Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
ladder — Selfhosted alternative to 12ft.io. and 1ft.io. Proxy to remove CORS headers and modify HTML | Kitploit
Tools/GitHubGitHub/everywall/ladder
Web Proxies & InterceptionWeb SecurityAPI SecurityAnti-Bot
GitHubeverywall/ladder

ladder

Selfhosted alternative to 12ft.io. and 1ft.io. Proxy to remove CORS headers and modify HTML

View Repository
8.8k511231 month agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Ladder

License go.mod Go version GitHub tag (with filter) GitHub (Pre-)Release Date GitHub Downloads all releases GitHub Build Status (with event)

Ladder is a http web proxy.

简体中文

Ladder is a developer tool for testing and analyzing paywall implementations and content delivery behavior on modern websites.

It allows developers, researchers, and publishers to simulate different client environments (such as browsers and crawlers) and observe how content is served under varying conditions. This makes it useful for debugging paywall configurations, verifying access controls, http headers, and ensuring consistent behavior across different user agents.

Ladder is intended for legitimate testing, research, and quality assurance purposes only. It should only be used in compliance with applicable laws and the terms of service of the target website.

screenshot

How it works

sequenceDiagram
    client->>+ladder: GET
    ladder-->>ladder: apply RequestModifications
    ladder->>+website: GET
    website->>-ladder: 200 OK
    ladder-->>ladder: apply ResultModifications
    ladder->>-client: 200 OK

Features

  • Remove/modify CORS headers from responses, assets, and images ...
  • Remove/modify other headers (e.g. Content-Security-Policy)
  • Remove/inject custom code (HTML, CSS, JavaScript) into the page
  • Apply domain based ruleset/code to modify response / requested URL
  • Keep site browsable
  • API
  • Fetch RAW HTML
  • Custom User Agent
  • Custom X-Forwarded-For IP
  • Docker container (amd64, arm64)
  • Linux binary
  • Mac OS binary
  • Windows binary (untested)
  • Basic Auth
  • Access logs
  • Might break tracking, adds and other 3rd party content
  • Limit the proxy to a list of domains
  • Expose Ruleset to other ladders
  • Robots.txt testing
  • Optional TOR proxy
  • A key to share a proxied URL

Limitations

Some websites deliver different content (Cloaking) depending on the type of client accessing them (for example, search engine crawlers versus standard web browsers). Ladder can be configured to emulate different client types in order to retrieve publicly accessible content for testing, automation, or research purposes.

However, many websites implement advanced mechanisms to restrict automated access, such as fingerprinting, rate limiting, or behavioral analysis. Ladder does not circumvent such protections and may not function correctly on services that actively restrict or control access.

Third-party tools such as FlareSolverr exist and may be used independently to render web pages in a headless browser environment. These tools are not part of Ladder, and their use may be subject to legal and contractual restrictions. Users are solely responsible for ensuring that their usage complies with all applicable regulations.

Installation

Warning: If your instance will be publicly accessible, make sure to enable Basic Auth. This will prevent unauthorized users from using your proxy. If you do not enable Basic Auth, anyone can use your proxy to browse nasty/illegal stuff. And you will be made responsible for it.

Binary

  1. Download binary here
  2. Unpack and run the binary ./ladder -r https://raw.githubusercontent.com/everywall/ladder-rules/main/ruleset.yaml
  3. Open Browser (Default: http://localhost:8080)

Docker

docker run -p 8080:8080 -d --env RULESET=https://raw.githubusercontent.com/everywall/ladder-rules/main/ruleset.yaml --name ladder ghcr.io/everywall/ladder:latest

Docker Compose

curl https://raw.githubusercontent.com/everywall/ladder/main/docker-compose.yaml --output docker-compose.yaml
docker-compose up -d

Helm

See README.md in helm-chart sub-directory for more information.

Usage

Browser

  1. Open Browser (Default: http://localhost:8080)
  2. Enter URL
  3. Press Enter

Or direct by appending the URL to the end of the proxy URL: http://localhost:8080/https://www.example.com

Or create a bookmark with the following URL:

javascript:window.location.href="http://localhost:8080/"+location.href

API

curl -X GET "http://localhost:8080/api/https://www.example.com"

RAW

http://localhost:8080/raw/https://www.example.com

Running Ruleset

http://localhost:8080/ruleset

Configuration

Environment Variables

VariableDescriptionValue
PORTPort to listen on8080
PREFORKSpawn multiple server instancesfalse
USER_AGENTUser agent to emulateMozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)
X_FORWARDED_FORIP forwarder address66.249.66.1
USERPASSEnables Basic Auth, format admin:123456``
LOG_URLSLog fetched URL'strue
DISABLE_FORMDisables URL Form Frontpagefalse
FORM_PATHPath to custom Form HTML``
RULESETPath or URL to a ruleset file, accepts local directorieshttps://raw.githubusercontent.com/everywall/ladder-rules/main/ruleset.yaml or /path/to/my/rules.yaml or /path/to/my/rules/
EXPOSE_RULESETMake your Ruleset available to other ladderstrue
ALLOWED_DOMAINSComma separated list of allowed domains. Empty = no limitations``
ALLOWED_DOMAINS_RULESETAllow Domains from Ruleset. false = no limitationsfalse
FLARESOLVERR_HOSTURL for the FlareSolverr service for Cloudflare bypass (optional)http://localhost:8191

ALLOWED_DOMAINS and ALLOWED_DOMAINS_RULESET are joined together. If both are empty, no limitations are applied. | BASE_PATH | Base path for the proxy, useful if you want to run the proxy on a subpath (e.g. http://localhost:8080/proxy/) | `` |

Ruleset

It is possible to apply custom rules to modify the response or the requested URL. This can be used to remove unwanted or modify elements from the page. The ruleset is a YAML file, a directory with YAML Files, or an URL to a YAML file that contains a list of rules for each domain. These rules are loaded on startup.

There is a basic ruleset available in a separate repository ruleset.yaml. Feel free to add your own rules and create a pull request.

Download Tool