
WAFNinja
WAFNinja is a tool which contains two functions to attack Web Application Firewalls.

WAFNinja is a tool which contains two functions to attack Web Application Firewalls.

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

Detect and bypass web application firewalls and protection systems

Modular WAF bypass fuzzer with multi-threading, request manipulation, and payload encoding for red team web application testing.

YAML-driven framework for testing Web Application Firewall (WAF) rules using OWASP Core Rule Set baselines. Automates regression detection and…

Tests your WAF with +160 payloads

React Shell & Next.js RSC Exploit Tool (CVE-2025-55182)


Disrupt WAF by abusing SSL/TLS Ciphers


Multi-domain HTTP 403 bypass scanner that tests header manipulation techniques to discover hidden access paths on web servers, supporting bulk domain…

Burp Suite extension to encode an IP address focused to bypass application IP / domain blacklist.

Exploit Path Traversal in esm-dev

Local file inclusion exploitation tool

HackBar plugin for Burpsuite

A SOCKS proxy written in Python that randomizes your source IP address. Round-robin your evil packets through SSH tunnels or give them billions of…

Tools for auditing WAFS