命令执行写任意文件,主要用于命令执行但不出网情况
☆31Sep 9, 2023Updated 2 years ago
Alternatives and similar repositories for putter
Users that are interested in putter are comparing it to the libraries listed below
Sorting:
- php webshell bypass D盾、safedog、360、火绒等,仅支持php7☆18Aug 25, 2025Updated 6 months ago
- 适用于某EHR&HRM的加解密工具,可直接用于sqlmap☆25Jan 14, 2024Updated 2 years ago
- ☆28Aug 12, 2023Updated 2 years ago
- exchange接口爆破|邮箱爆破☆20Sep 19, 2024Updated last year
- 帆软bi反序列化漏洞利用工具☆56Jun 4, 2024Updated last year
- c3p0 new gadget☆28Apr 1, 2025Updated 11 months ago
- 某软最新公开gadgegt,新加入不出网利用。☆89Sep 6, 2024Updated last year
- ActiveMQ RCE (CVE-2023-46604) 回显利用工具☆41Sep 13, 2024Updated last year
- druid数据库密码解密☆37Apr 7, 2023Updated 2 years ago
- Spring Boot whitelabel error page SpEL rce EXP☆13May 24, 2024Updated last year
- 帆软报表漏洞检测工具☆114Jun 10, 2025Updated 9 months ago
- 检测域内常见一把梭漏洞,包括:NoPac、ZeroLogon、CVE-2022-26923、PrintNightMare☆79Oct 23, 2023Updated 2 years ago
- 哥斯拉Hikvision综合安防后渗透插件,运行中心/web前台/MinIO 配置提取(解密)重置密码,还原密码。☆170Oct 8, 2024Updated last year
- ☆37Jun 9, 2023Updated 2 years ago
- vcenter图形化漏洞利用工具☆70Nov 17, 2024Updated last year
- golang实现通过dcerpc和ntlmssp获取Windows远程主机信息☆28Apr 16, 2024Updated last year
- 用于windows反弹shell的yaml-payload☆71Jun 26, 2021Updated 4 years ago
- 一款linux 内网渗透辅助工具☆77Jan 31, 2024Updated 2 years ago
- 《深入JDBC安全:特殊URL构造与不出网反序列化利用技术揭秘》对应研究总结项目 "Deep Dive into JDBC Security: Special URL Construction and Non-Networked Deserialization Explo…☆572Feb 7, 2026Updated last month
- ☆40Nov 25, 2024Updated last year
- 专为渗透小白定制的SQL注入靶场,上手简单(巨难),练习sql注入的不二之选☆59Jun 12, 2025Updated 9 months ago
- 亿赛通电子文档安全管理系统XStream反序列化漏洞任意文件上传利用☆120Aug 9, 2024Updated last year
- 一个用友漏洞检测工具☆29May 15, 2024Updated last year
- 三色哥斯拉(Godzilla)☆68Dec 27, 2024Updated last year
- CVE-2021-42287/CVE-2021-42278 Exploiter☆13Jan 12, 2023Updated 3 years ago
- Burpsuite extension. Supports ASP.NET ViewStateDecoder☆33Mar 1, 2026Updated 3 weeks ago
- 对Exchange Proxyshell 做了二次修改,精确的拆分、实现辅助性安全测试。☆17Nov 23, 2021Updated 4 years ago
- 用于网站(HTTP)自动化判断开放和网页快照拍摄☆12Jan 25, 2021Updated 5 years ago
- 一个能够利用MSSQL的xp_cmdshell功能来进行流量代理的脚本,用于在站酷分离且不出网SQL注入进行代理☆107Sep 19, 2022Updated 3 years ago
- xxl-job内存马☆227Jan 26, 2025Updated last year
- "闪紫"(英文名shiningZ)社工字典生成工具,支持ABC自定义排列组合、ABC列字典AI扩展、AI提示词联想字典、自定义AI提示、字典去重、结果导出等☆31Oct 27, 2025Updated 4 months ago
- java实现反序列化建立socket连接☆60Dec 27, 2024Updated last year
- 用友的一些反序列化链子以及1day,二开了狼组的YongYouNcTool,改了一下逻辑以及poc☆124Oct 12, 2024Updated last year
- riverPass 是一个用Go编写的瑞数WAF绕过工具。它利用了WebSocket协议,将请求发送的自身浏览器中,从而绕过了瑞数WAF的检测。☆234Oct 18, 2024Updated last year
- Yonyou-UNSERIALIZE,用友NC 反序列化检查工具,批量检测用友NC 反序列化☆50Jul 21, 2023Updated 2 years ago
- 用java实现构造openwire协议,利用activeMQ < 5.18.3 RCE 回显利用 内存马注入☆288Nov 20, 2023Updated 2 years ago
- 如果反序列化过程中使用resolveClass拉黑了TemplatesImpl如何绕过☆53Sep 10, 2023Updated 2 years ago
- 哥斯拉nacos后渗透插件 maketoken adduser☆150Jul 7, 2023Updated 2 years ago
- JumpServer 堡垒机未授权综合漏洞利用, Exploit for CVE-2023-42442 / CVE-2023-42820 / RCE 2021☆273Jun 6, 2025Updated 9 months ago