access.log combined
        SecAuditLog ${APACHE_LOG_DIR}/test_audit.log

        ProxyPass / http://127.0.0.1:18080/
        ProxyPassReverse / http://127.0.0.1:18080/
</VirtualHost>
  1. Vaya a /etc/apache2/sites-enabled y cree el archivo 002-moc.conf
root@kitploit:~
$ cd /etc/apache2/sites-enabled/
$ sudo touch 002-moc.conf
$ sudo vim 002-moc.conf

Copie y pegue el siguiente código y guárdelo.

root@kitploit:~
<VirtualHost 127.0.0.1:18080>

        ErrorLog ${APACHE_LOG_DIR}/moc_error.log
        CustomLog ${APACHE_LOG_DIR}/moc_access.log combined

        RewriteEngine On
        RewriteRule ^(.*)$ $1 [R=200,L]
</VirtualHost>
  1. Reinicie Apache
root@kitploit:~
$ sudo systemctl restart apache2
  1. Cree el archivo wafparan01d3_rulesremove.conf dentro de /etc/apache2/conf-enabled
root@kitploit:~
$ sudo touch /etc/apache2/conf-enabled/wafparan01d3_rulesremove.conf
  1. Recargue Apache
root@kitploit:~
$ sudo service apache2 reload

Pruebe su FE y BE (mock)

root@kitploit:~
Must be specify a domain , edit the following lines  

Windows:
C:\Windows\System32\drivers\etc\hosts
192.168.56.106 test.domain <-- add this line and specify your IP address  

Linux: 
/etc/hosts
192.168.1.23 test.domain <-- add this line and specify your IP address 

$ curl -i -k -s -XGET http://test.domain:8080/
HTTP/1.1 200 OK
Date: Mon, 22 Nov 2021 06:31:41 GMT
Server: Apache/2.4.41 (Ubuntu)
Content-Length: 571
Content-Type: text/html; charset=iso-8859-1
Vary: Accept-Encoding

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>200 OK</title>
</head><body>
<h1>OK</h1>
<p>The server encountered an internal error or
misconfiguration and was unable to complete
your request.</p>
<p>Please contact the server administrator at 
 [no address given] to inform them of the time this error occurred,
 and the actions you performed just before this error.</p>
<p>More information about this error may be available
in the server error log.</p>
<hr>
<address>Apache/2.4.41 (Ubuntu) Server at 127.0.0.1 Port 18080</address>
</body></html>

$ curl -i -k -s -XGET http://localhost:18080/
HTTP/1.1 200 OK
Date: Mon, 22 Nov 2021 06:27:17 GMT
Server: Apache/2.4.41 (Ubuntu)
Content-Length: 571
Content-Type: text/html; charset=iso-8859-1

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>200 OK</title>
</head><body>
<h1>OK</h1>
<p>The server encountered an internal error or
misconfiguration and was unable to complete
your request.</p>
<p>Please contact the server administrator at 
 [no address given] to inform them of the time this error occurred,
 and the actions you performed just before this error.</p>
<p>More information about this error may be available
in the server error log.</p>
<hr>
<address>Apache/2.4.41 (Ubuntu) Server at localhost Port 18080</address>
</body></html>

Cómo usarlo

Para obtener ayuda, puede utilizar la opción help. El uso básico consiste en pasar los diferentes argumentos definidos.
Ejemplo:

root@kitploit:~
$ sudo python3 wafparan01d3.py -h 

           (                                  )   ) (       )
 (  (      ))\ )          ) (      )        ( /(( /( )\ ) ( /(
 )\))(  ( /(()/( `  )  ( /( )(  ( /(  (     )\())\()|()/( )\())
 ((_)()\ )(_))(_))/(/(  )(_)|()\ )(_)) )\ ) ((_)((_)\ ((_)|(_)\
_(()((_|(_)(_) _((_)_\((_)_ ((_|(_)_ _(_/( /  (_) (_)_| |__ (_)
\ V  V / _` |  _| '_ \) _` | '_/ _` | ' \)) () || |/ _` ||_ \
 \_/\_/\__,_|_| | .__/\__,_|_| \__,_|_||_| \__/ |_|\__,_|___/
                |_|

                    ~ WAFPARANO1D3 : v1.1 ~
     The Web Application Firewall Paranoia Level Test Tool.

