
WAFNinja
WAFNinja is a tool which contains two functions to attack Web Application Firewalls.

WAFNinja is a tool which contains two functions to attack Web Application Firewalls.

Java-based framework for systematic fuzzing and analysis of TLS libraries. Enables arbitrary protocol message crafting, modification, and testing of…

Automatic SSTI detection tool with interactive interface

CVE-2022-46364 Apache CXF XOP:Include SSRF / LFI

CRLFISCANNER is a lightweight and powerful CLI tool designed for bug bounty hunters and penetration testers to automatically detect CRLF injection…

A wordlist of API names for web application assessments

Um script automatizado melhorando o exploit do cve-2011-0762 postado no exploit-db

Go Web Application Penetration Test

Software for fuzzing, used on web application pentestings.

Application for capturing, modifying and sending custom WebSocket data from client to server and vice versa.


htcap is a web application scanner able to crawl single page application (SPA) recursively by intercepting ajax calls and DOM changes.

The Offensive Manual Web Application Penetration Testing Framework.

Modular WAF bypass fuzzer with multi-threading, request manipulation, and payload encoding for red team web application testing.

A structure-aware JSON fuzzer

CVE-2020-6308 mass exploiter/fuzzer.

Tools for auditing WAFS