oss存储桶遍历漏洞利用脚本
☆93Nov 23, 2024Updated last year
Alternatives and similar repositories for ossFileList
Users that are interested in ossFileList are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- burp插件,Oss漏洞被动扫描☆116Aug 8, 2025Updated last year
- 递归寻找JS泄露的路径。Recursively search for the paths of JS Files.For pentest☆11Sep 30, 2024Updated last year
- 辅助甲方安全人员巡检网站资产,发现并分析API安全问题☆535Jan 20, 2025Updated last year
- 万户数据库解密☆21Dec 3, 2023Updated 2 years ago
- Small & Fast Vulnerability Scanner Engine based on XRAY YAML Rule | 基于 XRAY YAML 规则的超轻量快速漏洞扫描引擎 | 基于 ANTLR 实现语法分析和完整的 XRAY YAML 规则实现 | 简单…☆180Jul 10, 2025Updated last year
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Burp插件,自动化挖掘SSRF,Redirect,Sqli漏洞,自定义匹配参数☆488Sep 10, 2023Updated 2 years ago
- OneScan 是一款用于递归目录扫描的 BurpSuite 插件☆1,252Jun 24, 2025Updated last year
- 云资产管理工具 目前工具定位是云安全相关工具,目前是两个模块 云存储工具、云服务工具, 云存储工具主要是针对oss存储、查看、删除、上传、下载、预览等等 云服务工具主要是针对rds、服务器的管理,查看、执行命令、接管等等☆1,168Feb 26, 2026Updated 5 months ago
- Burp插件,快速探测可能存在SQL注入的请求并标记,提高测试效率☆821Feb 26, 2026Updated 5 months ago
- 存储桶遍历漏洞利用工具☆465Jul 24, 2026Updated 2 weeks ago
- P1finger - 红队行动下的重点资产指纹识别工具,解决信息收集过程中的一小步☆455Aug 5, 2025Updated last year
- SQL Injection Scout 是一个用于 Burp Suite 的扩展,专为帮助安全研究人员和开发人员检测和分析 SQL 注入漏洞而设计。该扩展提供了丰富的配置选项和直观的用户界面,便于用户自定义扫描和分析过程。☆279Feb 6, 2026Updated 6 months ago
- 针对JWT渗透开发的漏洞验证/密钥爆破工具,针对CVE-2015-9235/空白密钥/未验证签名攻击/CVE-2016-10555/CVE-2018-0114/CVE-2020-28042的结果生成用于FUZZ,也可使用字典/字符枚举(包括JJWT)的方式进行爆破(JWT …☆289Aug 12, 2025Updated last year
- 对Auth/Waf 自动化bypass的burpsuite插件☆1,313May 10, 2026Updated 3 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- java-web 自动化鉴权绕过☆380Apr 3, 2025Updated last year
- 注入JVM进程 动态获取目标进程连接 的数据库☆343Mar 6, 2022Updated 4 years ago
- 一款帮助云租户发现和测试云上风险、增强云上防护能力的综合性开源工具☆618Feb 3, 2026Updated 6 months ago
- 一款轻量级匹配Sink点的代码审计扫描器,为了帮助红队过程中快速代码审计的小工具☆402Oct 6, 2024Updated last year
- 帆软bi反序列化漏洞利用工具☆199Mar 23, 2024Updated 2 years ago
- burpsuite插件-被动无感识别指纹-主动poc扫描☆26Sep 13, 2024Updated last year
- DockerRemoteAPI未授权访问(2375端口)利用工具,支持容器逃逸☆68Dec 29, 2024Updated last year
- 参照xffhelper源码修改,结合了fakeip的功能,生成jar包,不再需要py支持☆14Jun 10, 2021Updated 5 years ago
- 帆软报表漏洞检测工具☆121Jun 10, 2025Updated last year
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- xia_Yue 插件修改版,瞎越修改版,修复中文重放乱码,添加请求行越权测试,一键导出越权url,允许重复url测试等功能☆79Jan 5, 2026Updated 7 months ago
- 二开KillWxapkg项目,添加实时检测和开启web端服务☆52Nov 7, 2024Updated last year
- 一个想让你测试加密流量像测试明文一样简单高效的 Burp 插件。 A Burp plugin that makes testing encrypted traffic as simple and efficient as testing plaintext.☆1,104Mar 27, 2026Updated 4 months ago
- 一款微信小程序源码包信息收集工具,根据已有项目改编☆24Feb 11, 2025Updated last year
- JavaGadgetGenerator 工具,支持 ysoserial,Hessian,字节码,Expr/SSTI,Shiro,JDBC 等 Gadget 生成,封装,混淆,出网延迟探测,内存马注入等...☆576Apr 3, 2026Updated 4 months ago
- 让"WAF绕过"变得简单☆436Jan 26, 2025Updated last year
- dirsx 是一款能够自动化过滤扫描结果的目录扫描工具☆364Mar 12, 2026Updated 5 months ago
- 用友漏洞综合利用工具☆269Nov 9, 2024Updated last year
- 目标是成为当下最完善的API挖掘工具,实现自动提取响应敏感信息、URI信息,并且对URI进行自动|手动递归检查☆265Aug 16, 2025Updated 11 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- jeecg综合漏洞利用工具☆454Aug 30, 2024Updated last year
- Nuclei POC 管理与漏洞验证工具-Nuclei GUI☆553Apr 24, 2026Updated 3 months ago
- 帆软bi反序列化漏洞利用工具☆427Jan 25, 2025Updated last year
- 哥斯拉webshell管理工具的插件,用于连接websocket型webshell☆184Apr 17, 2024Updated 2 years ago
- xxl-job内存马☆233Jan 26, 2025Updated last year
- GodInfo 是一个功能全面的后渗透信息和凭据收集工具,旨在帮助安全测试人员在获得授权访问权限后,快速收集目标系统的信息和凭据。☆257Apr 29, 2025Updated last year
- 本工具为jeecg框架漏洞利用工具非jeecg-boot!☆184Aug 13, 2024Updated last year