usage: wafparan01d3.py [-h] [--run [_RUN]] [--debug [_DEBUG]] [--pl [_PARANOIALEVEL ...]] [--proxy [_PROXY]] [--payload [_PAYLOAD]] [--rules-remove [_RULESREMOVE]] [--log [_LOG]] [--domain [_DOMAIN]] [--conf-file [_CONF_FILE]]
                       [--time-sleep [_TIME_TO_SLEEP]] [--time-sleep-request [_TIME_TO_SLEEP_REQUEST]] [--desc [_DESC]] [--output-desc [_OUTPUT_DESC]]

optional arguments:
  -h, --help            show this help message and exit
  --run [_RUN]          Run script
  --debug [_DEBUG]      Debug mode
  --pl [_PARANOIALEVEL ...]
                        Define paranoia level Ex. -pl 2
  --proxy [_PROXY]      Define Proxy. Ex: http://127.0.0.1:8081
  --payload [_PAYLOAD]  Define payload file. Ex. --payload payload2.txt
  --rules-remove [_RULESREMOVE]
                        Define rules remove file. Ex. --rules-remove rules1.txt
  --log [_LOG]          Define path of the log file. Ex. --log /var/log/apache/wafparan01d3.log
  --domain [_DOMAIN]    Define your domain. Ex. --domain example.domain:8080
  --conf-file [_CONF_FILE]
                        Define configuration file. Ex. --conf-file /opt/modsecurity/crs/rules/INITIALIZATION.conf
  --time-sleep [_TIME_TO_SLEEP]
                        Sleep time per PL. Ex. --time-sleep 3
  --time-sleep-request [_TIME_TO_SLEEP_REQUEST]
                        Sleep time per Request. Ex. --time-sleep-request 3
  --desc [_DESC]        Description of the script and authors
  --output-desc [_OUTPUT_DESC]
                        Description of the output on console mode.
                                                              

Argumentos opcionales

root@kitploit:~
$ sudo python3 wafparan01d3.py -h 
	- show the help message

$ sudo python3 wafparan01d3.py --run
	- run the script with default options.

$ sudo python3 wafparan01d3.py --run --debug
	- Print every line on console.
	
$ sudo python3 wafparan01d3.py --run --pl 1
	- Run the script in assigned Paranoia Level.
	- By default runs on Paranoia Level 1, 2, 3, 4

$ sudo python3 wafparan01d3.py --run --payload file_payload2.txt
	- Define the payload file that you want to send to WAF.
	- By default takes the file mysql_gosecure.txt

$ sudo python3 wafparan01d3.py --run --rules-remove rules_removex.txt
	- Define the rules that you want to remove on GWAF.
	- Example of the file: 
		- Default 920000 920001 920002
	- By default takes the files: rules_remove1.txt, rules_remove2.txt, rules_remove3.txt, rules_remove4.txt

$ sudo python3 wafparan01d3.py --run --log /home/waf_user/paranoia.log
	- Define LOG File.
	- By default print the log on paranoia_debug.log

$ sudo python3 wafparan01d3.py --run --domain mydomain.test.com
	- Define Domain of Front End WAF.
	- By default runs over domain domain.test:8080
	
$ sudo python3 wafparan01d3.py --run --conf-file /opt/modsecurity/crs/rules/INITIALIZATION.conf
	- Define the configuration file to update the Paranoia Level
	- By default takes /etc/modsecurity/crs/rules/REQUEST-901-INITIALIZATION.conf

$ sudo python3 wafparan01d3.py --run --time-sleep 3
	- Define the time to sleep per Paranoia Level.

$ sudo python3 wafparan01d3.py --run --time-sleep-request 2
	- Define the time to sleep per request send to WAF.

$ sudo python3 wafparan01d3.py --desc
	- Print the description of the script and the authors.

Demostraciones

Puede probar wafparan01d3.py ejecutando el entorno de máquina virtual (Ubuntu) que implementa el WAF ModSecurity y el 'Mock' usando el último OWASP Core Rule Set CRS 3.3.2, evaluando los niveles de paranoia de ModSecurity de forma fácilmente personalizable.

Para ejecutar:

root@kitploit:~
$ git clone https://github.com/alt3kx/wafparan01d3.git
$ cd wafparan01d3
$ sudo python3 wafparan01d3.py --help 
root@kitploit:~
$ sudo python3 wafparan01d3.py --run

wafparan01d3_001

root@kitploit:~
$ sudo python3 wafparan01d3.py --run --debug --proxy http://192.168.56.1:8081

wafparan01d3_002

root@kitploit:~
$ sudo python3 wafparan01d3.py --run --debug --pl 1 2 --proxy http://192.168.56.1:8081 --log test.log --domain vulnerable.domain:8080 --time-sleep-request 1 --time-sleep 1 --rules-remove my_rules_remove.txt --payload my_payload.txt

wafparan01d3_003

WAF Rule Scientific Notation

https://github.com/mindhack03d/WAF-Rule-Scientific-Notation

Autores

Alex Hernandez aka (@_alt3kx_)
Jesus Huerta aka @mindhack03d

Descargar herramienta