
CVE-2024-30270-PoC
The script exploits Mailcow vulnerabilities via XSS and RCE, emphasizing the need for robust security measures and responsible usage to enhance web…

The script exploits Mailcow vulnerabilities via XSS and RCE, emphasizing the need for robust security measures and responsible usage to enhance web…

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

TCP tunneling over HTTP/HTTPS for web application servers

An open-source self-hosted purple team management web application.

Modular WAF bypass fuzzer with multi-threading, request manipulation, and payload encoding for red team web application testing.

CoWitness is a powerful web application testing tool that enhances the accuracy and efficiency of your testing efforts. It allows you to mimic an…

Anvil is a runtime-first attack surface assessment tool for Windows thick client applications, built for penetration testers and security researchers…

Web application penetration testing project targeting a WordPress environment. Includes exploitation of CVE-2019-9978, reverse shell execution,…

Six Degrees of Domain Admin

Burp Plugin to Bypass WAFs through the insertion of Junk Data


Webshell, Virtual Private Server (VPS) and cPanel Database




Một tập lệnh Python để DDOS một trang web bằng phương pháp nhiều phương pháp HTTP Flood, một trang web bình thường chỉ cần 5s để sập hoàn toàn!

Burp Suite extension to encode an IP address focused to bypass application IP / domain blacklist.