Skip to content

Releases: K0NGR3SS/WAFPierce

v1.6.0

17 Jun 19:41

Choose a tag to compare

What's Changed

  • v1.6: OOB confirmation, new attack modules, engine controls, imports/integrations, tests by @Marwan-verse in #2

New Contributors

Full Changelog: v1.5.1...v1.6.0

v1.5.1

16 Jun 18:24

Choose a tag to compare

Full Changelog: v1.5.0...v1.5.1

v1.5.0

16 Jun 17:53

Choose a tag to compare

Full Changelog: WAF...v1.5.0

WAFPierce 1.4

14 Mar 20:14

Choose a tag to compare

promotion

!!THIS IS A WINDOWS BINARY ONLY

WAFPierce is a WAF/CDN assessment and bypass validation tool for penetration testing and security research. It fingerprints 17+ WAF vendors and 12+ CDN providers, then tests 100+ bypass/evasion techniques using baseline + heuristic comparisons (status codes, response size, hashes) to confirm real bypasses—even when defenses return OK. It also supports rate-limit detection, API endpoint and directory discovery, protocol-level testing (request smuggling, HTTP/2 downgrade, WebSocket tunneling), comprehensive injection testing (SQLi, XSS, SSRF, NoSQL, LDAP, XXE, SSTI, Log4Shell), cloud-specific tests, a clean GUI, optimized parallel performance, and automated Markdown reporting.

Trailer

https://youtu.be/O_iT_AuvczY

Full Changelog: https://github.com/K0NGR3SS/WAFPierce/commits/WAF