
evilwaf
evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

WAFNinja is a tool which contains two functions to attack Web Application Firewalls.

SQL Injection Exploitation Tool

A vulnerable Android application that shows simple examples of vulnerabilities in a ctf style.

Simple DNS Rebinding Service

Intentionally vulnerable Android banking app for practicing mobile security testing, featuring root detection, anti-debugging, SSL pinning, and…

Fermion, an electron wrapper for Frida & Monaco.

application server attack toolkit

Command line tool to fetch, decode, brute-force and craft session cookies of a Flask application by guessing secret keys.

a very fast brute force webshell password tool

Python script to inject existing Android applications with a Meterpreter payload.

A Microservices-based framework for the study of Network Security and Penetration Test techniques

htcap is a web application scanner able to crawl single page application (SPA) recursively by intercepting ajax calls and DOM changes.

Full exploit chain (CVE-2019-11708 & CVE-2019-9810) against Firefox on Windows 64-bit.

CuckooDroid - Automated Android Malware Analysis with Cuckoo Sandbox.

An intentionally designed broken web application based on REST API.

Detects and exploits HTTP request smuggling vulnerabilities via HTTP/2 to HTTP/1.1 conversion, using automated header smuggling techniques to…

A tool designed to assist with finding all sinks and sources of a web application and display these results in a digestible manner.