
liffy
Local file inclusion exploitation tool

Local file inclusion exploitation tool

A penetration testing tool for bypassing HTTP 401/403 responses using various header manipulation techniques and path fuzzing.

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

Automated All-in-One OS Command Injection Exploitation Tool

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

Detect and bypass web application firewalls and protection systems

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

HackBar plugin for Burpsuite

Automated WAF security testing tool that detects false positives and false negatives using 15+ payload categories including SQLi, XSS, RCE, and…

Freeze is a payload toolkit for bypassing EDRs using suspended processes, direct syscalls, and alternative execution methods


Firewall bypass script based on DNS history records. This script will search for DNS A history records and check if the server replies for that…

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

WAFNinja is a tool which contains two functions to attack Web Application Firewalls.

The most powerful CRLF injection (HTTP Response Splitting) scanner.

Tests your WAF with +160 payloads

A SOCKS proxy written in Python that randomizes your source IP address. Round-robin your evil packets through SSH tunnels or give them billions of…

Tools for auditing WAFS