👮🏻♂️ XSS attack playground,there are answers in issues. XSS 攻防靶场,issues 有答案
☆310Feb 2, 2023Updated 3 years ago
Alternatives and similar repositories for xss-demo
Users that are interested in xss-demo are comparing it to the libraries listed below
Sorting:
- 一个包含php,java,python,C#等各种语言版本的XXE漏洞Demo☆816Nov 28, 2022Updated 3 years ago
- 一个想帮你总结所有类型的上传漏洞的靶场☆4,127Jun 26, 2023Updated 2 years ago
- 业务逻辑安全漏洞复现靶场☆32Jun 15, 2022Updated 3 years ago
- 国光的文件上传靶场,基于 upload-labs 定制☆207Mar 25, 2021Updated 4 years ago
- 一个关于PHP的代码审计项目☆1,914Sep 17, 2019Updated 6 years ago
- 使用docker快速搭建各大漏洞靶场,目前可以一键搭建17个靶场。☆2,424Mar 25, 2020Updated 5 years ago
- MSSQL注入提权,bypass的一些总结☆737Jun 25, 2024Updated last year
- 一个好玩的Web安全-漏洞测试平台☆4,315Dec 19, 2023Updated 2 years ago
- Burp suite 分块传输辅助插件☆2,026Feb 23, 2022Updated 4 years ago
- 国光的手把手带你用 SSRF 打穿内网靶场源码☆412May 10, 2021Updated 4 years ago
- JAVA 漏洞靶场 (Vulnerability Environment For Java)☆482Jul 15, 2021Updated 4 years ago
- CTF Training 经典赛题复现环境☆1,151Aug 26, 2019Updated 6 years ago
- 上传漏洞fuzz字典生成脚本☆1,270Apr 1, 2021Updated 4 years ago
- 南京邮电大学网络攻防训练平台题目(也有其他地方的题目,会标注)☆70Apr 27, 2018Updated 7 years ago
- 🚀Vulfocus 是一个漏洞集成平台,将漏洞环境 docker 镜像,放入即可使用,开箱即用。☆3,440Sep 9, 2025Updated 6 months ago
- 瓶颈渗透,web渗透,red红队,fuzz param,注释,js字典,ctf☆717Jul 20, 2022Updated 3 years ago
- 挖掘国内外漏洞平台必备的自动化捡钱赏金技巧,看了并去做了捡钱如喝水。☆422Nov 17, 2020Updated 5 years ago
- 该项目用来记录,我用来练手的PHP代码审计项目。☆192Feb 15, 2019Updated 7 years ago
- xss漏洞模糊测试payload的最佳集合 2020版☆511May 25, 2020Updated 5 years ago
- Web漏洞渗透测试靶场☆244Feb 5, 2018Updated 8 years ago
- 增强版WeblogicScan、检测结果更精确、插件化、添加CVE-2019-2618,CVE-2019-2729检测,Python3支持☆967Jun 16, 2024Updated last year
- php code audit for cms vulnerabilities / 代码审计,对一些大型cms漏洞的复现研究,更新源码和漏洞exp☆279Dec 12, 2018Updated 7 years ago
- 1000个PHP代码审计案例(2016.7以前乌云公开漏洞)☆1,109Jul 26, 2016Updated 9 years ago
- 快速搭建各种漏洞环境(Various vulnerability environment)☆3,785Oct 27, 2020Updated 5 years ago
- A fast vulnerability scanner helps pentesters pinpoint possibly vulnerable targets from a large number of web servers☆2,369Dec 31, 2024Updated last year
- bayonet是一款src资产管理系统,从子域名、端口服务、漏洞、爬虫等一体化的资产管理系统☆1,510Nov 22, 2022Updated 3 years ago
- 适用于一线安服的ctf培训题目,全docker环境一键启动☆554Nov 8, 2023Updated 2 years ago
- 应急响应实战笔记,一个安全工程师的自我修养。☆5,523Jun 26, 2023Updated 2 years ago
- ☆1,616Feb 2, 2023Updated 3 years ago
- 跟踪真实漏洞相关靶场环境搭建☆242Jul 19, 2018Updated 7 years ago
- PHP代码审计分段讲解☆1,721Aug 29, 2022Updated 3 years ago
- JSFinder is a tool for quickly extracting URLs and subdomains from JS files on a website.☆2,920Nov 24, 2021Updated 4 years ago
- 从wooyun中提取的payload,以及burp插件☆841Jun 17, 2022Updated 3 years ago
- 一款长亭自研的完善的安全评估工具,支持常见 web 安全问题扫描和自定义 poc | 使用之前务必先阅读文档☆11,471Oct 29, 2024Updated last year
- flash.cn钓鱼页(中文+英文)☆446Jul 21, 2022Updated 3 years ago
- SRC子域名资产监控☆1,298Jan 14, 2021Updated 5 years ago
- mysql注入,bypass的一些心得☆1,327Jun 25, 2024Updated last year
- A burp extension that add some useful function to Context Menu 添加一些右键菜单让burp用起来更顺畅☆1,903Mar 11, 2026Updated last week
- 文件变化实时监控工具(代 码审计/黑盒/白盒审计辅助工具)☆785Feb 23, 2025Updated last year