{"repo":"matrixleons/evilwaf","free":true,"listed":false,"github":"https://github.com/matrixleons/evilwaf","clone":"git clone https://github.com/matrixleons/evilwaf.git","description":"evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).","language":"Python","stars":886,"topics":["bug-bounty-tools","mitm-proxy","proxy","waf-bypass-tool","firewall","pentest","red-team","waf","waf-bypass"],"license":null,"category":"networking-infra","readme_excerpt":"--- EvilWAF is an advanced transparent MITM Firewall bypass proxy and deep WAF vulnerability scanner designed for authorized security testing. It operates at the transport layer — it does not touch payloads, cookies, or headers from your tools. Works with any tool like( ffuz , sqlmap , nuclei and etc) that supports --proxy . --- Features Proxy & Bypass - Transparent MITM Proxy — Works with any tool that supports --proxy . Zero configuration on tool side. - TCP Fingerprint Rotation — Rotates TCP stack options per request to avoid behavioral detection. - TLS Fingerprint Rotation — Rotates TLS fingerprint (JA3/JA4 style) paired with TCP profiles. - HTTP/2 Fingerprint Rotation — Per-request H2 SETTINGS and HEADERS frame profile rotation cycling through Chrome, Firefox, Safari, and Edge profiles to prevent WAF behavioral fingerprinting. - Source Port Manipulation — Rotates source port per request, breaking WAF session tracking and rate-limit counters that rely on source port consistency. - Cloudflare Header Injection — Injects Cloudflare-specific internal headers ( CF-Connecting-IP , CF-Ray , True-Client-IP ) with crafted values to test WAF header trust and attempt IP allowlist bypass. - Tor IP Rotation — Routes traffic through Tor and rotates exit IP every request automatically. - Proxy Pool IP Rotation — Rotates IP every request through external proxy pool. - Origin IP Hunter — Discovers the real server IP behind the WAF using 10 parallel scanners: - DNS history, SSL certificate","default_branch":null,"files":null,"tree":[],"storefront":"/r/matrixleons","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/matrixleons/evilwaf/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}