
WAFNinja
WAFNinja is a tool which contains two functions to attack Web Application Firewalls.

WAFNinja is a tool which contains two functions to attack Web Application Firewalls.

python3写的综合扫描工具,主要用来存活验证,敏感文件探测(目录扫描/js泄露接口/html注释泄露),WAF/CDN识别,端口扫描,指纹/服务识别,操作系统识别,POC扫描,SQL注入,绕过CDN,查询旁站等功能,主要用来甲方自测或乙方授权测试,请勿用来搞破坏。

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

Burp Plugin to Bypass WAFs through the insertion of Junk Data

Automated WAF security testing tool that detects false positives and false negatives using 15+ payload categories including SQLi, XSS, RCE, and…

Local file inclusion exploitation tool

Xss Payload Generator ~ Xss Scanner ~ Xss Dork Finder


Black-box regex fuzzing tool that generates payloads to bypass input validations, discover normalizations, and evade WAFs in web applications.

IP obfuscator made to make a malicious ip a bit cuter

WebPwn3r - Web Applications Security Scanner.

AWS WAF Solver, full reverse implemented in 100% Python & Golang.

teler-waf is a Go HTTP middleware that protects local web services from OWASP Top 10 threats, known vulnerabilities, malicious actors, botnets,…

Multi-domain HTTP 403 bypass scanner that tests header manipulation techniques to discover hidden access paths on web servers, supporting bulk domain…

Stealth dropper executing remote binaries without dropping them on disk .(HTTP3 support, ICMP support, invisible tracks, cross-platform,...)

XSSYA (Cross Site Scripting Scanner & Vulnerability Confirmation)


Disrupt WAF by abusing SSL/TLS Ciphers