
stunner
Test and exploit STUN/TURN servers for misconfigurations, enabling internal network pivoting via SOCKS proxy, memory leak attacks, and internal port…

Test and exploit STUN/TURN servers for misconfigurations, enabling internal network pivoting via SOCKS proxy, memory leak attacks, and internal port…

Automated WSUS MITM tool that spoofs Windows Update traffic over ARP, serves a signed executable with PowerShell payload, and escalates to local…




WatchGuard Firebox Default Configuration Allows Unauthorized SSH Access via Port 4118

Firewall rules to mitigate a zero-day vulnerability malware attack (CVE-2022-22965), known as Spring4Shell

OWASP ModSecurity Core Rule Set (CRS) Project (Official Repository)

Generic attack detection rule set for web application firewalls, protecting against OWASP Top Ten and common vulnerabilities with minimal false…

teler-waf is a Go HTTP middleware that protects local web services from OWASP Top 10 threats, known vulnerabilities, malicious actors, botnets,…

Security module for php7 and php8 - Killing bugclasses and virtual-patching the rest! https://snuffleupagus.rtfd.io

Web security audit tool with advanced technique (ON FIXING)

CVE-2025-55182-scanner with 2 different method

fail2ban filter that catches attacks againts log4j CVE-2021-44228

Fun things against the abuse of the recent CVE-2021-44228 (Log4Shell) vulnerability using common web servers.


Apache RewriteRule to mitigate potential DoS attack via Wordpress wp-admin/load-scripts.php file