
log4shell-coraza
Log4Shell (CVE-2021-44228) defense lab — nginx + Coraza WAF dynamic module + OWASP CRS v4. Educational use only.

Log4Shell (CVE-2021-44228) defense lab — nginx + Coraza WAF dynamic module + OWASP CRS v4. Educational use only.

CVE-2025-6389

A new way to exploit CVE-2025-58360 bypass WAF

react2shell PoC with Go / CVE-2025-55182

Detect CVE-2025-55182 & CVE-2025-66478 in Next.js/RSC applications (Rust)

High-performance Rust HTTP/HTTPS proxy with active defense: rate limiting, reputation-based access, WAF (anti-bot, anti-injection, path protection),…

A Log4j vulnerability scanner is used to identify the CVE-2021-44228 and CVE_2021_45046

Minimal PoC and Docker container demonstrating a WAF bypass in OWASP ModSecurity CRS via multipart charset handling, leading to XSS payload delivery.

CVE-2025-55182 & CVE-2025-66478 proof of concepts

Spring4Shell (CVE-2022-22965) DFIR lab with exploit simulation, Python WAF, IOC-based detection, and PCAP analysis.

Let's help websites stay safe until they are properly patched!

Details : CVE-2021-44228

Hands-on lab on detecting and mitigating web app threats using OWASP ZAP, Burp Suite, and ModSecurity WAF (with OWASP CRS). Case study: Spring4Shell…

CVE-2025-55182-POC

Log4j-RCE (CVE-2021-44228) Proof of Concept

Reproduces CVE-2025-29927 middleware authorization bypass in Next.js 14.2.24 and demonstrates exploitation with curl to bypass authentication and…

XSStrike based XSS scanner with custom features. Detects XSS vulnerabilities in web applications.

Go tool that passively discovers the real origin IP behind a WAF/CDN using multiple OSINT sources, then verifies candidates via HTML similarity, SSL…