
liffy
Local file inclusion exploitation tool

Local file inclusion exploitation tool

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Automates HTTP 403 access control bypass techniques using header manipulation, path obfuscation, and HTTP method conversion for web application…


🛡️ Open-source and cloud-native Web Application Firewall (WAF)

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. It has a robust event-based…

Everything about Web Application Firewalls (WAFs) from Security Standpoint! 🔥

Next generation web scanner

Automated Web Application Firewall fingerprinting tool that identifies and detects over 200 WAF products by analyzing HTTP responses to normal and…

Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

Generic attack detection rule set for web application firewalls, protecting against OWASP Top Ten and common vulnerabilities with minimal false…

Detect and bypass web application firewalls and protection systems

HackBar plugin for Burpsuite

Burp Plugin to Bypass WAFs through the insertion of Junk Data

Modular password sprayer with SSH proxy rotation, MFA bypass, and domain recon. Supports O365, ADFS, OWA, Okta, Cisco VPN. Automates credential…

Unified application gateway providing reverse proxy, WAF, CC defense, OAuth2 authentication, ACME certificate automation, and GSLB for secure,…

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).