
BounceBack
↕️🤫 Stealth redirector for your red team operation security

↕️🤫 Stealth redirector for your red team operation security

Modular WAF bypass fuzzer with multi-threading, request manipulation, and payload encoding for red team web application testing.

This is a powerful and stealthy PHP reverse shell designed for ethical hacking and penetration testing. It establishes a reliable and quiet…

Stealth dropper executing remote binaries without dropping them on disk .(HTTP3 support, ICMP support, invisible tracks, cross-platform,...)

React2Shell Ultimate - The most comprehensive CVE-2025-66478 Scanner for Next.js RSC RCE vulnerability. Multi-mode detection, WAF bypass, local…

nginx CVE scanner + RCE exploit framework (CVE-2026-42945 + 16 others)

CVE-2025-55182 RCE vulnerability in Next.js/React RSC servers (exploit and scanner)

Next.js RSC RCE vulnerability scanner with multiple scan modes, WAF bypass, interactive shell, and batch scanning for authorized penetration testing.

Hands-on lab exercise for exploiting Log4Shell (CVE-2021-44228) with JNDI injection, LDAP referral servers, and reverse shell payloads. Includes…

IP obfuscator made to make a malicious ip a bit cuter

React Shell & Next.js RSC Exploit Tool (CVE-2025-55182)

A PHP backdoor management and generation tool/C2 featuring end to end encrypted payload streaming designed to bypass WAF, IDS, SIEM systems.

Exploit for CVE-2025-55182 & CVE-2025-66478

A non-intrusive surface scanner for CVE-2025-55182 (React Server Components RCE). Detects exposed RSC endpoints in React 19 and Next.js applications

Burp Suite extension to encode an IP address focused to bypass application IP / domain blacklist.

Advanced Exploitation Toolkit for Next.js Server Actions (CVE-2025-55182)

Mass Hunting & Exploitation PoC for CVE-2025-55182 & CVE-2025-66478

一個測試CVE-2024-4577和CVE-2024-8926的安全滲透工具