
identYwaf
Blind WAF identification tool

Blind WAF identification tool

CloudBunny is a tool to capture the real IP of the server that uses a WAF as a proxy or protection. In this tool we used three search engines to…

Quickjack is a point-and-click tool for intuitively producing advanced clickjacking and frame slicing attacks.

React Shell & Next.js RSC Exploit Tool (CVE-2025-55182)

A tool designed to automate various techniques in order to bypass HTTP 401 and 403 response codes and gain access to unauthorized areas in the…

Bypass 4xx HTTP response status codes and more. The tool is based on Python Requests, PycURL, and HTTP Client.

XSS Fuzzer is a tool which generates XSS payloads based on user-defined vectors and fuzzing lists.

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

Tool to bypass 40X response codes.

Next.js RSC RCE Exploit Tool (CVE-2025-55182)

Sorry, this tool WAS abandoned for a while. I got stress on this thing.

A penetration testing tool for bypassing HTTP 401/403 responses using various header manipulation techniques and path fuzzing.

Go-based scanner and exploitation tool for CVE-2025-55182 (Next.js RCE). Supports batch scanning, command execution, Godzilla memory shell injection,…

CVE-2025-55182 & CVE-2025-66478 Detection Tool for Next.js RSC RCE

Automated exploit tool for CVE-2026-1357, an unauthenticated RCE in WPvivid Backup & Migration. Scans WordPress targets, bypasses WAF/403, uploads a…

An automatic SQL Injection tool which takes advantage of ~DorkNet~ Googler, Ddgr, WhatWaf and sqlmap.

Automated Tool That Generates The Perfect Meterpreter Powershell Payload

A PHP backdoor management and generation tool/C2 featuring end to end encrypted payload streaming designed to bypass WAF, IDS, SIEM systems.