


Modular password sprayer with SSH proxy rotation, MFA bypass, and domain recon. Supports O365, ADFS, OWA, Okta, Cisco VPN. Automates credential…

Tool for discovering the origin host behind a reverse proxy. Useful for bypassing cloud WAFs!

The most powerful CRLF injection (HTTP Response Splitting) scanner.

React2Shell Ultimate - The most comprehensive CVE-2025-66478 Scanner for Next.js RSC RCE vulnerability. Multi-mode detection, WAF bypass, local…

XIP generates a list of IP addresses by applying a set of transformations used to bypass security measures e.g. blacklist filtering, WAF, etc.

Burp Plugin to Bypass WAFs through the insertion of Junk Data




Exploit for CVE-2021-45468, an Imperva WAF bypass.

Precision-Based Detection of RSC/Next.js Remote Code Execution Vulnerabilities (CVE-2025-55182, CVE-2025-66478)

Everything about Web Application Firewalls (WAFs) from Security Standpoint! 🔥

A cheat sheet that contains advanced queries for SQL Injection of all types.

Curated XSS payload collection and filter-bypass cheat sheet: WAF-specific evasion, JS/HTML injection vectors, encoding tricks, DOMPurify and…


This is the data that powers the PortSwigger URL validation bypass cheat sheet.