
liffy
Local file inclusion exploitation tool

Local file inclusion exploitation tool

AWS WAF Solver, full reverse implemented in 100% Python & Golang.

The most powerful CRLF injection (HTTP Response Splitting) scanner.

React Shell & Next.js RSC Exploit Tool (CVE-2025-55182)

Analysing parameters with all payloads' bypass methods, aiming at benchmarking security solutions like WAF.

Multi-domain HTTP 403 bypass scanner that tests header manipulation techniques to discover hidden access paths on web servers, supporting bulk domain…

Bypass 4xx HTTP response status codes and more. The tool is based on Python Requests, PycURL, and HTTP Client.

[漏洞复现] 全球首款利用PHP默认环境(XAMPP)的CVE-2024-4577 PHP-CGI RCE 漏洞 EXP。



A non-intrusive surface scanner for CVE-2025-55182 (React Server Components RCE). Detects exposed RSC endpoints in React 19 and Next.js applications

Web2 bug bounty Agent Skill — evidence-based, no AI slop. Covers 18 vulnerability classes across HackerOne, Bugcrowd, Intigriti, and YesWeHack.

Mass Hunting & Exploitation PoC for CVE-2025-55182 & CVE-2025-66478

log4j2 RCE漏洞(CVE-2021-44228)内网扫描器,可用于在不出网的条件下进行漏洞扫描,帮助企业内部快速发现Log4jShell漏洞。

nginx CVE scanner + RCE exploit framework (CVE-2026-42945 + 16 others)

CVE-2025-55182-bypass-waf

A Nuclei Template for Apache Log4j RCE (CVE-2021-44228) Detection with WAF Bypass Payloads