
SafeLine
Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

🛡️ Open-source and cloud-native Web Application Firewall (WAF)

Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…


WAFNinja is a tool which contains two functions to attack Web Application Firewalls.

Unified application gateway providing reverse proxy, WAF, CC defense, OAuth2 authentication, ACME certificate automation, and GSLB for secure,…

HackBar plugin for Burpsuite

Tests your WAF with +160 payloads

Local file inclusion exploitation tool

AWS WAF Solver, full reverse implemented in 100% Python & Golang.

The most powerful CRLF injection (HTTP Response Splitting) scanner.

React Shell & Next.js RSC Exploit Tool (CVE-2025-55182)

Analysing parameters with all payloads' bypass methods, aiming at benchmarking security solutions like WAF.

Multi-domain HTTP 403 bypass scanner that tests header manipulation techniques to discover hidden access paths on web servers, supporting bulk domain…

Bypass 4xx HTTP response status codes and more. The tool is based on Python Requests, PycURL, and HTTP Client.

[漏洞复现] 全球首款利用PHP默认环境(XAMPP)的CVE-2024-4577 PHP-CGI RCE 漏洞 EXP。
