WAF Rule Testing

Trigger Cloudflare WAF custom rules and managed rulesets

SQL Injection Tests

Basic SQLi

Sends a request with ?sqli_test=1 payload. Expected: Blocked by WAF custom rule.

Union Select

Sends ?union_select=test payload. Expected: Blocked by WAF custom rule.

XSS Tests

Script Tag

Sends ?xss_test=<script> payload. Expected: Blocked by WAF custom rule.

JavaScript Protocol

Sends ?javascript=alert(1) payload. Expected: Blocked by WAF custom rule.

Path Traversal

Dot-Dot-Slash

Requests /../../../etc/passwd. Expected: Blocked by WAF custom rule.

Suspicious User Agents

Known Bad Bots

Sends request with Sqlmap or Nikto User-Agent. Expected: Managed Challenge.

Results

Run a test to see results...