
WAFNinja
WAFNinja is a tool which contains two functions to attack Web Application Firewalls.

WAFNinja is a tool which contains two functions to attack Web Application Firewalls.

An example C program which contains vulnerable code for common types of vulnerabilities. It can be used to show fuzzing concepts.

Find regular expressions which are vulnerable to ReDoS (Regular Expression Denial of Service)

XSS Fuzzer is a tool which generates XSS payloads based on user-defined vectors and fuzzing lists.

Golang tool which helps dropping the irrelevant entries from your ffuf result file.

A simple POC of the CVE-2025-53367, creating a .djvu-file which triggers an OOB-write in the heap

Suzuki connect app is used to get the car information like Fuel, Ignition status, Current location, Seat buckle status etc. In Ignis, Zeta variant…

The Swiss Army knife for 802.11, BLE, HID, CAN-bus, IPv4 and IPv6 networks reconnaissance and MITM attacks.


VIPROY - VoIP Pen-Test Kit for Metasploit Framework

A wordlist framework to fullfill your kinks with your wordlists. For security researchers, bug bounty and hackers.

AFL/QEMU fuzzing with full-system emulation.

Research runtime for differentiable neural computers, GPU-based CPU emulation, and program synthesis. Features neural ALU, constant-time crypto, JEPA…

Modular WAF bypass fuzzer with multi-threading, request manipulation, and payload encoding for red team web application testing.

A linux system call fuzzer using TriforceAFL

Edge-coverage-guided fuzzer for PHP libraries that detects bugs via crashes, timeouts, and warnings. Supports corpus management, crash minimization,…

Grammar-based HTTP/1 fuzzer with mutation ability