TomAPU / poc_and_expView external linksLinks
搜集的或者自己写的poc或者exp
☆205Sep 27, 2022Updated 3 years ago
Alternatives and similar repositories for poc_and_exp
Users that are interested in poc_and_exp are comparing it to the libraries listed below
Sorting:
- Spring Cloud SnakeYAML 反序列化一键注入cmdshell和reGeorg☆135Sep 24, 2020Updated 5 years ago
- Java RCE 回显测试代码☆1,015Oct 15, 2020Updated 5 years ago
- CommonsBeanutils1,CommonsCollectionsK1☆58Nov 16, 2020Updated 5 years ago
- Shiro-550 不依赖CC链利用工具☆451Jun 19, 2024Updated last year
- Windows rdp相关的登录记录导出工具,可用于后渗透中Windows服务器的信息收集阶段。输出内容包括:本地rdp端口、mstsc缓存、cmdkey缓存、登录成功、失败日志事件。☆283Jun 23, 2024Updated last year
- SpringBoot Actuator未授权自动化利用,支持信息泄漏/RCE☆232Dec 5, 2020Updated 5 years ago
- 宽字节安全团队的博客☆31Mar 29, 2021Updated 4 years ago
- 红队工具:各大OA利用工具,万户、致远、通达等☆259Jul 23, 2021Updated 4 years ago
- ☆232Jan 3, 2022Updated 4 years ago
- Windows活动目录中的LDAP信息收集工具☆234Oct 9, 2021Updated 4 years ago
- WebLogic利用CVE-2020-2883打Shiro rememberMe反序列化漏洞,一键注册蚁剑filter内存shell☆535Aug 25, 2020Updated 5 years ago
- 域信息收集工具☆411Sep 16, 2022Updated 3 years ago
- CVE-2022-22947☆222Mar 3, 2022Updated 3 years ago
- xray+rad批量主动扫描☆227Oct 19, 2022Updated 3 years ago
- 红队行动中利用白利用、免杀、自动判断网络环境生成钓鱼可执行文件。☆367Jun 19, 2024Updated last year
- spring boot Fat Jar 任意写文件漏洞到稳定 RCE 利用技巧☆753Apr 14, 2021Updated 4 years ago
- Yapi mock script RCE another version. Webshell way. 另一种 Webshell 方式的 Yapi 命令执行的方法 相比于其他的利用方式 更加微操和可控 影响更小☆66Jul 4, 2024Updated last year
- 各种数据库的利用姿势☆1,034Jan 3, 2025Updated last year
- (周瑜)Java - SpringBoot 持久化 WebShell(不仅仅是SpringBoot,适合任何符合JavaEE规范的服务)☆615Dec 29, 2021Updated 4 years ago
- 检测域环境内,域机器的本地管理组成员是否存在弱口令和通用口令,对域用户的权限分配以及域内委派查询☆353Aug 10, 2021Updated 4 years ago
- 利用任意文件下载漏洞循环下载反编译 Class 文件获得网站 Java 源代码☆711May 10, 2021Updated 4 years ago
- 利用NTLM Hash读取Exchange邮件☆441Jan 7, 2025Updated last year
- nim一键免杀☆215Mar 8, 2021Updated 4 years ago
- fastjson 被动扫描、不出网payload生成☆367Nov 19, 2021Updated 4 years ago
- JNDI服务利用工具 RMI/LDAP,支持部分场景回显、内存shell,高版本JDK场景下利用等,fastjson rce命令执行,log4j rce命令执行 漏洞检测辅助工具☆2,011May 21, 2024Updated last year
- CobaltStrike <= 4.7.1 RCE☆388Oct 25, 2022Updated 3 years ago
- 影子用户 克隆☆232Dec 30, 2021Updated 4 years ago
- TongdaOA 11.7 ~11.8 通达OA,任意用户登录+后台getshell☆86Jul 16, 2021Updated 4 years ago
- JCE - JSP/JPSX CodeEncode - 用于 Webshell 逃避静态查杀的辅助脚本☆258Oct 29, 2021Updated 4 years ago
- Shiro反序列化利用工具,支持新版本(AES-GCM)Shiro的key爆破,配合ysoserial,生成回显Payload☆898May 28, 2021Updated 4 years ago
- 基于go语言的致远OA漏洞检测工具☆39Oct 28, 2022Updated 3 years ago
- 通达OA 任意用户登录漏洞☆360Aug 27, 2020Updated 5 years ago
- 改造BeichenDream/InjectJDBC加入shiro获取key和修改key功能☆279Nov 28, 2023Updated 2 years ago
- 六大云存储,泄露利用检测工具☆1,238Mar 28, 2025Updated 10 months ago
- Collect JSP webshell of various implementation methods. 梳理和发现的JSP Webshell各种姿势☆1,404Jan 18, 2022Updated 4 years ago
- FinalShellDecodePass 加密解密☆83Dec 1, 2021Updated 4 years ago
- 防火墙出网探测工具,内网穿透型socks5代理☆270Nov 12, 2021Updated 4 years ago
- codemillx is a tool for CodeQL, extract the comments in the code and generate codeql module. 强化Go开源项目安全检测(内含开源项目漏洞挖掘方法)☆205Mar 19, 2022Updated 3 years ago
- One-click injection into the SSHD process to record and send the password for ssh login☆426Mar 12, 2024Updated last year