Quick WAF paranoid Doctor Evaluation

WAFPARAN01D3
The Web Application Firewall Paranoia Level Test Tool.
— From alt3kx.github.io
Introduction to Paranoia Levels
In essence, the Paranoia Level (PL) allows you to define how aggressive the Core Rule Set is.
Reference: https://coreruleset.org/20211028/working-with-paranoia-levels/
How it works
- The
wafparan01d3.py
python3 script takes malicious requests using encoded payloads placed in different parts of HTTP requests based on GET parameters, The results of the evaluation are recorded in the report debug filewafparan01d3.log
created on your machine. - Observe the behavior and response for each WAF paranoia level setting different attacks or payloads by using the default config level.
- The PoC