Skip to content
KitploitKITPLOIT
StrumentiBlog
Invia
StrumentiBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

··Feed·Contatto·Privacy·© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
wafparan01d3 — Quick WAF "paranoid" Doctor Evaluation | WAFPARAN01D3 Tool | Kitploit
Strumenti/GitHubGitHub/alt3kx/wafparan01d3
Defensive ToolsScripting & AutomationConfiguration AuditingWeb SecurityPenetration Testing
GitHubalt3kx/wafparan01d3

wafparan01d3

Quick WAF "paranoid" Doctor Evaluation | WAFPARAN01D3 Tool

Vedi Repository
2464 anni faRevisionato da Kitploit

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi

Valutazione rapida del WAF "paranoid" Doctor

wafparano1d3
WAFPARAN01D3

Lo strumento di test del livello di paranoia del Web Application Firewall.
— Da alt3kx.github.io

Introduzione ai livelli di paranoia

In sostanza, il livello di paranoia (PL) consente di definire quanto sia aggressivo il Core Rule Set.
Riferimento: https://coreruleset.org/20211028/working-with-paranoia-levels/

Come funziona

  • Lo script python3 wafparan01d3.py invia richieste malevole utilizzando payload codificati collocati in diverse parti delle richieste HTTP basate su parametri GET. I risultati della valutazione vengono registrati nel file di debug wafparan01d3.log creato sulla vostra macchina.
  • Osservare il comportamento e la risposta per ogni livello di paranoia del WAF impostando diversi attacchi o payload utilizzando il livello di configurazione predefinito.
  • La PoC di seguito fornisce l'installazione e la configurazione di base da zero e riutilizza il WAF attualmente distribuito impostando un semplice "Mock" e simulando il backend.
  • I payload predefiniti disponibili erano chiamati mysql_gosecure.txt basati sulla ricerca "A Scientific Notation Bug in MySQL left AWS WAF Clients Vulnerable to SQL Injection" di gosecure disponibile qui https://www.gosecure.net/blog/2021/10/19/a-scientific-notation-bug-in-mysql-left-aws-waf-clients-vulnerable-to-sql-injection/ valutando i nostri WAF utilizzando modsecurity nei loro diversi livelli di paranoia sia in una configurazione predefinita che disabilitando diverse regole / IDs in modo scaglionato e rapido.

Approccio

  • Pentesters: ambito GreyBox con accesso limitato alla macchina Linux del WAF utilizzando una "shell" con privilegi per avviare/ricaricare e modificare i file di configurazione di Apache del WAF in ambienti DEV/STG/TEST inviando diversi payload.
  • Security Officers: prendere la migliore decisione per applicare il livello di paranoia del WAF per ogni soluzione della vostra organizzazione.
  • Blueteamers: applicazione delle regole, migliori alert, meno falsi positivi nella vostra organizzazione.
  • Integrators: eseguire una risoluzione dei problemi più approfondita e definire rapidamente il livello di paranoia del WAF adeguato personalizzando le regole o creando patch virtuali.

Prova di concetto: basata su Ubuntu 20.04.3 e OWASP Core Rule Set (CRS) v3.3.2

Riferimento: https://www.inmotionhosting.com/support/server/apache/install-modsecurity-apache-module/

Installazione iniziale

  1. Aggiorna i repository del software:
root@kitploit:~
$ sudo apt update -y && sudo apt dist-upgrade -y
  1. Installa i pacchetti essenziali:
root@kitploit:~
$ sudo apt-get install build-essential -y
  1. Installa apache2 per ubuntu (se non è già installato):
root@kitploit:~
$ sudo apt-get install apache2 -y
  1. Scarica e installa il modulo ModSecurity per Apache:
root@kitploit:~
$ sudo apt install libapache2-mod-security2 -y
  1. Installa curl per ubuntu (se non è già installato):
root@kitploit:~
$ sudo apt-get install curl vim gridsite-clients net-tools -y
  1. Riavvia il servizio Apache:
root@kitploit:~
$ sudo systemctl restart apache2
  1. Assicurati che la versione del software installato sia almeno 2.9.x:
root@kitploit:~
$ sudo apt-cache show libapache2-mod-security2

install

Configurare ModSecurity

  1. Copia e rinomina il file:
root@kitploit:~
$ sudo cp /etc/modsecurity/modsecurity.conf-recommended /etc/modsecurity/modsecurity.conf

Successivamente, cambia la modalità di rilevamento di ModSecurity. Per prima cosa, spostati nella cartella cd /etc/modsecurity
2. Modifica il file di configurazione di ModSecurity con vi, vim, emacs o nano.

root@kitploit:~
$ sudo vim /etc/modsecurity/modsecurity.conf
  1. Vicino all'inizio del file vedrai SecRuleEngine DetectionOnly. Cambia DetectionOnly in On.

