{"id":965,"date":"2015-07-20T13:58:24","date_gmt":"2015-07-20T11:58:24","guid":{"rendered":"http:\/\/www.ayhanarda.com\/blog\/?p=965"},"modified":"2015-07-20T13:58:24","modified_gmt":"2015-07-20T11:58:24","slug":"wafw00f-aracini-kullanarak-hedef-sistemde-waf-web-application-firewall-tespiti","status":"publish","type":"post","link":"https:\/\/www.ayhanarda.com\/blog\/2015\/07\/wafw00f-aracini-kullanarak-hedef-sistemde-waf-web-application-firewall-tespiti\/","title":{"rendered":"Wafw00f arac\u0131n\u0131 kullanarak hedef sistemde Waf (Web Application Firewall) tespiti"},"content":{"rendered":"<p>Bir sisteme sald\u0131rmadan \u00f6nce (g\u00fcvenlik testi diyelim \ud83d\ude42 ) hedefin \u00f6n\u00fcnde ne \u00e7e\u015fit bir firewall oldu\u011funu bilmek i\u015fimizi kolayla\u015ft\u0131racakt\u0131r ki buna g\u00f6re y\u00f6ntemler ile i\u00e7eriye girmeye \u00e7al\u0131\u015fal\u0131m ya da hi\u00e7 arkam\u0131za bakmadan ka\u00e7al\u0131m. Bu tespiti kolayla\u015ft\u0131rmak i\u00e7in Wafw00f isimli bir ara\u00e7 var ve bu ara\u00e7 Kali Linux i\u00e7inde \u00f6ntan\u0131ml\u0131 olarak kurulu geliyor , Di\u011fer distro lara da ayr\u0131ca kurabilirsiniz. A\u00e7\u0131k kaynak kodlu bir uygulamad\u0131r ve kodlar\u0131 incelemek ister iseniz <a href=\"https:\/\/github.com\/sandrogauci\/wafw00f\" target=\"_blank\">https:\/\/github.com\/sandrogauci\/wafw00f<\/a> adresini de ziyaret edebilirsiniz.<\/p>\n<p>Peki wafw00f asl\u0131nda ne yap\u0131yor. \u00d6nce normal http istekleri g\u00f6nderiyor , analiz ediyor , sonra s\u0131rad\u0131\u015f\u0131 tabir edebilece\u011fimiz \u00f6rne\u011fin bilindik injection metodlar\u0131 gibi anormal istekler g\u00f6ndererek yine cevaplar\u0131 analiz ediyor , e\u011fer \u00f6nde bilindik bir waf var ise gelen cevap i\u00e7inde bunun imzas\u0131na bak\u0131yor ve a\u015fa\u011f\u0131daki cihazlar\u0131 tan\u0131yabiliyor.<\/p>\n<p><code>Applicure dotDefender<br \/>\nArt of Defence HyperGuard<br \/>\nAqtronix WebKnight<br \/>\nBarracuda Aplication Firewall<br \/>\nBinarySec<br \/>\nCisco ACE XML Gateway<br \/>\nCitrix NetScaler<br \/>\nCloudFlare<br \/>\nDenyALL WAF<br \/>\neEye Digital Security - SecureIIS<br \/>\nF5 FirePass<br \/>\nF5 TrafficShield<br \/>\nF5 BIG-IP (LTM, APM, ASM)<br \/>\nIBM Web Application Security<br \/>\nIBM DataPower<br \/>\nImperva SecureSphere<br \/>\nInfoGuard Airlock<br \/>\nIncapsula WAF<br \/>\nJuniper WebApp Secure<br \/>\nMicrosoft ISA Server<br \/>\nMicrosoft UrlScan<br \/>\nNetContinuum<br \/>\nProfense<br \/>\nTrustWave ModSecurity<br \/>\nTeros WAF<br \/>\nUSP Secure Entry Server<\/code><\/p>\n<p>Kullan\u0131m\u0131 olduk\u00e7a basit, a\u015fa\u011f\u0131daki \u00f6rnekleri inceleyebiliriz.