
mitmproxy
An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Bypass 4xx HTTP response status codes and more. The tool is based on Python Requests, PycURL, and HTTP Client.

Automates HTTP 403 access control bypass techniques using header manipulation, path obfuscation, and HTTP method conversion for web application…

Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…

Extension for Burp Suite which uses AWS API Gateway to rotate your IP on every request.

Exploit for CVE-2024-4577 PHP-CGI RCE on Windows, with WAF bypass and SSRF support. Provides multiple exploit variants for default, WAF, and SSRF…

Multi-domain HTTP 403 bypass scanner that tests header manipulation techniques to discover hidden access paths on web servers, supporting bulk domain…

Bash script that adds custom HTTP headers to requests for bulk testing of 403 bypass techniques on web applications.

Reverse Engineer of Trust Decision Chinese Security

Agentic Pentesting MCP server that discovers, exploits, and reports web application vulnerabilities.

WordPress Pre-Auth RCE Exploit + Scanner + WAF Bypass | CVE-2026-63030 + CVE-2026-60137 | Go + Python + Metasploit modules + Docker lab

This Burp Suite extension allows for the automatic creation and deletion of an upstream SOCKS5 proxy on popular cloud services.

A simple script just made for self use for bypassing 403

Firewall bypass script based on DNS history records. This script will search for DNS A history records and check if the server replies for that…

XSS Fuzzer is a tool which generates XSS payloads based on user-defined vectors and fuzzing lists.

Security Tool for Reconnaissance and Information Gathering on a website. (python 3.x)

Stealth dropper executing remote binaries without dropping them on disk .(HTTP3 support, ICMP support, invisible tracks, cross-platform,...)