FTW – Framework For Testing WAFs

This project was created by researchers from ModSecurity and Fastly to help provide rigorous tests for WAF rules. It uses the OWASP Core Ruleset V3 as a baseline to test rules on a WAF. Each rule from the ruleset is loaded into a YAML file that issues HTTP requests that will trigger these rules. Users can verify the execution of the rule after the tests are issued to make sure the expected response is received from an attack.
Goals / Use cases include:

  • Find regressions in WAF deployments by using continuous integration and issuing repeatable attacks to a WAF
  • Provide a testing framework for new rules into ModSecurity, if a rule is submitted it MUST have corresponding positive & negative tests
  • Evaluate WAFs against a common, agreeable baseline ruleset (OWASP)
  • Test and verify custom rules for WAFs that are not part of the core rule set

For our 1.0 release announcement, check out the OWASP CRS Blog

  • git clone https://github.com/CRS-support/ftw.git
  • cd ftw
  • virtualenv env && source ./env/bin/activate
  • pip install -r requirements.txt
  • py.test -s -v test/test_default.py --ruledir=test/yaml

Writing your first tests
The core of FTW is it’s extensible yaml based tests. This section lists a few resources on how they are formatted, how to write them and how you can use them.
OWASP CRS wrote a great blog post describing how FTW tests are written and executed.
YAMLFormat.md is ground truth of all yaml fields that are currently understood by FTW.
After reading these two resources, you should be able to get started in writing tests. You will most likely be checking against status code responses, or web request responses using the log_contains directive. For integrating FTW to test regexes within your WAF logs, refer to ExtendingFTW.md

Provisioning Apache+Modsecurity+OWASP CRS
If you require an environment for testing WAF rules, there has been one created with Apache, Modsecurity and version 3.0.0 of the OWASP core ruleset. This can be deployed by:

  • Checking out the repository: git clone https://github.com/fastly/waf_testbed.git
  • Typing vagrant up

Download FTW


This is only an educational purposes only I am not responsible for further activities

Join my forum and learn more ethical hacking and penetration testing


Get me at







15 Replies to “FTW – Framework For Testing WAFs”

  1. Greetings! I’ve been following your blog for some time now and finally got the courage to go ahead and give you a shout out from Atascocita Texas! Just wanted to tell you keep up the excellent work!

  2. Wonderful items from you, man. I’ve have in mind your stuff previous to and you are just extremely great. I actually like what you’ve obtained here, really like what you are stating and the way in which through which you say it. You’re making it enjoyable and you still take care of to keep it smart. I can not wait to learn far more from you. This is really a tremendous web site.

  3. Thanks for the suggestions you have discussed here. Furthermore, I believe there are numerous factors which keep your automobile insurance premium all the way down. One is, to consider buying automobiles that are in the good list of car insurance companies. Cars that happen to be expensive are more at risk of being robbed. Aside from that insurance policies are also based on the value of your car or truck, so the higher priced it is, then higher a premium you spend.

  4. I抳e learn several just right stuff here. Definitely worth bookmarking for revisiting. I surprise how so much attempt you set to create this type of excellent informative site.

  5. I discovered your weblog web site on google and test just a few of your early posts. Proceed to maintain up the superb operate. I simply additional up your RSS feed to my MSN Information Reader. Searching for ahead to studying extra from you afterward!?

  6. Hi! I just wanted to ask if you ever have any problems with hackers? My last blog (wordpress) was hacked and I ended up losing months of hard work due to no backup. Do you have any methods to protect against hackers?

  7. obviously like your web-site but you need to check the spelling on quite a few of your posts. A number of them are rife with spelling issues and I find it very troublesome to tell the truth nevertheless I抣l certainly come back again.

  8. I do enjoy the way you have framed this situation and it really does supply us some fodder for consideration. Nonetheless, through just what I have seen, I simply just hope when other feedback stack on that folks keep on point and in no way embark upon a soap box involving the news du jour. Still, thank you for this excellent piece and even though I do not necessarily concur with the idea in totality, I regard the point of view.

  9. Yet another thing I would like to talk about is that as opposed to trying to accommodate all your online degree courses on days and nights that you end work (considering that people are drained when they go back home), try to have most of your lessons on the weekends and only a couple courses for weekdays, even if it means taking some time off your end of the week. This is really good because on the weekends, you will be more rested as well as concentrated upon school work. Thanks a lot for the different tips I have realized from your weblog.

  10. I抦 not sure where you are getting your info, but great topic. I needs to spend some time learning more or understanding more. Thanks for fantastic information I was looking for this info for my mission.

  11. Thanks for the different tips discussed on this website. I have realized that many insurance companies offer prospects generous reductions if they decide to insure a couple of cars together. A significant amount of households possess several autos these days, specifically those with old teenage kids still dwelling at home, as well as the savings with policies can soon increase. So it pays off to look for a great deal.

  12. Great weblog here! Additionally your web site loads up fast! What web host are you using? Can I am getting your associate hyperlink for your host? I desire my web site loaded up as quickly as yours lol

  13. My brother suggested I might like this blog. He was totally right. This post truly made my day. You cann’t imagine simply how much time I had spent for this info! Thanks!

Leave a Reply

Your email address will not be published. Required fields are marked *