
liffy
Local file inclusion exploitation tool

Local file inclusion exploitation tool

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

Detect and bypass web application firewalls and protection systems

HackBar plugin for Burpsuite

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

WAFNinja is a tool which contains two functions to attack Web Application Firewalls.

Tests your WAF with +160 payloads

A SOCKS proxy written in Python that randomizes your source IP address. Round-robin your evil packets through SSH tunnels or give them billions of…

Tools for auditing WAFS

React Shell & Next.js RSC Exploit Tool (CVE-2025-55182)

This Burp Suite extension allows for the automatic creation and deletion of an upstream SOCKS5 proxy on popular cloud services.

Analysing parameters with all payloads' bypass methods, aiming at benchmarking security solutions like WAF.

Multi-domain HTTP 403 bypass scanner that tests header manipulation techniques to discover hidden access paths on web servers, supporting bulk domain…

Modular WAF bypass fuzzer with multi-threading, request manipulation, and payload encoding for red team web application testing.

YAML-driven framework for testing Web Application Firewall (WAF) rules using OWASP Core Rule Set baselines. Automates regression detection and…


Burp Suite extension to encode an IP address focused to bypass application IP / domain blacklist.