Loading...
Click "Run Test" to check if your proxy properly strips spoofed headers
Test the maximum size of a single header value, or the total size of all headers combined
Test the maximum length of a URL path or query string that the proxy accepts
Test if null bytes and unprintable characters are properly blocked
Send known attack strings to the server (via header, URL path, query) and check whether the WAF blocks them
Ask the server to send known attack strings back to the browser (via response body, response header) and check whether the WAF blocks them
No headers received yet
Waiting for handshake...
Not connected
Waiting for connection...
Not connected