<\/p>\n<p>\u00d6nce ayhanarda.com u test edelim<\/p>\n<div id=\"wpshdo_1\" class=\"wp-synhighlighter-outer\"><div id=\"wpshdt_1\" class=\"wp-synhighlighter-expanded\"><table border=\"0\" width=\"100%\"><tr><td align=\"left\" width=\"80%\"><a name=\"#codesyntax_1\"><\/a><a id=\"wpshat_1\" class=\"wp-synhighlighter-title\" href=\"#codesyntax_1\"  onClick=\"javascript:wpsh_toggleBlock(1)\" title=\"Click to show\/hide code block\">Source code<\/a><\/td><td align=\"right\"><a href=\"#codesyntax_1\" onClick=\"javascript:wpsh_code(1)\" title=\"Show code only\"><img decoding=\"async\" border=\"0\" style=\"border: 0 none\" src=\"https:\/\/www.ayhanarda.com\/blog\/wp-content\/plugins\/wp-synhighlight\/themes\/default\/images\/code.png\" \/><\/a>&nbsp;<a href=\"#codesyntax_1\" onClick=\"javascript:wpsh_print(1)\" title=\"Print code\"><img decoding=\"async\" border=\"0\" style=\"border: 0 none\" src=\"https:\/\/www.ayhanarda.com\/blog\/wp-content\/plugins\/wp-synhighlight\/themes\/default\/images\/printer.png\" \/><\/a>&nbsp;<a href=\"https:\/\/www.ayhanarda.com\/blog\/wp-content\/plugins\/wp-synhighlight\/About.html\" target=\"_blank\" title=\"Show plugin information\"><img decoding=\"async\" border=\"0\" style=\"border: 0 none\" src=\"https:\/\/www.ayhanarda.com\/blog\/wp-content\/plugins\/wp-synhighlight\/themes\/default\/images\/info.gif\" \/><\/a>&nbsp;<\/td><\/tr><\/table><\/div><div id=\"wpshdi_1\" class=\"wp-synhighlighter-inner\" style=\"display: block;\"><pre class=\"php\" style=\"font-family:monospace;\">root<span class=\"sy0\">@<\/span>ayhanarda<span class=\"sy0\">.<\/span>com<span class=\"sy0\">:<\/span>~<span class=\"co2\"># wafw00f ayhanarda.com\n<\/span>\n                                 ^     ^\n        _   __  _   ____ _   __  _    _   ____\n       <span class=\"co1\">\/\/\/7\/ \/.' \\ \/ __\/\/\/\/7\/ \/,' \\ ,' \\ \/ __\/<\/span>\n      <span class=\"sy0\">|<\/span> V V <span class=\"co1\">\/\/ o \/\/ _\/ | V V \/\/ 0 \/\/ 0 \/\/ _\/  <\/span>\n      <span class=\"sy0\">|<\/span>_n_<span class=\"sy0\">,<\/span><span class=\"st_h\">'\/_n_\/\/_\/   |_n_,'<\/span> \\_<span class=\"sy0\">,<\/span><span class=\"st_h\">' \\_,'<\/span><span class=\"sy0\">\/<\/span>_<span class=\"sy0\">\/<\/span>    \n                                <span class=\"sy0\">&lt;<\/span>   \n                                 <span class=\"sy0\">...<\/span><span class=\"st_h\">'\n&nbsp;\n    WAFW00F - Web Application Firewall Detection Tool\n&nbsp;\n    By Sandro Gauci &amp;&amp; Wendel G. Henrique\n&nbsp;\nChecking http:\/\/ayhanarda.com\nGeneric Detection results:\nThe site http:\/\/ayhanarda.com seems to be behind a WAF \nReason: The server returned a different response code when a string trigged the blacklist.\nNormal response code is &quot;404&quot;, while the response code to an attack is &quot;406&quot;\nNumber of requests: 11<\/span><\/pre><\/div><\/div>\n<p>Yukar\u0131daki analizde diyor ki , ne \u00e7e\u015fit bir firewall oldu\u011funu analiz edemedim ama 11. g\u00f6nderdi\u011fim istekte ald\u0131\u011f\u0131m yan\u0131t de\u011fi\u015fti bu da demek oluyor ki bir g\u00fcvenlik korumas\u0131 alt\u0131nda ama ne oldu\u011funu bilemedim , \u015fimdi farkl\u0131 bir \u00f6rne\u011fe bakal\u0131m.