
liffy
Local file inclusion exploitation tool

Local file inclusion exploitation tool

Open-source IDS/IPS and WAF engine that analyzes logs and HTTP requests to detect and block malicious IPs, leveraging a crowdsourced community…

Bypass 4xx HTTP response status codes and more. The tool is based on Python Requests, PycURL, and HTTP Client.

Burp extension to evade TLS fingerprinting. Bypass WAF, spoof any browser.


A PHP backdoor management and generation tool/C2 featuring end to end encrypted payload streaming designed to bypass WAF, IDS, SIEM systems.

A Proof-Of-Concept Exploit for CVE-2021-44228 vulnerability.

Advanced security testing tool for CVE-2025-55182 vulnerability assessment in Next.js applications. Features interactive shell, batch scanning, WAF…

Fun things against the abuse of the recent CVE-2021-44228 (Log4Shell) vulnerability using common web servers.

CVE-2025-55182 RCE vulnerability in Next.js/React RSC servers (exploit and scanner)

A evolved version of assetnote CVE-2025-55182 scanner

An advanced command-line framework for discovery, validation, and exploitation of CVE-2025-55182 and CVE-2025-66478 affecting Next.js applications…

React/Next.js React4Shell RCE CVE-2025-55182 checker


CVE-2025-6389

🛡️ Explore CVE-2025-55182, a critical RCE vulnerability in React's Flight Protocol, demonstrating exploitation techniques and mitigation strategies.