
liffy
Local file inclusion exploitation tool

Local file inclusion exploitation tool

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. It has a robust event-based…

Automated All-in-One OS Command Injection Exploitation Tool

A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228

A cheat sheet that contains advanced queries for SQL Injection of all types.

Detect and bypass web application firewalls and protection systems


evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

A fully automated, reliable, and accurate scanner for finding Spring4Shell and Spring Cloud RCE vulnerabilities

The most powerful CRLF injection (HTTP Response Splitting) scanner.

Tools for auditing WAFS

This script automates SQL injection testing using SQLMap with AI-powered decision making.


Analysing parameters with all payloads' bypass methods, aiming at benchmarking security solutions like WAF.

[漏洞复现] 全球首款利用PHP默认环境(XAMPP)的CVE-2024-4577 PHP-CGI RCE 漏洞 EXP。

React2Shell Ultimate - The most comprehensive CVE-2025-66478 Scanner for Next.js RSC RCE vulnerability. Multi-mode detection, WAF bypass, local…

YAML-driven framework for testing Web Application Firewall (WAF) rules using OWASP Core Rule Set baselines. Automates regression detection and…