<\/p>\n<div id=\"wpshdo_2\" class=\"wp-synhighlighter-outer\"><div id=\"wpshdt_2\" class=\"wp-synhighlighter-expanded\"><table border=\"0\" width=\"100%\"><tr><td align=\"left\" width=\"80%\"><a name=\"#codesyntax_2\"><\/a><a id=\"wpshat_2\" class=\"wp-synhighlighter-title\" href=\"#codesyntax_2\"  onClick=\"javascript:wpsh_toggleBlock(2)\" title=\"Click to show\/hide code block\">Source code<\/a><\/td><td align=\"right\"><a href=\"#codesyntax_2\" onClick=\"javascript:wpsh_code(2)\" title=\"Show code only\"><img decoding=\"async\" border=\"0\" style=\"border: 0 none\" src=\"https:\/\/www.ayhanarda.com\/blog\/wp-content\/plugins\/wp-synhighlight\/themes\/default\/images\/code.png\" \/><\/a>&nbsp;<a href=\"#codesyntax_2\" onClick=\"javascript:wpsh_print(2)\" title=\"Print code\"><img decoding=\"async\" border=\"0\" style=\"border: 0 none\" src=\"https:\/\/www.ayhanarda.com\/blog\/wp-content\/plugins\/wp-synhighlight\/themes\/default\/images\/printer.png\" \/><\/a>&nbsp;<a href=\"https:\/\/www.ayhanarda.com\/blog\/wp-content\/plugins\/wp-synhighlight\/About.html\" target=\"_blank\" title=\"Show plugin information\"><img decoding=\"async\" border=\"0\" style=\"border: 0 none\" src=\"https:\/\/www.ayhanarda.com\/blog\/wp-content\/plugins\/wp-synhighlight\/themes\/default\/images\/info.gif\" \/><\/a>&nbsp;<\/td><\/tr><\/table><\/div><div id=\"wpshdi_2\" class=\"wp-synhighlighter-inner\" style=\"display: block;\"><pre class=\"php\" style=\"font-family:monospace;\">root<span class=\"sy0\">@<\/span>ayhanarda<span class=\"sy0\">.<\/span>com<span class=\"sy0\">:<\/span>~<span class=\"co2\"># wafw00f hostgator.com\n<\/span>\n                                 ^     ^\n        _   __  _   ____ _   __  _    _   ____\n       <span class=\"co1\">\/\/\/7\/ \/.' \\ \/ __\/\/\/\/7\/ \/,' \\ ,' \\ \/ __\/<\/span>\n      <span class=\"sy0\">|<\/span> V V <span class=\"co1\">\/\/ o \/\/ _\/ | V V \/\/ 0 \/\/ 0 \/\/ _\/  <\/span>\n      <span class=\"sy0\">|<\/span>_n_<span class=\"sy0\">,<\/span><span class=\"st_h\">'\/_n_\/\/_\/   |_n_,'<\/span> \\_<span class=\"sy0\">,<\/span><span class=\"st_h\">' \\_,'<\/span><span class=\"sy0\">\/<\/span>_<span class=\"sy0\">\/<\/span>    \n                                <span class=\"sy0\">&lt;<\/span>   \n                                 <span class=\"sy0\">...<\/span><span class=\"st_h\">'\n&nbsp;\n    WAFW00F - Web Application Firewall Detection Tool\n&nbsp;\n    By Sandro Gauci &amp;&amp; Wendel G. Henrique\n&nbsp;\nChecking http:\/\/hostgator.com\nThe site http:\/\/hostgator.com is behind a Imperva\nNumber of requests: 9<\/span><\/pre><\/div><\/div>\n<p>Yukar\u0131daki \u00f6rne\u011fe bakacak olursak 6. istekte cihaz\u0131 tan\u0131mlam\u0131\u015f ve hostgator.com un Imperva isimli bir web application firewall arkas\u0131nda oldu\u011funu belirtmi\u015f.<\/p>\n<p>\u00d6rnekleri \u00e7o\u011faltabilirsiniz , mesela amazon.com a bakar iseniz Citrix Netscaler arkas\u0131nda oldu\u011funu g\u00f6rebilirsiniz.<\/p>\n<p>Ayhan ARDA<\/p>\n<div style=\"padding-bottom:20px; padding-top:10px;\" class=\"hupso-share-buttons\"><!