Valore originale: SecRuleEngine DetectionOnly
Nuovo valore: SecRuleEngine On

modsec

  1. Salva le modifiche.
  2. Riavvia Apache:
root@kitploit:~
$ sudo systemctl restart apache2

Scaricare OWASP Core Rule Set

  1. Scarica l'ultima versione del CRS da CoreRuleSet.org/installation
root@kitploit:~
$ cd ~
$ wget https://github.com/coreruleset/coreruleset/archive/refs/tags/v3.3.2.zip
  1. Verifica il checksum, assicurati che corrisponda a quello pubblico disponibile qui: https://coreruleset.org/installation/
root@kitploit:~
$ sha1sum v3.3.2.zip && echo ProvidedChecksum
88f336ba32a89922cade11a4b8e986f2e46a97cf  v3.3.2.zip
ProvidedChecksum 

checksum

  1. Decomprimi il file zip.
root@kitploit:~
$ unzip v3.3.2.zip
  1. Sposta il file di configurazione del CRS dalla nuova directory nella tua directory ModSecurity:
root@kitploit:~
$ sudo mv coreruleset-3.3.2/crs-setup.conf.example /etc/modsecurity/crs/crs-setup.conf
  • (Opzionale ma raccomandato) Sposta la directory rules dalla nuova directory nella tua directory ModSecurity:
root@kitploit:~
$ sudo mv coreruleset-3.3.2/rules/ /etc/modsecurity/crs/
  1. Modifica il file security2.conf di Apache per assicurarti che carichi le regole di ModSecurity:
root@kitploit:~
$ sudo vim /etc/apache2/mods-enabled/security2.conf
root@kitploit:~
<IfModule security2_module>
        # Default Debian dir for modsecurity's persistent data
        SecDataDir /var/cache/modsecurity

        # Include all the *.conf files in /etc/modsecurity.
        # Keeping your local configuration in that directory
        # will allow for an easy upgrade of THIS file and
        # make your life easier
        IncludeOptional /etc/modsecurity/crs-setup.conf
        IncludeOptional /etc/modsecurity/rules/*.conf

        # Include OWASP ModSecurity CRS rules if installed
        #IncludeOptional /usr/share/modsecurity-crs/*.load
</IfModule>

secmodule

  1. Assicurati che sia il file di configurazione predefinito di ModSecurity che il nuovo file di configurazione del CRS siano elencati. Il percorso del primo file di configurazione potrebbe essere già incluso. Il secondo percorso del file dovrebbe essere dove hai spostato la directory /rules.
  2. Modifica /etc/apache2/apache2.conf
root@kitploit:~
$ sudo vim /etc/apache2/apache2.conf

Copia e incolla il seguente codice e salvalo.

root@kitploit:~
# Include list of ports to listen on
Include ports.conf

Include /etc/modsecurity/modsecurity.conf
Include /etc/modsecurity/crs/crs-setup.conf
Include /etc/modsecurity/crs/rules/*.conf

ports

Caricare i moduli Apache Rewrite e Proxy

  1. Copia i seguenti moduli. Abilita il modulo Proxy e Rewrite.
root@kitploit:~
$ cd /etc/apache2
$ sudo cp mods-available/proxy_http.load mods-enabled
$ sudo cp mods-available/proxy.load mods-enabled/
$ sudo cp mods-available/rewrite.load mods-enabled/
  1. Riavvia Apache
root@kitploit:~
$ sudo systemctl restart apache2

Aggiungere virtualhost per testare i "Mock"

  1. Aggiungi le porte, modifica /etc/apache2/ports.conf
root@kitploit:~
$ sudo vim /etc/apache2/ports.conf

Copia e incolla il seguente codice e salvalo.

root@kitploit:~
# If you just change the port or add more ports here, you will likely also
# have to change the VirtualHost statement in
# /etc/apache2/sites-enabled/000-default.conf

Listen 8080
Listen 18080

<IfModule ssl_module>
        Listen 443
</IfModule>

<IfModule mod_gnutls.c>
        Listen 443
</IfModule>

ports2

  1. Vai in /etc/apache2/sites-enabled, crea il file 001-test.conf
root@kitploit:~
$ cd /etc/apache2/sites-enabled/
$ sudo touch 001-test.conf
$ sudo vim 001-test.conf

Copia e incolla il seguente codice e salvalo.

root@kitploit:~
<VirtualHost *:8080>
        ServerName test.domain:8080

        SecRuleEngine On

        ErrorLog ${APACHE_LOG_DIR}/test_error.log
        CustomLog ${APACHE_LOG_DIR}/test_access.log combined
        SecAuditLog ${APACHE_LOG_DIR}/test_audit.log

