
Burp-Encode-IP
Burp Suite extension to encode an IP address focused to bypass application IP / domain blacklist.

Burp Suite extension to encode an IP address focused to bypass application IP / domain blacklist.

Generate primary obfuscated or secondary obfuscated CVE-2021-44228 or CVE-2021-45046 payloads to evade WAF detection.

A new way to exploit CVE-2025-58360 bypass WAF

Open-source IDS/IPS and WAF engine that analyzes logs and HTTP requests to detect and block malicious IPs, leveraging a crowdsourced community…

Automated Web Application Firewall fingerprinting tool that identifies and detects over 200 WAF products by analyzing HTTP responses to normal and…

CF-Hero is a reconnaissance tool that uses multiple data sources to discover the origin IP addresses of Cloudflare-protected web applications

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

Burpsuite Extension to bypass 403 restricted directory

🚫 Advanced tool for security researchers to bypass 403/40X restrictions through smart techniques and adaptive request manipulation. Fast. Precise.…

Burp extension to evade TLS fingerprinting. Bypass WAF, spoof any browser.

A Python library to utilize AWS API Gateway's large IP pool as a proxy to generate pseudo-infinite IPs for web scraping and brute forcing.

Burp Plugin to Bypass WAFs through the insertion of Junk Data

Extension for Burp Suite which uses AWS API Gateway to rotate your IP on every request.

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

A ready to use JSONP endpoints/payloads to help bypass content security policy (CSP) of different websites.

IP obfuscator made to make a malicious ip a bit cuter

A Burp Suite extension to help pentesters to bypass WAFs or test their effectiveness using a number of techniques

A Burp Suite extension for identifying injection flaws (LFI, RCE, SQLi), authentication/authorization issues, and HTTP 403 access violations. It…