
log4j-CVE-2021-44228
CVE-2021-44228

CVE-2021-44228

a simple react2shell poc with basic waf bypass

CVE-2025-6389


Disrupt WAF by abusing SSL/TLS Ciphers

CloudBunny is a tool to capture the real IP of the server that uses a WAF as a proxy or protection. In this tool we used three search engines to…

XIP generates a list of IP addresses by applying a set of transformations used to bypass security measures e.g. blacklist filtering, WAF, etc.

Automates HTTP 403 access control bypass techniques using header manipulation, path obfuscation, and HTTP method conversion for web application…

A simple script just made for self use for bypassing 403

Stealth dropper executing remote binaries without dropping them on disk .(HTTP3 support, ICMP support, invisible tracks, cross-platform,...)