        ProxyPass / http://127.0.0.1:18080/
        ProxyPassReverse / http://127.0.0.1:18080/
</VirtualHost>
  1. Vai in /etc/apache2/sites-enabled, crea il file 002-moc.conf
root@kitploit:~
$ cd /etc/apache2/sites-enabled/
$ sudo touch 002-moc.conf
$ sudo vim 002-moc.conf

Copia e incolla il seguente codice e salvalo.

root@kitploit:~
<VirtualHost 127.0.0.1:18080>

        ErrorLog ${APACHE_LOG_DIR}/moc_error.log
        CustomLog ${APACHE_LOG_DIR}/moc_access.log combined

        RewriteEngine On
        RewriteRule ^(.*)$ $1 [R=200,L]
</VirtualHost>
  1. Riavvia apache
root@kitploit:~
$ sudo systemctl restart apache2
  1. Crea il file wafparan01d3_rulesremove.conf all'interno di /etc/apache2/conf-enabled
root@kitploit:~
$ sudo touch /etc/apache2/conf-enabled/wafparan01d3_rulesremove.conf
  1. Ricarica Apache
root@kitploit:~
$ sudo service apache2 reload

Testa il tuo FE e BE (mock)

root@kitploit:~
Devi specificare un dominio, modifica le seguenti righe:  

Windows:
C:\Windows\System32\drivers\etc\hosts
192.168.56.106 test.domain <-- aggiungi questa riga e specifica il tuo indirizzo IP  

Linux: 
/etc/hosts
192.168.1.23 test.domain <-- aggiungi questa riga e specifica il tuo indirizzo IP 

$ curl -i -k -s -XGET http://test.domain:8080/
HTTP/1.1 200 OK
Date: Mon, 22 Nov 2021 06:31:41 GMT
Server: Apache/2.4.41 (Ubuntu)
Content-Length: 571
Content-Type: text/html; charset=iso-8859-1
Vary: Accept-Encoding

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>200 OK</title>
</head><body>
<h1>OK</h1>
<p>The server encountered an internal error or
misconfiguration and was unable to complete
your request.</p>
<p>Please contact the server administrator at 
 [no address given] to inform them of the time this error occurred,
 and the actions you performed just before this error.</p>
<p>More information about this error may be available
in the server error log.</p>
<hr>
<address>Apache/2.4.41 (Ubuntu) Server at 127.0.0.1 Port 18080</address>
</body></html>

$ curl -i -k -s -XGET http://localhost:18080/
HTTP/1.1 200 OK
Date: Mon, 22 Nov 2021 06:27:17 GMT
Server: Apache/2.4.41 (Ubuntu)
Content-Length: 571
Content-Type: text/html; charset=iso-8859-1

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>200 OK</title>
</head><body>
<h1>OK</h1>
<p>The server encountered an internal error or
misconfiguration and was unable to complete
your request.</p>
<p>Please contact the server administrator at 
 [no address given] to inform them of the time this error occurred,
 and the actions you performed just before this error.</p>
<p>More information about this error may be available
in the server error log.</p>
<hr>
<address>Apache/2.4.41 (Ubuntu) Server at localhost Port 18080</address>
</body></html>

Come si usa

Per ottenere aiuto puoi utilizzare l'opzione help. L'uso di base consiste nel passare diversi argomenti definiti.
Esempio:

root@kitploit:~
$ sudo python3 wafparan01d3.py -h 

           (                                  )   ) (       )
 (  (      ))\ )          ) (      )        ( /(( /( )\ ) ( /(
 )\))(  ( /(()/( `  )  ( /( )(  ( /(  (     )\())\()|()/( )\())
((_)()\ )(_))(_))/(/(  )(_)|()\ )(_)) )\ ) ((_)((_)\ ((_)|(_)\
_(()((_|(_)(_) _((_)_\((_)_ ((_|(_)_ _(_/( /  (_) (_)_| |__ (_)
\ V  V / _` |  _| '_ \) _` | '_/ _` | ' \)) () || |/ _` ||_ \
 \_/\_/\__,_|_| | .__/\__,_|_| \__,_|_||_| \__/ |_|\__,_|___/
                |_|

                    ~ WAFPARANO1D3 : v1.1 ~
     The Web Application Firewall Paranoia Level Test Tool.

