matrixleons/Evilwaf ? reverse-engineered prompt
Reverse engineered prompt
Build me a Python security testing tool called EvilWAF that acts like a transparent proxy for authorized testing and helps spot weak or misconfigured web application firewalls.
I want it to work with normal tools that can use a proxy, show a live terminal dashboard, and also have a headless mode for scripts. It should be able to detect common WAFs, try different network and protocol fingerprints, rotate things like source port and TLS behavior, and optionally route through Tor or a proxy pool. If it can find the real origin server behind the WAF, it should switch to that and keep testing there.
Also include a scanner mode that checks for common WAF weaknesses, rate limiting issues, header trust problems, session issues, and misconfigurations, then gives confidence scores and avoids reporting noisy false positives. Make it run cleanly on Linux and macOS, support HTTPS interception with generated certs, and include Docker support. Use the current docs online if you need to fill in any missing details.
Are you gonna build this?
make sure you review the code using coderabbit