
liffy
Local file inclusion exploitation tool

Local file inclusion exploitation tool

Burp Suite extension to encode an IP address focused to bypass application IP / domain blacklist.

🛡️ Open-source and cloud-native Web Application Firewall (WAF)

Tools for auditing WAFS

Disrupt WAF by abusing SSL/TLS Ciphers

Extension for Burp Suite which uses AWS API Gateway to rotate your IP on every request.

Modular WAF bypass fuzzer with multi-threading, request manipulation, and payload encoding for red team web application testing.

Unified application gateway providing reverse proxy, WAF, CC defense, OAuth2 authentication, ACME certificate automation, and GSLB for secure,…

A guided mutation-based fuzzer for ML-based Web Application Firewalls

Curated CSV collection of community-sourced Web Application Firewall bypass payloads for testing and validating WAF protections.

Modular password sprayer with SSH proxy rotation, MFA bypass, and domain recon. Supports O365, ADFS, OWA, Okta, Cisco VPN. Automates credential…

WAFNinja is a tool which contains two functions to attack Web Application Firewalls.

Analysing parameters with all payloads' bypass methods, aiming at benchmarking security solutions like WAF.

pentest on MagnoHost hosting provider & MeteorCloud infrastructure with 15+ servers mapped. Findings: MariaDB exposed on 6 servers, OmniDialer…

🛡️ Explore CVE-2025-55182, a critical RCE vulnerability in React's Flight Protocol, demonstrating exploitation techniques and mitigation strategies.

This Burp Suite extension allows for the automatic creation and deletion of an upstream SOCKS5 proxy on popular cloud services.

Cloud-based Web Application Firewall (WAF) providing L3/L7 protection against SQLi, XSS, DDoS, and bot attacks. Features AI assistant, anti-bot…

Multi-domain HTTP 403 bypass scanner that tests header manipulation techniques to discover hidden access paths on web servers, supporting bulk domain…