一款高效的参数fuzz工具|A faster param fuzzing test tool
☆103Nov 8, 2020Updated 5 years ago
Alternatives and similar repositories for paramFuzzer
Users that are interested in paramFuzzer are comparing it to the libraries listed below
Sorting:
- 一款用于攻击spring boot actuator的集成环境,目前集成三种攻击方式,支持1.x、2.x☆86Jul 26, 2021Updated 4 years ago
- 基于注册表劫持BypassUAC☆28Dec 16, 2020Updated 5 years ago
- 火刃 - 轻量级的,多功能的,联合xray、物联网引擎的全自动广域队列扫描器☆28Mar 7, 2022Updated 3 years ago
- More Easier Burp Extension To Solve Javascript Front End Encryption,一款更易使用的解决前端加密问题的Burp插件。☆46Apr 15, 2020Updated 5 years ago
- xss漏洞模糊测试payload的最佳集合 2020版☆511May 25, 2020Updated 5 years ago
- 一款基于webshell命令执行功能实现的GUI webshell管理工具,支持流量加密☆218Jun 4, 2021Updated 4 years ago
- AntSword(蚁剑)全参数流量XOR和Base64加伪装WebShell☆163Sep 28, 2021Updated 4 years ago
- Nexus Repository Manager3 - 远程执行代码漏洞回显payload☆13Sep 29, 2020Updated 5 years ago
- 利用xray高级版批量收集子域名☆18Feb 19, 2020Updated 6 years ago
- 一个轻量级Web蜜罐 - A Little Web Honeypot.🍯🍯🍯🐝🐝🐝☆200Jan 13, 2022Updated 4 years ago
- Windows活动目录中的LDAP信息收集工具☆234Oct 9, 2021Updated 4 years ago
- Behinder3.0 Beta4 源码(Decompile and Fixed)☆207Sep 1, 2020Updated 5 years ago
- 这个脚本主要提供对Exchange邮件服务器的账户爆破功能,集成了现有主流接口的爆破方式。☆339May 22, 2023Updated 2 years ago
- 内网安全·域账号弱口令审计☆163Dec 27, 2019Updated 6 years ago
- Python script for auto remove AV☆45May 20, 2020Updated 5 years ago
- ☆286Jan 15, 2020Updated 6 years ago
- 鱼儿在cs上线后自动收杆|Automatically stop fishing in javascript after the fish is hooked☆140Apr 19, 2020Updated 5 years ago
- evilzip lets you create a zip file(with password) that contains files with directory traversal characters in their embedded path.☆103Sep 16, 2021Updated 4 years ago
- 在渗透测试中快速检测常见中间件、组件的高危漏洞。☆728Mar 21, 2022Updated 3 years ago
- 一个全新的敏感文件发现工具☆225Jan 10, 2021Updated 5 years ago
- 📧Coremail邮件系统组织通讯录导出脚本☆158Sep 28, 2021Updated 4 years ago
- Cobalt Strike插件 - RDP日志取证&清除☆363Dec 23, 2019Updated 6 years ago
- 一键生成Java代码的burp插件/Generate Java script for fuzzing in Burp。☆51Jan 6, 2022Updated 4 years ago
- 从zoomeye or shodan or file 获取目标进行攻击。☆17Nov 21, 2019Updated 6 years ago
- how detect CVE-2020-2551 poc exploit python Weblogic RCE with IIOP☆211Mar 5, 2023Updated 2 years ago
- 一键提取安卓应用中可能存在的敏感信息。☆1,011Oct 21, 2021Updated 4 years ago
- 采用Golang编写的新一代端口及指纹扫描器☆159Nov 21, 2020Updated 5 years ago
- 帮助java环境下任意文件下载情况自动化读取源码的小工具☆167Apr 5, 2019Updated 6 years ago
- 利用NTLM Hash读取Exchange邮件☆441Jan 7, 2025Updated last year
- 读取登录过本机的登录失败或登录成功的所有计算机信息,在内网渗透中快速定位运维管理人员。☆221Sep 30, 2019Updated 6 years ago
- 通过BurpSuite来构建自己的爆破字典,可以通过字典爆破来发现隐藏资产。☆501Jan 30, 2024Updated 2 years ago
- Spring Boot Actuator未授权访问【XXE、RCE】单/多目标检测☆521May 21, 2020Updated 5 years ago
- SharpSQLTools 和@Rcoil一起写的小工具,可上传下载文件,xp_cmdshell与sp_oacreate执行命令回显和clr加载程序集执行相应操作。☆965Aug 5, 2021Updated 4 years ago
- POC-T强化版本 POC-S , 用于红蓝对抗中快速验证Web应用漏洞, 对功能进行强化以及脚本进行分类添加,自带dnslog等, 平台补充来自vulhub靶机及其他开源项目的高可用POC☆357Mar 12, 2020Updated 5 years ago
- Burp被动扫描流量转发插件☆1,459Jun 17, 2024Updated last year
- 使得Cobaltstrike支持Atexec☆89Jun 30, 2020Updated 5 years ago
- Java RCE 回显测试代码☆1,016Oct 15, 2020Updated 5 years ago
- 通过 Redis 主从写出无损文件☆719May 25, 2020Updated 5 years ago
- tomcat使用了自带session同步功能时,不安全的配置(没有使用EncryptInterceptor)导致存在的反序列化漏洞,通过精心构造的数据包, 可以对使用了tomcat自带session同步功能的服务器进行攻击。PS:这个不是CVE-2020-9484,9484…☆212May 19, 2020Updated 5 years ago