
janusec
Unified application gateway providing reverse proxy, WAF, CC defense, OAuth2 authentication, ACME certificate automation, and GSLB for secure,…

Unified application gateway providing reverse proxy, WAF, CC defense, OAuth2 authentication, ACME certificate automation, and GSLB for secure,…

HTTP/HTTPS interception proxy for testing Windows authentication mechanisms, supporting NTLM, Kerberos, pass-the-hash, pass-the-ticket and relay…

A proxy for net.tcp-based WCF traffic.

Mirror moved — see GitHub and Codeberg

Burp Suite extension to perform Kerberos authentication

Modern Web Firewall: stop account takeovers, weak passwords, cloud IPs, DoS attacks, disposable emails

OWASP Web Security Testing Guide RAG system with ChromaDB, MCP for Claude Code

Scanner for cPanel & WHM authentication bypass (CVE-2026-41940) that detects vulnerable versions via CRLF injection and session manipulation, with…

Python exploit for CVE-2025-31161, an authentication bypass in CrushFTP. Retrieves user lists via crafted CrushAuth and AWS4-HMAC-SHA256 headers.…

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

OWASP Raider: a novel framework for manipulating the HTTP processes of persistent sessions

Public PoC and detector for CVE-2026-20896 ("Gitea Docker: One Header, Any User")

Provides open-source SSO and identity provider functionality with SAML, OAuth2/OIDC, LDAP, and RADIUS support for centralized authentication,…

A reverse proxy that provides authentication with Google, Azure, OpenID Connect and many more identity providers.

Identity-aware reverse proxy that delivers zero-trust access to internal apps and services via context-aware policy, continuous verification, and no…

Modlishka. Reverse Proxy.

A cloud native Identity & Access Proxy / API (IAP) and Access Control Decision API that authenticates, authorizes, and mutates incoming HTTP(s)…

A reverse proxy like nginx, built on pingora, simple and efficient.