
evilwaf
evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

CF-Hero is a reconnaissance tool that uses multiple data sources to discover the origin IP addresses of Cloudflare-protected web applications

woodpecker-plugins

xpath is a fast, multi-technique XPath injection scanner written in Nim. It focuses on practical detection, response comparison, visible extraction,…

WebPwn3r - Web Applications Security Scanner.

Advanced security testing tool for CVE-2025-55182 vulnerability assessment in Next.js applications. Features interactive shell, batch scanning, WAF…

PoC for CVE-2017-5487 - WordPress User Enumeration via REST


From Dork to Download: Automating Google Dorks with Playwright


CVE-2025-61638 PoC

Automated Web Application Firewall fingerprinting tool that identifies and detects over 200 WAF products by analyzing HTTP responses to normal and…


Advanced reconnaissance utility

CloudBunny is a tool to capture the real IP of the server that uses a WAF as a proxy or protection. In this tool we used three search engines to…

Blind WAF identification tool

python3写的综合扫描工具,主要用来存活验证,敏感文件探测(目录扫描/js泄露接口/html注释泄露),WAF/CDN识别,端口扫描,指纹/服务识别,操作系统识别,POC扫描,SQL注入,绕过CDN,查询旁站等功能,主要用来甲方自测或乙方授权测试,请勿用来搞破坏。

A ready to use JSONP endpoints/payloads to help bypass content security policy (CSP) of different websites.