oss-sec mailing list archives
Re: Open Source WAF testing tools
From: Ivan Novikov <in () wallarm com>
Date: Sun, 16 May 2021 12:29:32 -0700
Hi Martin, We made GoTestWAF with no any vendor-specific things. It's mainly cover OWASP Top-10 and API data encodings such as REST/JSON, SOAP/XML, GraphQL, and WebSockets since the latest versions. You can add your payloads as easy as making Yaml files. At the end of the last year, it was significantly improved by community detects https://github.com/wallarm/gotestwaf/pull/29 , thanks Vulners team and a https://github.com/waf-bypass-maker/waf-community-bypasses project. We are actively working on the project and any advice or suggestions in a form of GitHub issue or pull-requests will be highly appreciated. Have a great weekend everyone! On Sun, May 16, 2021 at 12:07 PM Martin O'Neil <martinoneil.cyber () gmail com> wrote:
Hi, list, Does anybody know an open-source tool for testing Web Application Firewalls? In an ideal case, with an out-of-the-box-ready CLI/UI, PDF reports, and a configurable set of payloads to test. I need it to check if my WAF deployment and rules work well. I found at least 5 projects, all made by WAF vendors. 1. https://github.com/wallarm/gotestwaf byWallarm 2. https://github.com/signalsciences/waf-testing-framework by Signal Sciences 3. https://github.com/fastly/ftw by Fastly 4. https://microsoft.github.io/WAFBench/ by Microsoft Azure WAF team 5. https://github.com/f5devcentral/f5-waf-tester by F5 The GoTestWAF project looks more active and supported by the community. Does anybody recommend some other GitHub repositories, preferably made by 3rd party folks? Thanks Martin.
-- Ivan Novikov Wallarm, CEO +1.650.454.9339
Current thread:
- Open Source WAF testing tools Martin O'Neil (May 16)
- Re: Open Source WAF testing tools Brandon Perry (May 16)
- Re: Open Source WAF testing tools Ivan Novikov (May 16)