WEB 跨域postMessage() 漏洞挖掘工具,基本原理:使用AJAX 获取页面代码,结合iframe 和data 协议构造测试环境,然后在iframe 下的window.onmessage 中插入hook 监控onmessage 的参数,最后通过能否被原来的onmessage 逻辑引用参数中的data 属性来判断是否可以跨域传递数据..
☆11Sep 13, 2016Updated 10 years ago
Alternatives and similar repositories for cross_domain_postmessage_vuln_dig
Users that are interested in cross_domain_postmessage_vuln_dig are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- whatweb的插件☆15Aug 15, 2014Updated 12 years ago
- Web在线菜刀☆18Oct 18, 2017Updated 8 years ago
- 针对PHP网马的正则查杀☆13Jan 10, 2018Updated 8 years ago
- 用于快速探测未授权MongoDB数据库结构,取第一条内容,并统计数据数量。A tool for unauthorized MongoDB database , take the first content, and the number of statistical da…☆26Dec 5, 2016Updated 9 years ago
- ☆16Aug 9, 2017Updated 9 years ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- ZZCMS v8.2-重装GETSHELL工具☆11May 8, 2018Updated 8 years ago
- ☆16Aug 31, 2018Updated 8 years ago
- nmap模块扫描端口服务后,调用对应的exp检测☆12Jun 9, 2018Updated 8 years ago
- XSS hunter 收集Webview 页面上存在的反射,储存型XSS ,方便应急APP 和前端页面在发布时遇到XSS 安全问题..☆42Oct 9, 2016Updated 9 years ago
- 《横向移动攻 击与检测技术》专栏文章☆17Sep 5, 2019Updated 7 years ago
- 漏洞复现记录☆11Jun 18, 2019Updated 7 years ago
- 修改htcap的数据库为mysql☆24Jul 9, 2017Updated 9 years ago
- ☆20May 12, 2016Updated 10 years ago
- 通过调用zoomeye来获取安装JBoss机器的地址,然后通过HEAD请求植入webshell。 wxPython写了一个界面的控制程序。☆12Mar 28, 2018Updated 8 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Ssdt Hook Detection tool☆13Nov 11, 2016Updated 9 years ago
- 常用系统服务默认端口列表☆13Apr 25, 2017Updated 9 years ago
- Spring messaging STOMP protocol RCE☆113Apr 12, 2018Updated 8 years ago
- ☆16Aug 12, 2009Updated 17 years ago
- Cross Domain XHR: A drop-in replacement for XmlHttpRequest object.☆60Jan 31, 2013Updated 13 years ago
- 分布式互联网开放端口与协议扫描☆18Jul 20, 2016Updated 10 years ago
- 一款开源指纹识别工具。☆15May 19, 2017Updated 9 years ago
- 一个Fuzzing服务器端模板注入漏洞的半自动化工具☆15Aug 4, 2016Updated 10 years ago
- CVE-2017-4878 Samples - http://blog.talosintelligence.com/2018/02/group-123-goes-wild.html☆17Feb 5, 2018Updated 8 years ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- ☆21Jan 31, 2018Updated 8 years ago
- 总结一些渗透中值得关注的默认端口☆23May 19, 2016Updated 10 years ago
- CVE-2017-7269 回显PoC ,用于远程漏洞检测..☆89Oct 27, 2018Updated 7 years ago
- 本脚本旨在生成各类畸形URL链接,进行探测使用的payload,尝试绕过服务端ssrf限制。☆28Jan 9, 2019Updated 7 years ago
- Maintain Windows Persistence with an evil Netshell Helper DLL☆11Jul 28, 2018Updated 8 years ago
- 2 web tasks from ZeroNights HackQuest 2016☆49Mar 24, 2017Updated 9 years ago
- 大型超市运营系统框架,基于GWT EJB JPA,完整的Java EE Web Application☆10Jun 25, 2014Updated 12 years ago
- 前端信息安全☆10Nov 8, 2017Updated 8 years ago
- Monitor and prevent unexpected behavior of Java programs.☆14Jul 6, 2021Updated 5 years ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- ☆106Feb 2, 2018Updated 8 years ago
- 常用的一些Exploit,经常会更新,也欢迎各位提交新的exp给我。☆26Jul 27, 2018Updated 8 years ago
- Burpsuite HTTP 插件,主要用于内网测试,可定制Content-Type和Response Content☆24Jul 2, 2018Updated 8 years ago
- ModularAdmin V2 Preview☆11Dec 25, 2017Updated 8 years ago
- PHP Bing Translation API Class☆12Jun 19, 2018Updated 8 years ago
- 目前生产环境使用的elasticsearch☆10Apr 29, 2014Updated 12 years ago
- ☆16Jul 21, 2017Updated 9 years ago