
HatCloud
Ruby-based tool to bypass Cloudflare protection by discovering the origin server's real IP address through DNS analysis, useful for testing server…

Ruby-based tool to bypass Cloudflare protection by discovering the origin server's real IP address through DNS analysis, useful for testing server…

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

Reverse-engineered tool to bypass Trust Decision security by generating dynamic fingerprints and tokens, exploiting TLS and payload verification…

Tests hundreds of URL bypass techniques against 40X protected pages using raw curl requests, with multi-mode scanning, header spoofing, and JSON/HTML…

Like curl, but it gets past Anubis and Cloudflare bot-walls.

Multi-vector exploit framework for CVE-2026-60206 targeting Oracle WebLogic Server SAML authentication bypass, with mass scanning, safe detection,…

Proof-of-concept exploit for CVE-2025-29927, demonstrating Next.js middleware authentication, authorization, and CSP bypass via the…

Reproduces CVE-2025-29927 middleware authorization bypass in Next.js 14.2.24 and demonstrates exploitation with curl to bypass authentication and…

🚫 Advanced tool for security researchers to bypass 403/40X restrictions through smart techniques and adaptive request manipulation. Fast. Precise.…

Automatic SQL injection and database takeover tool

A fast, simple, recursive content discovery tool written in Rust.

Automated Web Application Firewall fingerprinting tool that identifies and detects over 200 WAF products by analyzing HTTP responses to normal and…

Tool for discovering the origin host behind a reverse proxy. Useful for bypassing cloud WAFs!

Automated WAF security testing tool that detects false positives and false negatives using 15+ payload categories including SQLi, XSS, RCE, and…

Automated web reconnaissance tool with dork scanning, SQLi/XSS detection, port scanning, admin panel discovery, and WAF/captcha bypass capabilities.

Security Tool for Reconnaissance and Information Gathering on a website. (python 3.x)

Web application firewall testing tool with 344+ attack payloads, auto WAF detection, bypass techniques, and full reconnaissance including DNS,…

Local file inclusion exploitation tool