
liffy
Local file inclusion exploitation tool

Local file inclusion exploitation tool


🚫 Advanced tool for security researchers to bypass 403/40X restrictions through smart techniques and adaptive request manipulation. Fast. Precise.…

Modular WAF bypass fuzzer with multi-threading, request manipulation, and payload encoding for red team web application testing.

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

Burp Suite extension for automated detection and exploitation of HTTP request smuggling vulnerabilities, supporting HTTP/1.1 and HTTP/2-downgrade…

Advanced reconnaissance utility


evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

Advanced security testing tool for CVE-2025-55182 vulnerability assessment in Next.js applications. Features interactive shell, batch scanning, WAF…

Advanced React Server Components RCE scanner for CVE-2025-55182. Features: multi-stage fingerprinting, vulnerability verification, DNS exfiltration,…

Detect and bypass web application firewalls and protection systems

Advanced Exploitation Toolkit for Next.js Server Actions (CVE-2025-55182)

A cheat sheet that contains advanced queries for SQL Injection of all types.

A PHP backdoor management and generation tool/C2 featuring end to end encrypted payload streaming designed to bypass WAF, IDS, SIEM systems.

Advanced SQL Injection Scanner with AI-powered analysis, ethical compliance framework, and professional reporting.

Quickjack is a point-and-click tool for intuitively producing advanced clickjacking and frame slicing attacks.

Automated web security auditing tool that detects environment misconfigurations, probes backend vulnerabilities, and bypasses WAF/IDS protections…