
Burp-Encode-IP
Burp Suite extension to encode an IP address focused to bypass application IP / domain blacklist.

Burp Suite extension to encode an IP address focused to bypass application IP / domain blacklist.

Modular WAF bypass fuzzer with multi-threading, request manipulation, and payload encoding for red team web application testing.

React2Shell Ultimate - The most comprehensive CVE-2025-66478 Scanner for Next.js RSC RCE vulnerability. Multi-mode detection, WAF bypass, local…

Hands-on lab exercise for exploiting Log4Shell (CVE-2021-44228) with JNDI injection, LDAP referral servers, and reverse shell payloads. Includes…

↕️🤫 Stealth redirector for your red team operation security

IP obfuscator made to make a malicious ip a bit cuter

React Shell & Next.js RSC Exploit Tool (CVE-2025-55182)

Automated Tool That Generates The Perfect Meterpreter Powershell Payload

Stealth dropper executing remote binaries without dropping them on disk .(HTTP3 support, ICMP support, invisible tracks, cross-platform,...)

nginx CVE scanner + RCE exploit framework (CVE-2026-42945 + 16 others)

Advanced security testing tool for CVE-2025-55182 vulnerability assessment in Next.js applications. Features interactive shell, batch scanning, WAF…

This is a powerful and stealthy PHP reverse shell designed for ethical hacking and penetration testing. It establishes a reliable and quiet…

Exploit for CVE-2025-55182 & CVE-2025-66478

Advanced Exploitation Toolkit for Next.js Server Actions (CVE-2025-55182)

Next.js RSC RCE Exploit Tool (CVE-2025-55182)

Go-based scanner and exploitation tool for CVE-2025-55182 (Next.js RCE). Supports batch scanning, command execution, Godzilla memory shell injection,…

A PHP backdoor management and generation tool/C2 featuring end to end encrypted payload streaming designed to bypass WAF, IDS, SIEM systems.

Python exploit for CVE-2025-64446 targeting FortiWeb WAF, enabling unauthorized user creation and privilege escalation through a crafted HTTP request.