
waf-detector
🛡️ High-performance WAF & CDN detection tool. Identify protection layers (Cloudflare, Akamai, AWS, Fastly, and more), run effectiveness and…

🛡️ High-performance WAF & CDN detection tool. Identify protection layers (Cloudflare, Akamai, AWS, Fastly, and more), run effectiveness and…

Self-hosted SSRF redirect, payload, callback, and DNS workbench

Domain OSINT and security reconnaissance framework running 26 parallel modules for DNS, ports, subdomains, leaked credentials, exposed endpoints,…

PhantomRecon is a CLI-based, modular, agent-driven red team automation tool designed to demonstrate autonomous offensive security workflows powered…

Exfiltrate blind Remote Code Execution and SQL injection output over DNS via Burp Collaborator.

Network, recon and offensive-security tool for Linux.

Automated man-in-the-middle attack tool.

PwnSTAR (Pwn SofT-Ap scRipt) - for all your fake-AP needs!

Exploit for CVE-2015-6357 Cisco FireSIGHT Management Center Certificate Validation Vulnerability

Community curated list of templates for the nuclei engine to find security vulnerabilities.

Delivering PHP RCE (CVE-2024-4577) to the Local Network Servers

CVE-2025-24813_POC

CVE-2021-44228,log4j2 burp插件 Java版本,dnslog选取了非dnslog.cn域名

A script that checks for vulnerable Log4j (CVE-2021-44228) systems using injection of the payload in common HTTP headers.

Reproducer for CVE-2026-48205: Apache Camel camel-dns dns.* header injection redirecting DNS queries to an attacker-controlled resolver (SSRF via…

Reproducer for CVE-2026-42527 — Apache Camel permissive default ObjectInputFilter admits java.net.URL, enabling a DNS-based out-of-band side channel

Cookie-based authentication vulnerability on Tk-Rt-Wr135G

Proof-of-concept exploit for CVE-2021-23017 targeting a remote host with a custom DNS server. Designed for security testing and vulnerability…