
lightbulb-framework
Tools for auditing WAFS

Tools for auditing WAFS

CVE-2025-6389

Detect and bypass web application firewalls and protection systems

A cheat sheet that contains advanced queries for SQL Injection of all types.

Quickjack is a point-and-click tool for intuitively producing advanced clickjacking and frame slicing attacks.

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

Professional-grade Denial of Service (DoS) exploitation framework for CVE-2025-55184 targeting React Server Components. Features 8 attack modes, WAF…

React2Shell: An exploitation framework for CVE-2025-55182 (Next.js/React RCE).

React2Shell-Exploit — Complete exploitation framework for CVE-2025-55182, including Python exploit, Docker vulnerable lab, Burp Suite manual and…

Automated Tool That Generates The Perfect Meterpreter Powershell Payload

a critical Remote Code Execution (RCE) vulnerability in React Server Components (RSC). It also includes a realistic "Lab Environment" to safely test…

This project demonstrates a Web Application Firewall (WAF) simulation using Flask and a vulnerability checker for CVE-2017-5638. The WAF middleware…

This room is based on exploiting the notorious Log4j vulnerability ( CVE-2021-44228), also referred to as the Log4Shell. The weakness enables…

Proof of Concept for the Log4Shell vulnerability (CVE-2021-44228), developed as part of the coursework for the curricular unit TPAS in the Master's…

Undetected version of the Playwright testing and automation library.

Tool for discovering the origin host behind a reverse proxy. Useful for bypassing cloud WAFs!

CF-Hero is a reconnaissance tool that uses multiple data sources to discover the origin IP addresses of Cloudflare-protected web applications

Firewall bypass script based on DNS history records. This script will search for DNS A history records and check if the server replies for that…