
coreruleset
Generic attack detection rule set for web application firewalls, protecting against OWASP Top Ten and common vulnerabilities with minimal false…

Generic attack detection rule set for web application firewalls, protecting against OWASP Top Ten and common vulnerabilities with minimal false…

Best DDoS Attack Script Python3, (Cyber / DDos) Attack With 56 Methods

↕️🤫 Stealth redirector for your red team operation security

A Python library to utilize AWS API Gateway's large IP pool as a proxy to generate pseudo-infinite IPs for web scraping and brute forcing.

🚫 Advanced tool for security researchers to bypass 403/40X restrictions through smart techniques and adaptive request manipulation. Fast. Precise.…

Proof-of-concept exploit for CVE-2026-21876 demonstrating multipart charset bypass of OWASP CRS WAF in Flask, ASP.NET, and Spring Boot applications.

Pre-authentication RCE exploit for CVE-2025-55182 (React2Shell) targeting React Server Components. Features scanning, OAST verification, WAF bypass,…

Extension for Burp Suite which uses AWS API Gateway to rotate your IP on every request.

Header bypass for CVE-2025-55182 (React Server Components RCE).

CVE-2025-55182-POC

Let's help websites stay safe until they are properly patched!

Flex QR Code Generator <= 1.2.5 - Unauthenticated Arbitrary File Upload

Bypass 4xx HTTP response status codes and more. The tool is based on Python Requests, PycURL, and HTTP Client.

PyMultitor - Python Multi Threaded Tor Proxy

Cloudflare Image Resizing <= 1.5.6 | Unauthenticated Remote Code Execution

Burp Plugin to Bypass WAFs through the insertion of Junk Data

Hands-on lab on detecting and mitigating web app threats using OWASP ZAP, Burp Suite, and ModSecurity WAF (with OWASP CRS). Case study: Spring4Shell…

A penetration testing tool for bypassing HTTP 401/403 responses using various header manipulation techniques and path fuzzing.