翻译国外的@WebBreacher的安全/渗透测试/红队面试题,有部分参考作用
☆283Aug 5, 2023Updated 2 years ago
Alternatives and similar repositories for offensiveinterview
Users that are interested in offensiveinterview are comparing it to the libraries listed below
Sorting:
- 个人准备渗透测试和安全面试的经验之谈,和去部分厂商的面试题,干货真的满满~☆1,969Sep 18, 2021Updated 4 years ago
- 在渗透测试中快速检测常见中间件、组件的高危漏洞。☆728Mar 21, 2022Updated 3 years ago
- 用于记录分享一些有趣的案例☆866Jan 10, 2022Updated 4 years ago
- BCS(北京网络安全大会)2019 红队行动会议重点内容☆819Sep 4, 2019Updated 6 years ago
- 用于辅助安全工程师漏洞挖掘、测试、复现,集合了mock、httplog、dns tools、xss,可用于测试各类无回显、无法直观判断或特定场景下的漏洞。☆866Jul 21, 2019Updated 6 years ago
- 免杀webshell无 限生成工具☆1,288Apr 3, 2020Updated 5 years ago
- MSSQL注入提权,bypass的一些总结☆737Jun 25, 2024Updated last year
- 绿盟科技漏洞扫描器(RSAS)漏洞库☆366May 30, 2019Updated 6 years ago
- Information Security (Web Security/Penetration Testing Direction) Interview Questions/Solutions 信息安全(Web安全/渗透测试方向)面试题/解题思路☆479Jul 25, 2019Updated 6 years ago
- 信息安全方面面试清单☆291Feb 2, 2024Updated 2 years ago
- Burp suite 分块传输辅助插件☆2,023Feb 23, 2022Updated 4 years ago
- ATT&CK实操☆373Sep 7, 2019Updated 6 years ago
- 瓶颈渗透,web渗透,red红队,fuzz param,注释,js字典,ctf☆717Jul 20, 2022Updated 3 years ago
- Java安全相关的漏洞和技术demo,原生Java、Fastjson、Jackson、Hessian2、XML反序列化漏洞利用和Spring、Dubbo、Shiro、CAS、Tomcat、RMI、Nexus等框架\中间件\功能的exploits以及Java Security…☆2,689Mar 14, 2024Updated last year
- 从wooyun中提取的payload,以及burp插件☆842Jun 17, 2022Updated 3 years ago
- 红队基础设施自动化部署工具☆852Jan 4, 2023Updated 3 years ago
- Airbug(空气洞),收集漏洞poc用于安全产品☆355Sep 26, 2019Updated 6 years ago
- Cobalt Strike系列☆2,413Dec 3, 2023Updated 2 years ago
- PC客户端(C-S架构)渗透测试checklist / Client side(C-S) penetration checklist☆663Feb 24, 2021Updated 5 years ago
- 360/0Kee-Team/crawlergo动态爬虫结合长亭XRAY扫描器的被动扫描功能☆1,183Nov 10, 2021Updated 4 years ago
- 一个包含php,java,python,C#等各种语言版本的XXE漏洞Demo☆815Nov 28, 2022Updated 3 years ago
- RedTeam资料收集整理☆328Dec 10, 2020Updated 5 years ago
- 渗透测试用到的东东☆428May 6, 2020Updated 5 years ago
- Burp被动扫描流量转发插件☆1,460Jun 17, 2024Updated last year
- mysql注入,bypass的一些心得☆1,326Jun 25, 2024Updated last year
- Tomcat-Ajp协议文件读取漏洞☆797Mar 3, 2020Updated 6 years ago
- 上传漏洞fuzz字典生成脚本☆1,270Apr 1, 2021Updated 4 years ago
- 一个各种方式突破Disable_functions达到命令执行的shell☆1,198Oct 17, 2023Updated 2 years ago
- Redis 4.x/5.x RCE☆975Nov 30, 2021Updated 4 years ago
- 关于ThinkPHP框架的历史漏洞分析集合☆1,118Jan 18, 2020Updated 6 years ago
- PocHubs是为了整合网上知名开源框架的漏洞详细和POC☆230Jun 19, 2019Updated 6 years ago
- KunLun-M是一个完全开源的静态白盒扫描工具,支持PHP、JavaScript的语义扫描,基础安全、组件安全扫描,Chrome Ext\Solidity的基础扫描。☆2,379Jan 16, 2026Updated last month
- ☆404Feb 28, 2020Updated 6 years ago
- 个人域渗透学习笔记☆1,801Feb 7, 2020Updated 6 years ago
- 基于burpsuite headless 的代理式被动扫描系统☆95Feb 10, 2020Updated 6 years ago
- Fastjson vulnerability quickly exploits the framework(fastjson漏洞快速利用框架)☆1,389Dec 16, 2022Updated 3 years ago
- 帮助java环境下任意文件下载情况自动化读取源码的小工具☆167Apr 5, 2019Updated 6 years ago
- 从shodan获取使用了相同favicon.ico的网站☆189Feb 16, 2019Updated 7 years ago
- 总结了20+.Net反序列化文章,持续更新☆748Apr 3, 2024Updated last year