
liffy
Local file inclusion exploitation tool

Local file inclusion exploitation tool

Open-source IDS/IPS and WAF engine that analyzes logs and HTTP requests to detect and block malicious IPs, leveraging a crowdsourced community…

Bypass 4xx HTTP response status codes and more. The tool is based on Python Requests, PycURL, and HTTP Client.

Python-based interactive packet manipulation library for forging, decoding, sending, capturing, and analyzing network packets across a wide range of…

🛡️ Open-source and cloud-native Web Application Firewall (WAF)

Next generation web scanner

Burp extension to evade TLS fingerprinting. Bypass WAF, spoof any browser.

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

Firewall bypass script based on DNS history records. This script will search for DNS A history records and check if the server replies for that…


A SOCKS proxy written in Python that randomizes your source IP address. Round-robin your evil packets through SSH tunnels or give them billions of…

CVE-2021-44228 Log4j2 remote code injection exploit with JNDI payload generation, WAF bypass techniques, and practical exploitation walkthrough for…

Security Tool for Reconnaissance and Information Gathering on a website. (python 3.x)

A PHP backdoor management and generation tool/C2 featuring end to end encrypted payload streaming designed to bypass WAF, IDS, SIEM systems.

XSSYA (Cross Site Scripting Scanner & Vulnerability Confirmation)

From Dork to Download: Automating Google Dorks with Playwright

A Proof-Of-Concept Exploit for CVE-2021-44228 vulnerability.

CVE-2025-55182 RCE vulnerability in Next.js/React RSC servers (exploit and scanner)