matrixleons/evilwaf ? reverse-engineered prompt
Reverse engineered prompt
Build me a Python tool for authorized security testing that acts like a transparent MITM proxy and WAF scanner. I want to be able to point tools like sqlmap or nuclei at it with a normal proxy setting, and have it handle the rest without changing my requests. It should detect common WAF vendors, try a few smart transport layer tricks to avoid fingerprint based blocking, and if it can find the real origin server behind the WAF, send traffic there directly.
Also include a scanner mode that checks for common WAF weaknesses, like rate limiting, header trust issues, method handling, session problems, and encoding based bypasses, then keeps a confidence score and avoids noisy false positives by rechecking findings. Give it a clean terminal dashboard for live traffic and results, plus a headless mode for scripts. If it helps, add Docker support and make sure it works on Linux and macOS.
Are you gonna build this?
make sure you review the code using coderabbit