diff --git a/README.md b/README.md
index 3f276b7..5cc110e 100644
--- a/README.md
+++ b/README.md
@@ -1024,27 +1024,6 @@ Wanna fingerprint WAFs? Lets see how.
-
-
- NinjaFirewall (NinTechNet)
- |
-
-
- - Detectability: Moderate
- - Detection Methodology:
-
- - Response page title contains
NinjaFirewall: 403 Forbidden .
- - Response page contains:
-
- For security reasons, it was blocked and logged text snippet.
- NinjaFirewall keyword.
-
-
- - Returns a
403 Forbidden response upon malicious requests.
-
-
- |
-
NetScaler (Citrix)
@@ -1085,6 +1064,27 @@ Wanna fingerprint WAFs? Lets see how.
|
+
+
+ NinjaFirewall (NinTechNet)
+ |
+
+
+ - Detectability: Moderate
+ - Detection Methodology:
+
+ - Response page title contains
NinjaFirewall: 403 Forbidden .
+ - Response page contains:
+
+ For security reasons, it was blocked and logged text snippet.
+ NinjaFirewall keyword in title.
+
+
+ - Returns a
403 Forbidden response upon malicious requests.
+
+
+ |
+
NSFocus Firewall
@@ -1109,8 +1109,13 @@ Wanna fingerprint WAFs? Lets see how.
Detection Methodology:
- Response headers contain header
X-Engine field with value onMessage Shield .
- - Response page may contain
onMessage SHIELD keyword.
- - You might encounter response page with
This site is protected by an enhanced security system to ensure a safe browsing experience .
+ - Blocked response page contains:
+
+ Blackbaud K-12 conducts routine maintenance keyword.
+ This site is protected by an enhanced security system .
+ - Reference to
https://status.blackbaud.com URL.
+ - Reference to
https://maintenance.blackbaud.com URL.
+
|
@@ -1121,10 +1126,10 @@ Wanna fingerprint WAFs? Lets see how.
- - Detectability: Difficult
+ - Detectability: Moderate
- Detection Methodology:
- - Blocked response page contains the following text snippet
has been blocked in accordance with company policy .
+ - Blocked response page contains
Virus/Spyware Download Blocked .
|
@@ -1216,6 +1221,10 @@ Wanna fingerprint WAFs? Lets see how.
- Response headers contain
rbzid=
header field name.
- Response headers field values might contain
Reblaze Secure Web Gateway
text snippet.
+ - Response page contains:
+
+ Current session has been terminated
text.
+
@@ -1289,7 +1298,12 @@ Wanna fingerprint WAFs? Lets see how.
Detectability: Easy
Detection Methodology:
- - Response headers contain
Safe3
keyword.
+ - Response headers contain:
+
+ X-Powered-By
header has field value Safe3WAF
.
+ Server
header contains field value set to Safe3 Web Firewall
.
+
+ - Response page contains
Safe3waf
keyword.
@@ -1312,6 +1326,20 @@ Wanna fingerprint WAFs? Lets see how.
+
+
+ SecureIIS (eEye)
+ |
+
+
+ - Detectability: Easy
+ - Detection Methodology:
+
+ Server header contains value set to Secure Entry Server .
+
+
+ |
+
SecureIIS (eEye)
|