National Cyber Warfare Foundation (NCWF)

How unwaf turns passive OSINT into verified WAF origin discoveries


0 user ratings
2026-09-26 15:33:56
milo
Red Team (CNA)
"How

unwaf is a Go utility that passively uncovers the real origin IP behind a WAF/CDN and verifies candidates through HTML, certificate, and header scoring for authorized assessments.








Toolmmarting/unwaf — passive WAF/CDN origin-IP discovery and verification tool written in Go, version 3.0.0, GPL-3.0
CategoryReconnaissance / OSINT automation
Primary UseFinding and validating the true origin IP behind a WAF/CDN during authorized bug bounty and pentest engagements, using passive OSINT sources plus a weighted similarity score
Safe UseFor authorized security assessments, bug bounty programs with defined scope, and internal defense validation where teams test whether their own origin infrastructure leaks through their CDN
Telemetry NoteThe tool itself is passive-first, but it does query public APIs (crt.sh, AlienVault OTX, RapidDNS, HackerTarget, Wayback CDX), performs direct-to-origin HTTP requests with Host-header injection on 8 web ports, and can optionally expand into /24 neighbor scanning — origin-facing logs and rate limits on these third-party services will register its activity

unwaf by Martín Martín (mmarting/unwaf) solves one of the oldest problems in web recon: a target sits behind a WAF or CDN, typically Cloudflare, and everything you test hits the edge rather than the actual server. Instead of trying to punch through the proxy, unwaf works around it, correlating up to fifteen passive and semi-passive discovery sources to find historical or leaked origin IP addresses, then confirming each candidate against the live reference site with a weighted scoring model. At version 3.0.0 under GPL-3.0 with 187 stars, it is an actively maintained, single-binary Go project aimed squarely at the authorized bug bounty and pentest workflow — the README explicitly links it back to the author's writeup on passive WAF bypassing.


The architecture is a clean pipeline, and the README lays it out in ten ordered stages. First, unwaf fetches live Cloudflare CIDR ranges and merges them with hardcoded WAF/CDN ranges, including IPv6, so the tool always knows which addresses belong to proxies rather than origins. It then confirms the target is actually behind a WAF by resolving the domain's current A records, checking whether they fall inside those ranges, and fingerprinting the vendor via HTTP headers. Only then does discovery begin, which is a sensible ordering: there is no point hunting for an origin if none exists.


The discovery layer is where unwaf earns its density. Free, keyless methods include extracting ip4:/ip6: mechanisms from SPF records, resolving MX hosts while skipping obvious mega-providers like Google and Microsoft, probing 30+ common subdomains (mail, dev, staging, cpanel, origin), querying crt.sh Certificate Transparency data and resolving everything that lands outside WAF ranges, scraping RapidDNS, hitting the HackerTarget host search API, and mining archived hostnames from the Wayback Machine CDX API. AlienVault OTX passive DNS is also free with an optional key for higher rate limits.


API-backed sources extend coverage for operators with accounts. Shodan host search by SSL certificate CN, hostname, and favicon hash; SecurityTrails and ViewDNS for historical A records; Censys SSL search (a paid license) for hosts presenting matching certificates; and DNSDB/Farsight via its NDJSON API with a generous Community Edition quota. A nice touch is the favicon hashing method, which generates MD5, SHA256, and MMH3 hashes of favicon.ico — the MMH3 variant being the format Shodan and Censys index natively, which means the tool's output maps directly onto manual searches you might do in those engines.


What separates unwaf from a pile of recon scripts is the verification stage. Every candidate IP survives only if it passes a scored comparison against the reference site fetched through the WAF: HTML similarity carries 60% weight via diff-based text comparison, SSL certificate comparison carries 25% (broken down as 50% serial number, 25% CN match, 25% SAN overlap), and HTTP header comparison — Server, X-Powered-By, and Set-Cookie names — carries 15%. Status-code agreement adds or subtracts a further 5-20%. Candidates are probed on eight common web ports concurrently, both via direct IP and with Host-header injection, and only matches above the configurable threshold (default 60) are reported, complete with ASN/organization lookups and ready-made curl verification commands so the operator can manually confirm before acting on the result.


Filtering happens before verification, not after: any IP inside a known WAF/CDN range, or matching the domain's current DNS resolution, is discarded. This keeps the scoring stage focused on genuine origin candidates and reduces false positives from CDN edge nodes that happen to serve similar content. An optional --scan-neighbors mode expands confirmed bypass IPs into their /24 subnets and probes neighbors — useful in cloud tenancies where multiple origins share a block, but also the noisiest feature in the tool and one to use deliberately within scope boundaries.


Installation is a one-liner with the Go toolchain: go install github.com/mmarting/unwaf@latest. Basic invocation is equally minimal — unwaf -d example.com runs the full pipeline with free methods only, and it accepts full URLs like https://example.com/path as well as bare domains. On first run it writes a config template to $HOME/.unwaf.conf with clearly commented slots for each optional API key (viewdns, securitytrails, censys_token, censys_org_id, otx_api_key, shodan_api_key, dnsdb_api_key), which is friendlier than most recon tools that just fail cryptically on missing keys.


The flag surface is well thought out for real operations. -s original.html lets you supply a manually saved copy of the reference page for when the WAF blocks the tool itself — a self-aware design choice. -t 40 lowers the similarity threshold to catch partial matches on sites whose origin serves slightly different builds, -w 100 raises concurrency, and --rate-limit 2 --timeout 5 throttles and bounds requests when you need to be gentle. --proxy accepts http:// or socks5:// URLs for routing through Tor or Burp, --json and -o produce structured output, -l domains.txt enables batch mode, and -q strips everything down to bare IPs for piping.


That pipe-friendliness is clearly intentional — the README shows unwaf -q -d target.com feeding directly into nuclei and httpx, plus a jq recipe over the JSON output to extract .bypasses[].ip. This positions unwaf as a mid-pipeline component in a larger authorized workflow rather than a destination tool, which is exactly how mature recon utilities should behave.


From a defensive perspective, unwaf doubles as a misconfiguration audit for your own infrastructure. If it can find your origin, so can anyone. The sources it exploits — stale SPF entries, forgotten MX-adjacent hosts, dev and staging subdomains pointing directly at origin, historical A records still live in passive DNS, certificates logged in crt.sh — are all remediable. Origins should live on their own IP space with strict Host-header validation, default-virtual-host behavior disabled, and firewall rules that only accept traffic from the CDN's published ranges. Watching for direct-to-origin HTTP probes carrying your public Host header is the corresponding detection signal, since that Host-header injection pattern is intrinsic to how unwaf verifies candidates.


Caveats worth noting: Censys search requires a paid license, Shodan search needs a membership tier, and the free quotas on HackerTarget and SecurityTrails are tight enough that heavy batch runs will exhaust them quickly. The MMH3 favicon hashing, certificate serial matching, and diff-based HTML comparison are all recomputable by hand, so the tool is best understood as automation of well-documented tradecraft rather than any novel technique — which is precisely its value. For professionals with authorization, unwaf compresses hours of manual OSINT correlation into a single scored, verifiable report.



Official project repository for mmarting/unwaf.

Download Tool

Educational analysis for authorized security professionals. Use only in controlled, authorized environments.






Source: OffensiveSec
Source Link: https://www.offsecblog.com/2026/09/how-unwaf-turns-passive-osint-into.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Red Team (CNA)



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.