此脚本用于测试 Rdies 未授权访问,在没权限写ssh私钥和定时任务又不知道web绝对路径的情况下,进行WEB目录探测
☆73May 3, 2019Updated 6 years ago
Alternatives and similar repositories for RedisDirScan
Users that are interested in RedisDirScan are comparing it to the libraries listed below
Sorting:
- 通过 Redis 主从写出无损文件☆719May 25, 2020Updated 5 years ago
- ☆24Feb 24, 2019Updated 7 years ago
- 用于寻找多网卡主机方便内网跨网段渗透避免瞎打找不到核心网☆235Jul 17, 2020Updated 5 years ago
- 帮助java环境下任意文件下载情况自动化读取源码的小工具☆167Apr 5, 2019Updated 6 years ago
- ☆10May 23, 2019Updated 6 years ago
- 使用WindowsAPI写的一些渗透小工具☆101Jun 17, 2021Updated 4 years ago
- cobaltstrike ms17-010 module and some other☆419Jun 13, 2019Updated 6 years ago
- 内网渗透中快速获取数据库所有库名,表名,列名 。具体判断后再去翻数据,节省时间。适用于mysql,mssql。☆197Nov 11, 2019Updated 6 years ago
- 一款基于webshell命令执行功能实现的GUI webshell管理工具,支持流量加密☆218Jun 4, 2021Updated 4 years ago
- 利用任意文件下载漏洞循环下载反编译 Class 文件获得网站 Java 源代码☆711May 10, 2021Updated 4 years ago
- Using To MySQL Elevate Privileges.☆172Nov 24, 2020Updated 5 years ago
- 此项目用来提取收集以往泄露的密码中符合条件的强弱密码☆1,133Apr 1, 2019Updated 6 years ago
- 整理收集Struts2漏洞环境☆270Jan 9, 2018Updated 8 years ago
- ☆15Feb 13, 2018Updated 8 years ago
- 用于记录分享一些有趣的案例☆866Jan 10, 2022Updated 4 years ago
- Burp suite 分块传输辅助插件☆2,023Feb 23, 2022Updated 4 years ago
- 适合在命令行中使用的轻巧的SQL Server数据库安全检测工具☆431Oct 23, 2021Updated 4 years ago
- 修改的SweetPotato,使之可以用于CobaltStrike v4.0☆246Apr 30, 2020Updated 5 years ago
- Collect JSP webshell of various implementation methods. 梳理和发现的JSP Webshell各种姿势☆1,404Jan 18, 2022Updated 4 years ago
- MSSQL注入提权,bypass的一些总结☆737Jun 25, 2024Updated last year
- flash 劫持轮子,CSRF,劫持,跳转,swf 有需求可以提issues ,src挖掘,劫持response☆86Nov 9, 2019Updated 6 years ago
- 绕过专业工具检测的Webshell研究文章和免杀的Webshell☆1,733Nov 15, 2020Updated 5 years ago
- Windows杀软在线对比辅助☆287Jul 26, 2022Updated 3 years ago
- 自改自用的一些巡风插件☆23Apr 4, 2019Updated 6 years ago
- flash.cn钓鱼页(中文+英文)☆446Jul 21, 2022Updated 3 years ago
- 可在Windows下执行系统命令的Redis模块,可用于Redis主从复制攻击。☆264Nov 25, 2022Updated 3 years ago
- 关于Struts2框架的历史漏洞个人分析文章☆54Jun 17, 2020Updated 5 years ago
- Windows一键检测应急响应服务工具/r3数据采集☆100Apr 5, 2022Updated 3 years ago
- geacon:简单适配了一个profile配置文件,可直接拿来修改使用,用于cs上线linux.☆161Aug 3, 2022Updated 3 years ago
- 通过BurpSuite来构建自己的爆破字典,可以通过字典爆破来发现隐藏资产。☆501Jan 30, 2024Updated 2 years ago
- 递归式寻找域名和api。☆723Aug 3, 2023Updated 2 years ago
- 一个简单的现代化公司域名使用规律预测及生成工具☆388Feb 24, 2022Updated 4 years ago
- POC-T强化版本 POC-S , 用于红蓝对抗中快速验证Web应用漏洞, 对功能进行强化以及脚本进行分类添加,自带dnslog等, 平台补充来自vulhub靶机及其他开源项目的高可用POC☆357Mar 12, 2020Updated 5 years ago
- This tool is designed to simplify and automate the extraction and organization of useful data from Cobalt Strike logs.☆18Apr 24, 2019Updated 6 years ago
- GoScan是采用Golang语言编写的一款分布式综合资产管理系统,适合红队、SRC等使用☆717May 6, 2021Updated 4 years ago
- 鱼儿在cs上线后自动收杆|Automatically stop fishing in javascript after the fish is hooked☆140Apr 19, 2020Updated 5 years ago
- Cobalt Strike team server password brute force tool☆396Jan 30, 2018Updated 8 years ago
- 一款有图形界面的RDP(3389)口令检测工具☆335May 26, 2019Updated 6 years ago
- 免杀webshell无限生成工具☆1,288Apr 3, 2020Updated 5 years ago