
dontgo403
Tool to bypass 40X response codes.

Tool to bypass 40X response codes.

burp伪造ip爆破脚本

Bash script that adds custom HTTP headers to requests for bulk testing of 403 bypass techniques on web applications.

Stop getting 403 Forbidden. A specialized httpx-like toolkit for WAF evasion.

Header bypass for CVE-2025-55182 (React Server Components RCE).

Exploit for CVE-2021-45468, an Imperva WAF bypass.

Cloudflare Image Resizing <= 1.5.6 | Unauthenticated Remote Code Execution

Fun things against the abuse of the recent CVE-2021-44228 (Log4Shell) vulnerability using common web servers.

Let's help websites stay safe until they are properly patched!

CVE-2025-55182-POC

NAXSI is an open-source, high performance, low rules maintenance WAF for NGINX

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses


Successor of Undetected-Chromedriver. Providing a blazing fast framework for web automation, webscraping, bots and any other creative ideas which are…

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

Firewall bypass script based on DNS history records. This script will search for DNS A history records and check if the server replies for that…

From Dork to Download: Automating Google Dorks with Playwright

Exploit Path Traversal in esm-dev