---
title: "Asset not protected by Web Application Firewall (WAF)"
canonical: "https://kb.cynergy.app/space/MD/899416103/Asset%20not%20protected%20by%20Web%20Application%20Firewall%20(WAF)"
format: markdown
---
**Description **

Applications are a primary target for hackers, who exploit vulnerabilities such as design flaws as well as weaknesses in APIs, Edge Devices, Cloud Instances, open-source code, third-party widgets, and access control.

In addition to direct financial and data theft, web application threats can destroy assets, customer goodwill, and business reputations. That makes web application security imperative for organizations of all sizes.

This is why it’s important to protect all web applications exposed to the Internet.

**Hacker's View**

As a hacker, one of the first things I would check is if the web application is protected with WAF with tools like [Waaf00f](https://github.com/EnableSecurity/wafw00f) or [IdentYwaf](https://github.com/stamparm/identYwaf). 

Once determined if the web application is not protected by WAF, I will start trying different types of web application attacks such as:

- SQL injections
- Cross-site scripting
- Brute force attacks
- Credential stuffing
- Cookie poisoning and hijacking
- Man-in-the-middle (MITM) and man-in-the-browser attacks
- Sensitive data disclosure
- Deserialization attacks
- Session hijacking

**Mitigation**

There are multiple WAF providers, based on your provider, it is advised to protect your web applications with WAF. 

**Cynergy’s View**

![image](media://19516ea8-f9a4-4399-b197-8b614d74b734)

Cynergy allows you to detect if a web application is protected by WAF, once discovered that the web application is not protected, you as the user are notified in the inventory, under the Infrastructure assets, per each exposed web application identified. 

**Reference**

AWS WAF - [https://aws.amazon.com/waf/](https://aws.amazon.com/waf/)

GCP WAF - [https://cloud.google.com/armor/docs/rule-tuning](https://cloud.google.com/armor/docs/rule-tuning) 

Azure WAF - [https://azure.microsoft.com/en-us/services/web-application-firewall/#overview](https://azure.microsoft.com/en-us/services/web-application-firewall/#overview) 

Cloudflare WAF - [https://www.cloudflare.com/waf/](https://www.cloudflare.com/waf/) 

Imperva WAF - [https://www.imperva.com/products/web-application-firewall-waf/](https://www.imperva.com/products/web-application-firewall-waf/) 

F5 WAF - [https://www.f5.com/services/resources/glossary/web-application-security](https://www.f5.com/services/resources/glossary/web-application-security) 

Sucuri WAF -[https://sucuri.net/?cjevent=c4619389ff7a11ec800898e40a180510&cj_aid=13942195&cj_pid=8028369&cj_cid=4707016](https://sucuri.net/?cjevent=c4619389ff7a11ec800898e40a180510&cj_aid=13942195&cj_pid=8028369&cj_cid=4707016) 

Fortinet Forti WAF - [https://www.fortinet.com/products/web-application-firewall/fortiweb](https://www.fortinet.com/products/web-application-firewall/fortiweb) 

Barracuda WAF - [https://www.barracuda.com/products/webapplicationfirewall](https://www.barracuda.com/products/webapplicationfirewall) 

Akamai Kona - [https://www.akamai.com/products/web-application-protector](https://www.akamai.com/products/web-application-protector) 

Prophaze WAF - [https://prophaze.com/products/cloud-waf/](https://prophaze.com/products/cloud-waf/) 

AppTrana WAF - [https://www.indusface.com/web-application-firewall.php?utm_source=PPC&utm_medium=Comparitech-Lisitng&utm_campaign=Comparitech-Product-Listing-best-waf](https://www.indusface.com/web-application-firewall.php?utm_source=PPC&utm_medium=Comparitech-Lisitng&utm_campaign=Comparitech-Product-Listing-best-waf) 

StackPath WAF - [https://www.stackpath.com/products/waf](https://www.stackpath.com/products/waf)