
fire-wall-server
Python-based simulated firewall to detect and block Spring4Shell (CVE-2022-22965) exploit attempts. This project filters HTTP requests by identifying…

Python-based simulated firewall to detect and block Spring4Shell (CVE-2022-22965) exploit attempts. This project filters HTTP requests by identifying…

YAML-driven framework for testing Web Application Firewall (WAF) rules using OWASP Core Rule Set baselines. Automates regression detection and…

HTTP Request Smuggling

Exploit for CVE-2019-17638 targeting Jetty Java HTTP server, enabling remote code execution via crafted HTTP requests for security testing and…

A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory location beyond the header…

The most powerful CRLF injection (HTTP Response Splitting) scanner.

Windows-based C++ network scanner that fingerprints Cisco SD-WAN/vManage services and checks for CVE-2026-20127 exposure via HTTP endpoint analysis.

This project demonstrates a Web Application Firewall (WAF) simulation using Flask and a vulnerability checker for CVE-2017-5638. The WAF middleware…

Privaxy is the next generation tracker and advertisement blocker. It blocks ads and trackers by MITMing HTTP(s) traffic. Also check out my new…

Enumerates all HTML elements and attributes that can leak HTTP requests, enabling testing of browsers, web proxies, and email clients for unintended…

CVE-2021-41773 Exploit Lab

Fast and extensible multi-platform HTTP/1-2-3 web server with automatic HTTPS

CTF team website aggregating writeups and resources for web security challenges including XSS, SQLi, CSRF, SSRF, and XXE.

Docker Compose wrapper to deploy AperiSite, a curated platform hosting CTF writeups, security challenges, and educational resources covering web,…

The Browser Exploitation Framework Project

The OWASP NodeGoat project provides an environment to learn how OWASP Top 10 security risks apply to web applications developed using Node.js and how…

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

OWASP Top 10 for Large Language Model Apps (Part of the GenAI Security Project)