CVE-2022-0847-DirtyPipe-Exploit CVE-2022-0847 是存在于 Linux内核 5.8 及之后版本中的本地提权漏洞。攻击者通过利用此漏洞,可覆盖重写任意可读文件中的数据,从而可将普通权限的用户提升到特权 root。 CVE-2022-0847 的漏洞原理类似于 CVE-2016-5195 脏牛漏洞(Dirty Cow),但它更容易被利用。漏洞作者将此漏洞命名为“Dirty Pipe”
☆281Feb 2, 2023Updated 3 years ago
Alternatives and similar repositories for CVE-2022-0847
Users that are interested in CVE-2022-0847 are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A root exploit for CVE-2022-0847 (Dirty Pipe)☆1,126Mar 8, 2022Updated 4 years ago
- 致远OA综合利用工具☆231Dec 31, 2021Updated 4 years ago
- ☆308Feb 16, 2022Updated 4 years ago
- Spring Cloud Gateway 远程代码执行漏洞Exp Spring_Cloud_Gateway_RCE_Exp-CVE-2022-22947☆77Nov 14, 2022Updated 3 years ago
- 这是一个一键辅助抓取360安全浏览器密码的CobaltStrike脚本以及解密小工具,用于节省红队工作量,通过下载浏览器数据库、记录密钥来离线解密浏览器密码。☆638Apr 4, 2021Updated 5 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting with the flexibility to host WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Cloudways by DigitalOcean.
- 六大云存储,泄露利用检测工具☆1,250Mar 28, 2025Updated last year
- 冰蝎Java WebShell自动化免杀生成☆784Mar 15, 2022Updated 4 years ago
- A exploit tool for Grafana Unauthorized arbitrary file reading vulnerability (CVE-2021-43798), it can burst plugins / extract secret_key …☆269Oct 17, 2025Updated 5 months ago
- 一款针对Vcenter的综合利用工具,包含目前最主流的CVE-2021-21972、CVE-2021-21985以及CVE-2021-22005、One Access的CVE-2022-22954、CVE-2022-22972/31656以及log4j,提供一键上传webs…☆1,473Apr 25, 2024Updated last year
- 各种数据库的利用姿势☆1,034Jan 3, 2025Updated last year
- CVE-2022-23222: Linux Kernel eBPF Local Privilege Escalation☆578Jun 7, 2022Updated 3 years ago
- ☆195Dec 22, 2021Updated 4 years ago
- 远程shellcode加载&权限维持+小功能☆302May 7, 2024Updated last year
- 伪造Myslq服务端,并利用Mysql逻辑漏洞来获取客户端的任意文件反击攻击者☆363Apr 24, 2022Updated 3 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting with the flexibility to host WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Cloudways by DigitalOcean.
- 一款基于BurpSuite的被动式FastJson检测插件☆1,242Oct 1, 2022Updated 3 years ago
- shiro反序列化漏洞综合利用,包含(回显执行命令/注入内存马)修复原版中NoCC的问题 https://github.com/j1anFen/shiro_attack☆2,444Mar 28, 2026Updated last week
- 解决FastJson、Jackson、Log4j2、原生JNDI注入漏洞的高版本JDKBypass利用,探测本地可用反序列化gadget达到命令执行、回显命令执行、内存马注入☆775Jan 26, 2022Updated 4 years ago
- JNDI服务利用工具 RMI/LDAP,支持部分场景回显、内存shell,高版本JDK场景下利用等,fastjson rce命令执行,log4j rce命令执行 漏洞检测辅助工具☆2,016May 21, 2024Updated last year
- A Swagger API Exploit☆1,371Jun 7, 2024Updated last year
- 数据库综合利用工具☆544Feb 16, 2022Updated 4 years ago
- netspy是一款快速探测内网可达网段工具(深信服深蓝实验室天威战队强力驱动)☆2,214Jul 25, 2023Updated 2 years ago
- CVE-2022-30190-follina.py-修改版,可以自定义word模板,方便实战中钓鱼使用。☆393Apr 13, 2023Updated 2 years ago
- LSTAR - CobaltStrike 综合后渗透插件☆1,266Jan 30, 2022Updated 4 years ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- Log4j2 RCE Passive Scanner plugin for BurpSuite☆831Aug 4, 2023Updated 2 years ago
- CVE-2022-22947☆223Mar 3, 2022Updated 4 years ago
- 一款基于BurpSuite的被动式shiro检测插件☆1,798Dec 14, 2022Updated 3 years ago
- WeblogicTool,GUI漏洞利用工具,支持漏洞检测、命令执行、内存马注入、密码解密等(深信服深蓝实验室天威战队强力驱动)☆1,783Nov 1, 2023Updated 2 years ago
- Shiro反序列化利用工具,支持新版本(AES-GCM)Shiro的key爆破,配合ysoserial,生成回显Payload☆897May 28, 2021Updated 4 years ago
- A tool for detect&exploit vmware product log4j(cve-2021-44228) vulnerability.Support VMware HCX/vCenter/NSX/Horizon/vRealize Operations M…☆210Jan 24, 2022Updated 4 years ago
- 用于帮助企业内部快速扫描log4j2的jndi漏洞的burp插件☆212Apr 18, 2023Updated 2 years ago
- Burp被动扫描流量转发插件☆1,461Jun 17, 2024Updated last year
- AK资源管理工具,阿里云/腾讯云/华为云/AWS/UCLOUD/京东云/百度云/七牛云存储/火山引擎 AccessKey AccessKeySecret,利用AK获取资源信息和操作资源,ECS/CVM/E2/UHOST/ECI/BCC执行命令,OSS/COS/S3/BOS…☆780Feb 13, 2025Updated last year
- Wordpress hosting with auto-scaling on Cloudways • AdFully Managed hosting built for WordPress-powered businesses that need reliable, auto-scalable hosting. Cloudways SafeUpdates now available.
- 本项目用于搜集 2022 年的漏洞,注意:本项目并不刻意搜集 POC 或 EXP,主要以CVE-2021、CVE-2022 为关键词,包含但不限于漏洞资讯、漏洞复现、漏洞分析、漏洞验证、漏洞利用☆381Apr 17, 2022Updated 3 years ago
- 自动化爬取并自动测试所有swagger接口☆1,170Dec 1, 2025Updated 4 months ago
- 阿里云ECS、策略组辅助小工具☆880Mar 2, 2023Updated 3 years ago
- 基于向日葵RCE的本地权限提升,无需指定端口☆211Feb 24, 2022Updated 4 years ago
- Nacos JRaft Hessian 反序列化 RCE 加载字节码 注入内存马 不出网利用☆848Jul 7, 2023Updated 2 years ago
- CVE-2021-44228 Log4j2 BurpSuite Scanner,Customize ceye.io api or other apis,including internal networks☆841Jun 13, 2023Updated 2 years ago
- Burp suite 分块传输辅助插件☆2,031Feb 23, 2022Updated 4 years ago