
nowafpls
Burp Plugin to Bypass WAFs through the insertion of Junk Data

Burp Plugin to Bypass WAFs through the insertion of Junk Data

Tests your WAF with +160 payloads

React Shell & Next.js RSC Exploit Tool (CVE-2025-55182)

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

Disrupt WAF by abusing SSL/TLS Ciphers

Multi-domain HTTP 403 bypass scanner that tests header manipulation techniques to discover hidden access paths on web servers, supporting bulk domain…

Burp Suite extension to encode an IP address focused to bypass application IP / domain blacklist.

C exploit for CVE-2025-59342 path traversal in esm.sh CDN (v136 and earlier). Injects payloads via X-Zone-Id header with WAF bypass and cookie…

Modular password sprayer with SSH proxy rotation, MFA bypass, and domain recon. Supports O365, ADFS, OWA, Okta, Cisco VPN. Automates credential…

HackBar plugin for Burpsuite

A SOCKS proxy written in Python that randomizes your source IP address. Round-robin your evil packets through SSH tunnels or give them billions of…

Local file inclusion exploitation tool

Tools for auditing WAFS

Analysing parameters with all payloads' bypass methods, aiming at benchmarking security solutions like WAF.

This Burp Suite extension allows for the automatic creation and deletion of an upstream SOCKS5 proxy on popular cloud services.

Python-based detector for FortiWeb authentication bypass (CVE-2025-xxxxx). Sends exploit payload to create a test user as proof of exploitation.

Proof-of-concept exploit for CVE-2020-6519, a Content Security Policy bypass vulnerability in Chromium 83, enabling full CSP bypass across platforms.