
Bulk_403_Bypass
Bash script that adds custom HTTP headers to requests for bulk testing of 403 bypass techniques on web applications.

Bash script that adds custom HTTP headers to requests for bulk testing of 403 bypass techniques on web applications.

A ready to use JSONP endpoints/payloads to help bypass content security policy (CSP) of different websites.

Burp Plugin to Bypass WAFs through the insertion of Junk Data

A Burp Suite extension to help pentesters to bypass WAFs or test their effectiveness using a number of techniques

This room is based on exploiting the notorious Log4j vulnerability ( CVE-2021-44228), also referred to as the Log4Shell. The weakness enables…

Undetected version of the Playwright testing and automation library.

This Log4j RCE exploit originated from https://github.com/tangxiaofeng7/CVE-2021-44228-Apache-Log4j-Rce

Takes a single wordlist item and tests it one by one over a large collection of websites before moving onto the next. Create signatures to…

Unified application gateway providing reverse proxy, WAF, CC defense, OAuth2 authentication, ACME certificate automation, and GSLB for secure,…

Stuff that doesn't deserves its own repository.

From Dork to Download: Automating Google Dorks with Playwright

Burp Suite extension to encode an IP address focused to bypass application IP / domain blacklist.

Tool for discovering the origin host behind a reverse proxy. Useful for bypassing cloud WAFs!

Security Tool for Reconnaissance and Information Gathering on a website. (python 3.x)

Blind WAF identification tool

A SOCKS proxy written in Python that randomizes your source IP address. Round-robin your evil packets through SSH tunnels or give them billions of…

This Burp Suite extension allows for the automatic creation and deletion of an upstream SOCKS5 proxy on popular cloud services.

Reverse Engineer of Trust Decision Chinese Security