
web-threat-mitigation
Hands-on lab on detecting and mitigating web app threats using OWASP ZAP, Burp Suite, and ModSecurity WAF (with OWASP CRS). Case study: Spring4Shell…

Hands-on lab on detecting and mitigating web app threats using OWASP ZAP, Burp Suite, and ModSecurity WAF (with OWASP CRS). Case study: Spring4Shell…

A tool designed to automate various techniques in order to bypass HTTP 401 and 403 response codes and gain access to unauthorized areas in the…

XSSYA (Cross Site Scripting Scanner & Vulnerability Confirmation)

Generic attack detection rule set for web application firewalls, protecting against OWASP Top Ten and common vulnerabilities with minimal false…

A simple script just made for self use for bypassing 403

A Python library to utilize AWS API Gateway's large IP pool as a proxy to generate pseudo-infinite IPs for web scraping and brute forcing.

Extension for Burp Suite which uses AWS API Gateway to rotate your IP on every request.

↕️🤫 Stealth redirector for your red team operation security

🚫 Advanced tool for security researchers to bypass 403/40X restrictions through smart techniques and adaptive request manipulation. Fast. Precise.…

Automates HTTP 403 access control bypass techniques using header manipulation, path obfuscation, and HTTP method conversion for web application…

Exploit for Imperva Cloud WAF bypass using gzip Content-Encoding header to evade WAF rules on HTTP POST requests. Includes detection script and…

A firewall reverse proxy for preventing Log4J (Log4Shell aka CVE-2021-44228) attacks.

Bash script that adds custom HTTP headers to requests for bulk testing of 403 bypass techniques on web applications.

Header bypass for CVE-2025-55182 (React Server Components RCE).

Exploit for CVE-2021-45468, an Imperva WAF bypass.

Sorry, this tool WAS abandoned for a while. I got stress on this thing.

A penetration testing tool for bypassing HTTP 401/403 responses using various header manipulation techniques and path fuzzing.

Pre-authentication RCE exploit for CVE-2025-55182 (React2Shell) targeting React Server Components. Features scanning, OAST verification, WAF bypass,…