From 427d13a7b0d25e9a27a64202034126ecf492a7d0 Mon Sep 17 00:00:00 2001 From: 0xInfection Date: Fri, 29 Mar 2019 09:35:20 +0530 Subject: [PATCH] More accurate fingerprints for other WAFs --- README.md | 37 ++++++++++++++++++++++++++----------- 1 file changed, 26 insertions(+), 11 deletions(-) diff --git a/README.md b/README.md index 27d116f..87aea6f 100644 --- a/README.md +++ b/README.md @@ -308,7 +308,7 @@ Wanna fingerprint WAFs? Lets see how.
  • Request token ID with length from 20 to 25 between RequestId tag.
  • -
  • Server header field may contain awselb value.
  • +
  • Server header field contains awselb/2.0 value.
  • @@ -471,7 +471,7 @@ Wanna fingerprint WAFs? Lets see how.
  • Detectability: Moderate
  • Detection Methodology:
  • @@ -518,7 +518,6 @@ Wanna fingerprint WAFs? Lets see how.
  • Detection Methodology:
  • @@ -551,7 +550,7 @@ Wanna fingerprint WAFs? Lets see how.
  • Detectability: Moderate
  • Detection Methodology:
  • @@ -679,7 +678,7 @@ Wanna fingerprint WAFs? Lets see how.
  • Detection Methodology:
  • @@ -845,7 +844,7 @@ Wanna fingerprint WAFs? Lets see how.
  • Normal GET request headers contain visid_incap value.
  • Response headers may contain X-Iinfo header field name.
  • -
  • Set-Cookie header has cookie field incap_ses in response headers.
  • +
  • Set-Cookie header has cookie field incap_ses and visid_incap.
  • @@ -1016,7 +1015,7 @@ Wanna fingerprint WAFs? Lets see how.
  • One or more things in your request were suspicious text snippet.
  • rules of the mod_security module text snippet.
  • -
  • Response headers may contain Mod_Security or NYOB keywords.
  • +
  • Server header may contain Mod_Security or NYOB keywords.
  • @@ -1032,6 +1031,7 @@ Wanna fingerprint WAFs? Lets see how. @@ -1134,7 +1134,7 @@ Wanna fingerprint WAFs? Lets see how.
  • Detectability: Easy
  • Detection Methodology:
  • @@ -1409,9 +1409,10 @@ Wanna fingerprint WAFs? Lets see how.
  • Detectability: Difficult
  • Detection Methodology:
  • @@ -1622,6 +1623,20 @@ Wanna fingerprint WAFs? Lets see how. + + + Synology Cloud WAF + + + + + Tencent Cloud WAF @@ -1660,8 +1675,8 @@ Wanna fingerprint WAFs? Lets see how.
  • Detectability: Moderate
  • Detection Methodology: