
WAFNinja
WAFNinja is a tool which contains two functions to attack Web Application Firewalls.

WAFNinja is a tool which contains two functions to attack Web Application Firewalls.

Like curl, but it gets past Anubis and Cloudflare bot-walls.

Automated WAF security testing tool that detects false positives and false negatives using 15+ payload categories including SQLi, XSS, RCE, and…

A tool designed to automate various techniques in order to bypass HTTP 401 and 403 response codes and gain access to unauthorized areas in the…

Proof-of-concept exploit for CVE-2025-55182, demonstrating unauthenticated RCE in Next.js App Router via server-side object injection in React Server…

IP obfuscator made to make a malicious ip a bit cuter

Automatic SQL injection and database takeover tool

A fast, simple, recursive content discovery tool written in Rust.

Automated Web Application Firewall fingerprinting tool that identifies and detects over 200 WAF products by analyzing HTTP responses to normal and…

A Burp Suite extension for identifying injection flaws (LFI, RCE, SQLi), authentication/authorization issues, and HTTP 403 access violations. It…

CloudBunny is a tool to capture the real IP of the server that uses a WAF as a proxy or protection. In this tool we used three search engines to…

React Shell & Next.js RSC Exploit Tool (CVE-2025-55182)

Bypass 4xx HTTP response status codes and more. The tool is based on Python Requests, PycURL, and HTTP Client.

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

Tool to bypass 40X response codes.

Next.js RSC RCE Exploit Tool (CVE-2025-55182)

An automatic SQL Injection tool which takes advantage of ~DorkNet~ Googler, Ddgr, WhatWaf and sqlmap.

A PHP backdoor management and generation tool/C2 featuring end to end encrypted payload streaming designed to bypass WAF, IDS, SIEM systems.