mm0r1 / exploits
Pwn stuff.
☆1,766Updated 2 years ago
Alternatives and similar repositories for exploits:
Users that are interested in exploits are comparing it to the libraries listed below
- This tool generates gopher link for exploiting SSRF and gaining RCE in various servers☆2,929Updated last year
- HackBar plugin for Burpsuite☆1,560Updated 3 years ago
- PHPGGC is a library of PHP unserialize() payloads along with a tool to generate them, from command line or programmatically.☆3,321Updated last month
- Redis(<=5.0.5) RCE☆1,017Updated last year
- Webshell && Backdoor Collection☆1,851Updated 4 years ago
- Awesome Burp Suite Resources. 400+ open source Burp plugins, 400+ posts and videos.☆1,012Updated 4 years ago
- 🕷️ A `.git` folder exploiting tool that is able to restore the entire Git repository, including stash, common branches and common tags.☆1,473Updated this week
- Rip web accessible (distributed) version control systems: SVN/GIT/HG...☆1,715Updated 5 months ago
- Code-Audit-Challenges☆979Updated 6 years ago
- SSRF (Server Side Request Forgery) testing resources☆2,375Updated 3 months ago
- generate CobaltStrike's cross-platform payload☆2,335Updated last year
- A modern multiple reverse shell sessions manager written in go☆1,550Updated 3 weeks ago
- Next-Generation Linux Kernel Exploit Suggester☆1,873Updated last year
- Redis 4.x/5.x RCE☆944Updated 3 years ago
- Linux、macOS、Windows Kernel privilege escalation vulnerability collection, with compilation environment, demo GIF map, vulnerability detai…☆2,954Updated last year
- Tool for automatic exploitation of XXE vulnerability using direct and different out of band methods.☆1,577Updated last month
- weblogic 漏洞扫描工具。目前包含对以下漏洞的检测能力:CVE-2014-4210、CVE-2016-0638、CVE-2016-3510、CVE-2017-3248、CVE-2017-3506、CVE-2017-10271、CVE-2018-2628、CVE-201…☆2,020Updated last year
- Server-Side Template Injection and Code Injection Detection and Exploitation Tool☆3,850Updated 8 months ago
- A collection of proof-of-concept exploit scripts written by the team at Rhino Security Labs for various CVEs.☆816Updated 2 months ago
- A .DS_Store file disclosure exploit. It parses .DS_Store file and downloads files recursively.☆1,576Updated last year
- Automatic SSRF fuzzer and exploitation tool☆3,051Updated 7 months ago
- Neo-reGeorg is a project that seeks to aggressively refactor reGeorg☆2,951Updated 3 months ago
- Venom - A Multi-hop Proxy for Penetration Testers☆2,034Updated 2 years ago
- 一个各种方式突破Disable_functions达到命令执行的shell☆1,188Updated last year
- ☆1,329Updated 4 years ago
- Log4j2 RCE Passive Scanner plugin for BurpSuite☆781Updated last year
- bypass disable_functions via LD_PRELOA (no need /usr/sbin/sendmail)☆1,142Updated 3 years ago
- MySQL fake server for read files of connected clients☆591Updated 7 years ago
- A collection of pentest and development tips☆1,105Updated 2 years ago