
bunkerweb
🛡️ Open-source and cloud-native Web Application Firewall (WAF)

🛡️ Open-source and cloud-native Web Application Firewall (WAF)

Multi-domain HTTP 403 bypass scanner that tests header manipulation techniques to discover hidden access paths on web servers, supporting bulk domain…

Automated Web Application Firewall fingerprinting tool that identifies and detects over 200 WAF products by analyzing HTTP responses to normal and…

Generic attack detection rule set for web application firewalls, protecting against OWASP Top Ten and common vulnerabilities with minimal false…

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

WAFNinja is a tool which contains two functions to attack Web Application Firewalls.

Curated CSV collection of community-sourced Web Application Firewall bypass payloads for testing and validating WAF protections.

Tests your WAF with +160 payloads

🛡️ Explore CVE-2025-55182, a critical RCE vulnerability in React's Flight Protocol, demonstrating exploitation techniques and mitigation strategies.

Minimal PoC and Docker container demonstrating a WAF bypass in OWASP ModSecurity CRS via multipart charset handling, leading to XSS payload delivery.

PoC for CVE-2025-41373 Authenticated SQL Injection in Gandia Integra Total v2.1.2217.3–4.4.2236.1

Analysing parameters with all payloads' bypass methods, aiming at benchmarking security solutions like WAF.

Python-based detector for FortiWeb authentication bypass (CVE-2025-xxxxx). Sends exploit payload to create a test user as proof of exploitation.

This project demonstrates a Web Application Firewall (WAF) simulation using Flask and a vulnerability checker for CVE-2017-5638. The WAF middleware…

HackBar plugin for Burpsuite

RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)