
cloudbunny
CloudBunny is a tool to capture the real IP of the server that uses a WAF as a proxy or protection. In this tool we used three search engines to…

CloudBunny is a tool to capture the real IP of the server that uses a WAF as a proxy or protection. In this tool we used three search engines to…

A PHP backdoor management and generation tool/C2 featuring end to end encrypted payload streaming designed to bypass WAF, IDS, SIEM systems.

Encoder to bypass WAF filters using XOR operations.

A tool designed to automate various techniques in order to bypass HTTP 401 and 403 response codes and gain access to unauthorized areas in the…

Takes a single wordlist item and tests it one by one over a large collection of websites before moving onto the next. Create signatures to…

XIP generates a list of IP addresses by applying a set of transformations used to bypass security measures e.g. blacklist filtering, WAF, etc.

From Dork to Download: Automating Google Dorks with Playwright

Tool to bypass 40X response codes.

Bash script that adds custom HTTP headers to requests for bulk testing of 403 bypass techniques on web applications.

Pre-auth path traversal to arbitrary file delete in Avada (Fusion) Builder <= 3.15.3 leading to RCE (CVSS 9.1)

This is a powerful and stealthy PHP reverse shell designed for ethical hacking and penetration testing. It establishes a reliable and quiet…

This script automates SQL injection testing using SQLMap with AI-powered decision making.


Disrupt WAF by abusing SSL/TLS Ciphers

This Log4j RCE exploit originated from https://github.com/tangxiaofeng7/CVE-2021-44228-Apache-Log4j-Rce

Exploit for CVE-2021-45468, an Imperva WAF bypass.

Flex QR Code Generator <= 1.2.5 - Unauthenticated Arbitrary File Upload