
CVE-2022-4539
Exploit for CVE-2022-4539 that spoofs X-Forwarded-For headers to bypass WordPress WAF IP-based login and logging restrictions. Includes scalable…

Exploit for CVE-2022-4539 that spoofs X-Forwarded-For headers to bypass WordPress WAF IP-based login and logging restrictions. Includes scalable…

Fuzz 401/403/404 pages for bypasses

NAXSI is an open-source, high performance, low rules maintenance WAF for NGINX

A ModSecurity ruleset for detecting potential attacks using CVE-2018-6389

Scripts for: How to Build a Covert Pentesting Infrastructure Almost Free

A slightly more fun way to disable windows defender + firewall. (through the WSC api)

Programmatically create hunting rules for deserialization exploitation with multiple keywords, gadget chains, object types, encodings, and rule types

BlackLotus UEFI Windows Bootkit

Burp Plugin to Bypass WAFs through the insertion of Junk Data

AWS WAF Solver, full reverse implemented in 100% Python & Golang.

Dynamic shellcode loader with sophisticated evasion capabilities

teler-waf is a Go HTTP middleware that protects local web services from OWASP Top 10 threats, known vulnerabilities, malicious actors, botnets,…

collection of apis used in malware development

Bash simulator to control a server using PHP system functions.

Bypass age verification service from redhat

ShadowNet is an anonymous routing protocol that forces all connections (system-wide) to go through Tor while implementing Mixnet-like…

CVE-2021-40346 PoC (HAProxy HTTP Smuggling)