
waf-bypass
Automated WAF security testing tool that detects false positives and false negatives using 15+ payload categories including SQLi, XSS, RCE, and…

Automated WAF security testing tool that detects false positives and false negatives using 15+ payload categories including SQLi, XSS, RCE, and…

CloudBunny is a tool to capture the real IP of the server that uses a WAF as a proxy or protection. In this tool we used three search engines to…

Detect and bypass web application firewalls and protection systems

A tool designed to automate various techniques in order to bypass HTTP 401 and 403 response codes and gain access to unauthorized areas in the…

CF-Hero is a reconnaissance tool that uses multiple data sources to discover the origin IP addresses of Cloudflare-protected web applications

Automated Web Application Firewall fingerprinting tool that identifies and detects over 200 WAF products by analyzing HTTP responses to normal and…

Automated Αll-in-One OS command injection exploitation tool.

Like curl, but it gets past Anubis and Cloudflare bot-walls.

CVE-2025-29927 Proof of Concept

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses


First iteration of ML based Feedback WAF

teler-waf is a Go HTTP middleware that protects local web services from OWASP Top 10 threats, known vulnerabilities, malicious actors, botnets,…

Testing WAF protection against CVE-2021-44228 Log4Shell

Automatic SQL injection and database takeover tool

Disrupt WAF by abusing SSL/TLS Ciphers

Burp Plugin to Bypass WAFs through the insertion of Junk Data