nemesida-waf/waf-bypass ? reverse-engineered prompt
Reverse engineered prompt
Build me a Python command line tool that tests a website or API for WAF false positives and false negatives using a set of built in payloads. It should take a target host, let me add extra headers, proxy settings, user agent, timeout, thread count, and a way to ignore certain payload groups. I want it to run a bunch of tests across common security cases like SQL injection, XSS, LFI, RFI, RCE, SSTI, SSRF, GraphQL, NoSQL, LDAP, open redirect, and multipart form payloads, then show which requests were blocked, which got through, and which failed.
Please make the output easy to read in the terminal, and also support JSON output so it can be used in other tools. If a request gets flagged as interesting, I want a way to show the exact curl command to repeat it. It should also be easy to add custom payload files later. If you need to look up current Python packaging or Docker best practices, go ahead and do that.
Are you gonna build this?
make sure you review the code using coderabbit