From 5bff99159273de16b91cbf0a81006cd50032cdec Mon Sep 17 00:00:00 2001 From: 0xInfection Date: Mon, 18 Mar 2019 20:57:01 +0530 Subject: [PATCH] Added more fingerprints to precisely detect firewalls --- README.md | 131 +++++++++++++++++++++++++++++++++++------------------- 1 file changed, 85 insertions(+), 46 deletions(-) diff --git a/README.md b/README.md index b1ddb93..753a3e8 100644 --- a/README.md +++ b/README.md @@ -88,10 +88,10 @@ Wanna fingerprint WAFs? Lets see how. @@ -127,6 +127,30 @@ Wanna fingerprint WAFs? Lets see how.
  • AL-SESS cookie field name (case insensitive).
  • AL-LB value (case insensitive).
  • +
  • Blocked response page contains:
  • + + + + + + + + AlertLogic Firewall + + + @@ -145,6 +169,7 @@ Wanna fingerprint WAFs? Lets see how.
  • Sorry, your request has been blocked as it may cause potential threats to the server's security text snippet.
  • Reference to errors.aliyun.com site URL.
  • +
  • Blocked response code returned is 405.
  • @@ -165,22 +190,6 @@ Wanna fingerprint WAFs? Lets see how. - - - Armor Defense - - - - - Application Security Manager (F5 Networks) @@ -208,12 +217,31 @@ Wanna fingerprint WAFs? Lets see how. + + + + + + Armor Defense + + + @@ -259,7 +287,8 @@ Wanna fingerprint WAFs? Lets see how.
  • Access Denied in their keyword.
  • Request token ID with length from 20 to 25 between RequestId tag.
  • - + +
  • Server header field may contain awselb value.
  • @@ -309,6 +338,11 @@ Wanna fingerprint WAFs? Lets see how.
  • Response cookies may contain barra_counter_session value.
  • Response headers may contain barracuda_ keyword.
  • +
  • Response page contains:
  • + @@ -357,6 +391,7 @@ Wanna fingerprint WAFs? Lets see how.
  • Security check by BitNinja text snippet.
  • your IP will be removed from BitNinja.
  • Visitor anti-robot validation text snippet.
  • +
  • (You will be challenged by a reCAPTCHA page) text.
  • @@ -430,7 +465,25 @@ Wanna fingerprint WAFs? Lets see how.
  • Detectability: Easy
  • Detection Methodology:
  • + + + + + + Cerber (WordPress) + + + @@ -485,14 +538,18 @@ Wanna fingerprint WAFs? Lets see how. - Cloudbric + Cloudbric Firewall @@ -524,7 +581,7 @@ Wanna fingerprint WAFs? Lets see how.
  • Detectability: Easy
  • Detection Methodology:
  • @@ -538,7 +595,7 @@ Wanna fingerprint WAFs? Lets see how.
  • Detectability: Easy
  • Detection Methodology:
  • @@ -552,7 +609,7 @@ Wanna fingerprint WAFs? Lets see how.
  • Detectability: Easy
  • Detection Methodology:
  • @@ -1657,24 +1714,6 @@ Wanna fingerprint WAFs? Lets see how. - - - WordPress Cerber - - - - - XLabs Security WAF