usage: wafparan01d3.py [-h] [--run [_RUN]] [--debug [_DEBUG]] [--pl [_PARANOIALEVEL ...]] [--proxy [_PROXY]] [--payload [_PAYLOAD]] [--rules-remove [_RULESREMOVE]] [--log [_LOG]] [--domain [_DOMAIN]] [--conf-file [_CONF_FILE]]
                       [--time-sleep [_TIME_TO_SLEEP]] [--time-sleep-request [_TIME_TO_SLEEP_REQUEST]] [--desc [_DESC]] [--output-desc [_OUTPUT_DESC]]

optional arguments:
  -h, --help            show this help message and exit
  --run [_RUN]          Run script
  --debug [_DEBUG]      Debug mode
  --pl [_PARANOIALEVEL ...]
                        Define paranoia level Ex. -pl 2
  --proxy [_PROXY]      Define Proxy. Ex: http://127.0.0.1:8081
  --payload [_PAYLOAD]  Define payload file. Ex. --payload payload2.txt
  --rules-remove [_RULESREMOVE]
                        Define rules remove file. Ex. --rules-remove rules1.txt
  --log [_LOG]          Define path of the log file. Ex. --log /var/log/apache/wafparan01d3.log
  --domain [_DOMAIN]    Define your domain. Ex. --domain example.domain:8080
  --conf-file [_CONF_FILE]
                        Define configuration file. Ex. --conf-file /opt/modsecurity/crs/rules/INITIALIZATION.conf
  --time-sleep [_TIME_TO_SLEEP]
                        Sleep time per PL. Ex. --time-sleep 3
  --time-sleep-request [_TIME_TO_SLEEP_REQUEST]
                        Sleep time per Request. Ex. --time-sleep-request 3
  --desc [_DESC]        Description of the script and authors
  --output-desc [_OUTPUT_DESC]
                        Description of the output on console mode.
                                                              

Argomenti opzionali

root@kitploit:~
$ sudo python3 wafparan01d3.py -h 
	- show the help message

$ sudo python3 wafparan01d3.py --run
	- run the script with default options.

$ sudo python3 wafparan01d3.py --run --debug
	- Print every line on console.
	
$ sudo python3 wafparan01d3.py --run --pl 1
	- Run the script in assigned Paranoia Level.
	- By default runs on Paranoia Level 1, 2, 3, 4

$ sudo python3 wafparan01d3.py --run --payload file_payload2.txt
	- Define the payload file that you want to send to WAF.
	- By default takes the file mysql_gosecure.txt

$ sudo python3 wafparan01d3.py --run --rules-remove rules_removex.txt
	- Define the rules that you want to remove on GWAF.
	- Example of the file: 
		- Default 920000 920001 920002
	- By default takes the files: rules_remove1.txt, rules_remove2.txt, rules_remove3.txt, rules_remove4.txt

$ sudo python3 wafparan01d3.py --run --log /home/waf_user/paranoia.log
	- Define LOG File.
	- By default print the log on paranoia_debug.log

$ sudo python3 wafparan01d3.py --run --domain mydomain.test.com
	- Define Domain of Front End WAF.
	- By default runs over domain domain.test:8080
	
$ sudo python3 wafparan01d3.py --run --conf-file /opt/modsecurity/crs/rules/INITIALIZATION.conf
	- Define the configuration file to update the Paranoia Level
	- By default takes /etc/modsecurity/crs/rules/REQUEST-901-INITIALIZATION.conf

$ sudo python3 wafparan01d3.py --run --time-sleep 3
	- Define the time to sleep per Paranoia Level.

$ sudo python3 wafparan01d3.py --run --time-sleep-request 2
	- Define the time to sleep per request send to WAF.

$ sudo python3 wafparan01d3.py --desc
	- Print the description of the script and the authors.

Demo

Puoi provare wafparan01d3.py eseguendo l'ambiente VM (Ubuntu) che distribuisce WAF ModSecurity e 'Mock' utilizzando l'ultima versione di OWASP Core Rule Set CRS 3.3.2, valutando i livelli di paranoia di ModSecurity facilmente personalizzabili.

Per eseguire:

root@kitploit:~
$ git clone https://github.com/alt3kx/wafparan01d3.git
$ cd wafparan01d3
$ sudo python3 wafparan01d3.py --help 
root@kitploit:~
$ sudo python3 wafparan01d3.py --run

wafparan01d3_001

root@kitploit:~
$ sudo python3 wafparan01d3.py --run --debug --proxy http://192.168.56.1:8081

wafparan01d3_002

root@kitploit:~
$ sudo python3 wafparan01d3.py --run --debug --pl 1 2 --proxy http://192.168.56.1:8081 --log test.log --domain vulnerable.domain:8080 --time-sleep-request 1 --time-sleep 1 --rules-remove my_rules_remove.txt --payload my_payload.txt

wafparan01d3_003

WAF Rule Scientific Notation

https://github.com/mindhack03d/WAF-Rule-Scientific-Notation

Autori

Alex Hernandez aka (@_alt3kx_)
Jesus Huerta aka @mindhack03d

Scarica lo strumento