
evilwaf
Authorized WAF bypass proxy that rotates TCP/TLS/HTTP2 fingerprints, hunts origin IPs behind firewalls, and scans WAF defenses across 10 layers for…

Authorized WAF bypass proxy that rotates TCP/TLS/HTTP2 fingerprints, hunts origin IPs behind firewalls, and scans WAF defenses across 10 layers for…

Multi-technique XPath injection scanner with error-based, boolean/time-based blind, union, and auth bypass detection. Supports visible and blind data…

Mass exploit toolkit for CVE-2026-5524, an unauthenticated file upload RCE in Divi Form Builder. Features multi-threaded scanning, WAF bypass…

Security Tool for Reconnaissance and Information Gathering on a website. (python 3.x)

Uncovers origin IPs of Cloudflare-protected web apps using DNS records, historical DNS, Shodan/Censys/ZoomEye OSINT, and related-domain correlation…

From Dork to Download: Automating Google Dorks with Playwright

Automated scanner for CVE-2025-55182 (React2Shell) RCE vulnerability in React Server Components. Features async endpoint discovery, subdomain…

A Modular Framework for Pentesters and Bug Hunters written in python.

Advanced security testing tool for CVE-2025-55182 vulnerability assessment in Next.js applications. Features interactive shell, batch scanning, WAF…

Tests hundreds of URL bypass techniques against 40X protected pages using raw curl requests, with multi-mode scanning, header spoofing, and JSON/HTML…

Blind WAF identification tool that recognizes over 80 web protection systems by analyzing responses to non-destructive offensive payloads, enabling…

Discovers origin server IP addresses behind WAF-protected websites by querying Shodan, Censys, and ZoomEye search engines for domain information.

A ready to use JSONP endpoints/payloads to help bypass content security policy (CSP) of different websites.

Ruby-based tool to bypass Cloudflare protection by discovering the origin server's real IP address through DNS analysis, useful for testing server…

40X/HTTP bypasser in Go. Features: Verb tampering, headers, #bugbountytips, User-Agents, extensions, default credentials...

Plugins for Woodpecker framework: WebLogic T3/IIOP scanning, credential extraction, Spring Boot API scan, Log4j2 bypass payloads, and Java exec…

Automated web application security scanner detecting and exploiting RCE, SQL injection, and XSS vulnerabilities with WAF bypass payloads and backend…

Takes a single wordlist item and tests it one by one over a large collection of websites before moving onto the next. Create signatures to…