-- Hupso Share Buttons - https:\/\/www.hupso.com\/share\/ --><a class=\"hupso_toolbar\" href=\"https:\/\/www.hupso.com\/share\/\"><img decoding=\"async\" src=\"https:\/\/static.hupso.com\/share\/buttons\/lang\/tr\/share-medium.png\" style=\"border:0px; padding-top: 5px; float:left;\" alt=\"Share Button\"\/><\/a><script type=\"text\/javascript\">var hupso_services_t=new Array(\"Twitter\",\"Facebook\",\"Google Plus\",\"Pinterest\",\"Linkedin\");var hupso_background_t=\"#EAF4FF\";var hupso_border_t=\"#66CCFF\";var hupso_toolbar_size_t=\"medium\";var hupso_image_folder_url = \"\";var hupso_twitter_via=\"ayhanarda\";var hupso_url_t=\"\";var hupso_title_t=\"Wafw00f%20arac%C4%B1n%C4%B1%20kullanarak%20hedef%20sistemde%20Waf%20%28Web%20Application%20Firewall%29%20tespiti\";<\/script><script type=\"text\/javascript\" src=\"https:\/\/static.hupso.com\/share\/js\/share_toolbar.js\"><\/script><!-- Hupso Share Buttons --><\/div>","protected":false},"excerpt":{"rendered":"Bir sisteme sald\u0131rmadan \u00f6nce (g\u00fcvenlik testi diyelim \ud83d\ude42 ) hedefin \u00f6n\u00fcnde ne \u00e7e\u015fit bir firewall oldu\u011funu bilmek i\u015fimizi kolayla\u015ft\u0131racakt\u0131r ki buna g\u00f6re y\u00f6ntemler ile i\u00e7eriye girmeye \u00e7al\u0131\u015fal\u0131m ya da hi\u00e7 arkam\u0131za bakmadan ka\u00e7al\u0131m. Bu tespiti kolayla\u015ft\u0131rmak i\u00e7in Wafw00f isimli bir ara\u00e7 var ve bu ara\u00e7 Kali Linux i\u00e7inde \u00f6ntan\u0131ml\u0131 olarak kurulu geliyor , Di\u011fer distro [&hellip;]","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_coblocks_attr":"","_coblocks_dimensions":"","_coblocks_responsive_height":"","_coblocks_accordion_ie_support":"","footnotes":""},"categories":[313],"tags":[805,798,799,803,804,800,801,802],"class_list":["post-965","post","type-post","status-publish","format-standard","hentry","category-security","tag-hangi-waf","tag-kali","tag-kali-waf","tag-waf-detection","tag-waf-tespiti","tag-wafw00f","tag-wafw00f-kullanimi","tag-wafw00f-usage"],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/www.ayhanarda.com\/blog\/wp-json\/wp\/v2\/posts\/965","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.ayhanarda.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.ayhanarda.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.ayhanarda.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.ayhanarda.com\/blog\/wp-json\/wp\/v2\/comments?post=965"}],"version-history":[{"count":1,"href":"https:\/\/www.ayhanarda.com\/blog\/wp-json\/wp\/v2\/posts\/965\/revisions"}],"predecessor-version":[{"id":966,"href":"https:\/\/www.ayhanarda.com\/blog\/wp-json\/wp\/v2\/posts\/965\/revisions\/966"}],"wp:attachment":[{"href":"https:\/\/www.ayhanarda.com\/blog\/wp-json\/wp\/v2\/media?parent=965"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.ayhanarda.com\/blog\/wp-json\/wp\/v2\/categories?post=965"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.ayhanarda.com\/blog\/wp-json\/wp\/v2\/tags?post=965"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}