


Everything about Web Application Firewalls (WAFs) from Security Standpoint! 🔥

A cheat sheet that contains advanced queries for SQL Injection of all types.

Burp Plugin to Bypass WAFs through the insertion of Junk Data

Modular password sprayer with SSH proxy rotation, MFA bypass, and domain recon. Supports O365, ADFS, OWA, Okta, Cisco VPN. Automates credential…

Tool for discovering the origin host behind a reverse proxy. Useful for bypassing cloud WAFs!

Curated XSS payload collection and filter-bypass cheat sheet: WAF-specific evasion, JS/HTML injection vectors, encoding tricks, DOMPurify and…

The most powerful CRLF injection (HTTP Response Splitting) scanner.



React2Shell Ultimate - The most comprehensive CVE-2025-66478 Scanner for Next.js RSC RCE vulnerability. Multi-mode detection, WAF bypass, local…

XIP generates a list of IP addresses by applying a set of transformations used to bypass security measures e.g. blacklist filtering, WAF, etc.


This is the data that powers the PortSwigger URL validation bypass cheat sheet.


Log4Shell / Log4J Payload - CVE-2021-45046 and CVE-2022-42889

Exploit for CVE-2021-45468, an Imperva WAF bypass.