
nowafpls
Burp Plugin to Bypass WAFs through the insertion of Junk Data

Burp Plugin to Bypass WAFs through the insertion of Junk Data

A Burp Suite extension to help pentesters to bypass WAFs or test their effectiveness using a number of techniques

Exploit for Imperva Cloud WAF bypass using gzip Content-Encoding header to evade WAF rules on HTTP POST requests. Includes detection script and…

burp伪造ip爆破脚本

Flex QR Code Generator <= 1.2.5 - Unauthenticated Arbitrary File Upload

CVE-2025-55182-POC

A firewall reverse proxy for preventing Log4J (Log4Shell aka CVE-2021-44228) attacks.

Cloudflare Image Resizing <= 1.5.6 | Unauthenticated Remote Code Execution

Fun things against the abuse of the recent CVE-2021-44228 (Log4Shell) vulnerability using common web servers.

Header bypass for CVE-2025-55182 (React Server Components RCE).

Hands-on lab on detecting and mitigating web app threats using OWASP ZAP, Burp Suite, and ModSecurity WAF (with OWASP CRS). Case study: Spring4Shell…

Let's help websites stay safe until they are properly patched!

Proof-of-concept exploit for CVE-2026-21876 demonstrating multipart charset bypass of OWASP CRS WAF in Flask, ASP.NET, and Spring Boot applications.

Pre-authentication RCE exploit for CVE-2025-55182 (React2Shell) targeting React Server Components. Features scanning, OAST verification, WAF bypass,…

Exploit for CVE-2021-45468, an Imperva WAF bypass.

Exploit for CVE-2022-4539 that spoofs X-Forwarded-For headers to bypass WordPress WAF IP-based login and logging restrictions. Includes scalable…

Tool to bypass 40X response codes.

A Python library to utilize AWS API Gateway's large IP pool as a proxy to generate pseudo-infinite IPs for web scraping and brute forcing.