Detect and bypass web application firewalls and protection systems
β2,919Aug 11, 2024Updated last year
Alternatives and similar repositories for WhatWaf
Users that are interested in WhatWaf are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- WAFW00F allows one to identify and fingerprint Web Application Firewall (WAF) products protecting a website.β6,489Apr 19, 2026Updated 3 months ago
- Everything about Web Application Firewalls (WAFs) from Security Standpoint! π₯β7,561Mar 26, 2026Updated 4 months ago
- Automatic SSRF fuzzer and exploitation toolβ3,594Sep 4, 2025Updated 10 months ago
- A Tool for Domain Flyoversβ5,959May 22, 2022Updated 4 years ago
- Most advanced XSS scanner.β15,107Apr 26, 2025Updated last year
- Managed hosting for WordPress and PHP on Cloudways β’ AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Automatic bypass (brute force) wafβ993Mar 9, 2022Updated 4 years ago
- HTTP parameter discovery suite.β6,371Feb 20, 2025Updated last year
- A python script that finds endpoints in JavaScript filesβ4,429Apr 13, 2024Updated 2 years ago
- SSRF (Server Side Request Forgery) testing resourcesβ2,509Oct 12, 2024Updated last year
- WAFNinja is a tool which contains two functions to attack Web Application Firewalls.β829Dec 6, 2017Updated 8 years ago
- Next generation web scannerβ6,741Apr 2, 2026Updated 3 months ago
- Web application fuzzerβ6,545Jan 21, 2026Updated 6 months ago
- CMS Detection and Exploitation suite - Scan WordPress, Joomla, Drupal and over 180 other CMSsβ2,572Jul 17, 2026Updated last week
- JexBoss: Jboss (and Java Deserialization Vulnerabilities) verify and EXploitation Toolβ2,520Jan 21, 2020Updated 6 years ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits β’ AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- Web path scannerβ14,553Updated this week
- Server-Side Template Injection and Code Injection Detection and Exploitation Toolβ4,191Apr 21, 2024Updated 2 years ago
- Advanced reconnaissance utilityβ998Nov 20, 2023Updated 2 years ago
- Firewall bypass script based on DNS history records. This script will search for DNS A history records and check if the server replies foβ¦β1,299Sep 5, 2022Updated 3 years ago
- Automated penetration testing & attack surface management platform. Recon, scan, exploit, report β 600+ exploits, 90+ integrations, 10K+ β¦β10,644Jul 4, 2026Updated 3 weeks ago
- In-depth attack surface mapping and asset discoveryβ14,891Jul 19, 2026Updated last week
- Tool for automatic exploitation of XXE vulnerability using direct and different out of band methods.β1,782Dec 1, 2024Updated last year
- This tool can be used to brute discover GET and POST parametersβ1,396Aug 24, 2019Updated 6 years ago
- Fast passive subdomain enumeration tool.β14,087Updated this week
- Deploy on Railway without the complexity - Free Credits Offer β’ AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- A collection of Burpsuite Intruder payloads, BurpBounty payloads, fuzz lists, malicious file uploads and web pentesting methodologies andβ¦β3,965Sep 27, 2021Updated 4 years ago
- A swiss army knife for pentesting networksβ9,156Dec 6, 2023Updated 2 years ago
- File upload vulnerability scanner and exploitation tool.β3,329May 8, 2025Updated last year
- A high-performance DNS stub resolver for bulk lookups and reconnaissance (subdomain enumeration)β3,627Apr 15, 2026Updated 3 months ago
- Automated NoSQL database enumeration and web application exploitation tool.β3,332Updated this week
- ezXSS is an easy way for penetration testers and bug bounty hunters to test (blind) Cross Site Scripting.β2,324Jul 8, 2026Updated 3 weeks ago
- Totally Automatic LFI Exploiter (+ Reverse Shell) and Scannerβ1,958Apr 13, 2022Updated 4 years ago
- Sublert is a security and reconnaissance tool which leverages certificate transparency to automatically monitor new subdomains deployed bβ¦β1,033Feb 5, 2021Updated 5 years ago
- A powerful browser crawler for web vulnerability scannersβ3,037Mar 11, 2025Updated last year
- 1-Click AI Models by DigitalOcean Gradient β’ AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- A virtual host scanner that performs reverse lookups, can be used with pivot tools, detect catch-all scenarios, work around wildcards, alβ¦β1,310Aug 18, 2025Updated 11 months ago
- A fast port scanner written in go with a focus on reliability and simplicity. Designed to be used in combination with other tools for attβ¦β6,149Updated this week
- This tool generates gopher link for exploiting SSRF and gaining RCE in various serversβ3,400Apr 18, 2023Updated 3 years ago
- Knock Subdomain Scanβ4,174Feb 19, 2026Updated 5 months ago
- Awesome XSS stuffβ5,135Oct 30, 2024Updated last year
- A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.β8,998Dec 4, 2025Updated 7 months ago
- Burp Bounty (Scan Check Builder in BApp Store) is a extension of Burp Suite that allows you, in a quick and simple way, to improve the acβ¦β1,809Apr 26, 2024Updated 2 years ago