awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
Back to codewatchorg/bypasswaf

Open-source alternatives to Bypasswaf

19 open-source projects similar to codewatchorg/bypasswaf, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best Bypasswaf alternative.

  • nccgroup/burpsuitehttpsmugglernccgroup avatar

    nccgroup/BurpSuiteHTTPSmuggler

    744View on GitHub↗

    A Burp Suite extension to help pentesters to bypass WAFs or test their effectiveness using a number of techniques

    Java
    View on GitHub↗744
  • assetnote/nowafplsassetnote avatar

    assetnote/nowafpls

    1,487View on GitHub↗

    Burp Plugin to Bypass WAFs through the insertion of Junk Data

    Python
    View on GitHub↗1,487
  • c0ny1/chunked-coding-converterc0ny1 avatar

    c0ny1/chunked-coding-converter

    2,033View on GitHub↗

    Burp suite 分块传输辅助插件

    Java
    View on GitHub↗2,033
  • ultimatehackers/xsstrikeUltimateHackers avatar

    UltimateHackers/XSStrike

    15,027View on GitHub↗

    XSStrike is a security tool designed to detect cross-site scripting vulnerabilities through parameter fuzzing and web response analysis. It functions as a web application fuzzer and vulnerability scanner that identifies injection points and security flaws. The project includes a specialized utility for detecting blind XSS, where payloads execute asynchronously or on separate pages. It also features a JavaScript library auditor to identify outdated libraries with known vulnerabilities and a dedicated tool for identifying and bypassing web application firewalls using various evasion techniques.

    Python
    View on GitHub↗15,027
  • audi-1/sqli-labsAudi-1 avatar

    Audi-1/sqli-labs

    5,791View on GitHub↗

    sqli-labs is a collection of intentionally vulnerable web applications and sandbox environments designed for practicing the identification and exploitation of SQL injection vulnerabilities. It serves as a cybersecurity education lab where users can experiment with database exploits in a controlled setting. The environment provides specialized modules for testing a wide range of attack vectors, including error-based, boolean-blind, and time-based injections. It specifically covers advanced techniques such as second-order injections, stacked queries, and attacks targeting HTTP headers. The pro

    PHP
    View on GitHub↗5,791

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Find more with AI search
  • gilzy/403bypasserGilzy avatar

    Gilzy/403Bypasser

    57View on GitHub↗

    A Burp Suite extension made to automate the process of bypassing 403 pages. Heavily based on Orange Tsai's talk Breaking Parser Logic: Take Your Path Normalization off and Pop 0days Out!

    Python
    View on GitHub↗57
  • intrudir/bypassfuzzer-burpI

    intrudir/BypassFuzzer-Burp

    0View on GitHub↗
    View on GitHub↗0
  • leveryd/x-wafL

    leveryd/x-waf

    0View on GitHub↗
    View on GitHub↗0
  • portswigger/random-ip-address-headerPortSwigger avatar

    PortSwigger/random-ip-address-header

    6View on GitHub↗
    Java
    View on GitHub↗6
  • sleeyax/burp-awesome-tlssleeyax avatar

    sleeyax/burp-awesome-tls

    1,835View on GitHub↗

    Burp extension to evade TLS fingerprinting. Bypass WAF, spoof any browser.

    Java
    View on GitHub↗1,835
  • sn1r/forbidden-busterSn1r avatar

    Sn1r/Forbidden-Buster

    247View on GitHub↗

    A tool designed to automate various techniques in order to bypass HTTP 401 and 403 response codes and gain access to unauthorized areas in the system. This code is made for security enthusiasts and professionals only. Use it at your own risk.

    Python
    View on GitHub↗247
  • sule01u/autorizeprosule01u avatar

    sule01u/AutorizePro

    609View on GitHub↗

    English README IS HERE

    Python
    View on GitHub↗609
  • thelsa/burp-unauth-checkerT

    theLSA/burp-unauth-checker

    0View on GitHub↗
    View on GitHub↗0
  • 0x727/bypasspro0

    0x727/BypassPro

    0View on GitHub↗
    View on GitHub↗0
  • vavkamil/xffenumvavkamil avatar

    vavkamil/XFFenum

    99View on GitHub↗

    X-Forwarded-For 403 forbidden enumeration

    Python
    View on GitHub↗99
  • akashc99/json-escaper-burp-suite-python-pluginakashc99 avatar

    akashc99/JSON-Escaper-Burp-Suite-Python-plugin

    2View on GitHub↗

    The JSON Escaper Burp Suite plugin simplifies the process of escaping JSON payloads for pentesters, as there is no built-in option for this in Burp.

    Python
    View on GitHub↗2
  • bao7uo/waf-cookie-fetcherB

    bao7uo/waf-cookie-fetcher

    0View on GitHub↗

    use a headless webkit/browser (PhantomJS) to obtain the values of WAF-injected cookies which are calculated in the browser by client-side JavaScript code and then add them to Burp's cookie jar - selectively remove specific cookies from Burp's cookie jar - empty Burp's cookie jar, for example to…

    View on GitHub↗0
  • chroblert/jc-antitokenC

    chroblert/JC-AntiToken

    0View on GitHub↗
    View on GitHub↗0
  • devploit/nomore403devploit avatar

    devploit/nomore403

    1,792View on GitHub↗

    🚫 Advanced tool for security researchers to bypass 403/40X restrictions through smart techniques and adaptive request manipulation. Fast. Precise. Effective.

    Go
    View on GitHub↗1,792