渗透 超全面的渗透资料💯 包含:0day,xss,sql注入,提权……
☆114Jun 25, 2018Updated 7 years ago
Alternatives and similar repositories for penetration
Users that are interested in penetration are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- phpweb 前台任意文件上传☆16Jan 9, 2020Updated 6 years ago
- 打CTF实在厌倦了找利用链,就知道一个fastjson的版本,一堆依赖找啊找,头都疼。为了解决这个烦恼,用了卓卓师傅的fastjson黑名单工具和库,自己改造了一下。☆32Jan 3, 2020Updated 6 years ago
- 这个工具只是临时名称,我称他为端口隧道技术,解决隔离内网上线问题。☆78May 31, 2022Updated 3 years ago
- 过人 webshell 的生成工具☆262Apr 23, 2025Updated 11 months ago
- Shiro-550 不依赖CC链利用工具☆450Jun 19, 2024Updated last year
- 在渗透测试中快速检测常见中间件、组件的高危漏洞。☆728Mar 21, 2022Updated 4 years ago
- anti AV☆291Mar 12, 2020Updated 6 years ago
- 主流供应商的一些攻击性漏洞汇总☆808Nov 8, 2021Updated 4 years ago
- Mysql数据库执行监控☆12Dec 10, 2019Updated 6 years ago
- Information Security (Web Security/Penetration Testing Direction) Interview Questions/Solutions 信息安全(Web安全/渗透测试方向)面试题/解题思路☆479Jul 25, 2019Updated 6 years ago
- 在原有yso基础上实现依赖分离,内存马注入等功能。A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.☆68Sep 14, 2021Updated 4 years ago
- ☆115Jan 21, 2021Updated 5 years ago
- fastjson漏洞burp插件,检测fastjson<1.2.68基于dnslog,fastjson<=1.2.24和1.2.33<=fatjson<=1.2.47的不出网检测和TomcatEcho,SpringEcho回显方案。☆125May 14, 2021Updated 4 years ago
- Collect JSP webshell of various implementation methods. 梳理和发现的JSP Webshell各种姿势☆1,405Jan 18, 2022Updated 4 years ago
- 用于WebLogic poc及exp测试的基础脚本,后续将集成各版本poc库☆94Nov 4, 2020Updated 5 years ago
- 各种数据库的利用姿势☆1,033Jan 3, 2025Updated last year
- 云函数代理服务☆419Jun 6, 2025Updated 9 months ago
- 爆破js加密的后台登陆;JS加密;爆破密码;PyExecJS☆55Jan 20, 2021Updated 5 years ago
- woodpecker框架weblogic信息探测插件☆185Mar 23, 2022Updated 4 years ago
- RedTeaming知识星球2020年安全知识汇总☆473May 5, 2021Updated 4 years ago
- 增强版WeblogicScan、检测结果更精确、插件化、添加CVE-2019-2618,CVE-2019-2729检测,Python3支持☆967Jun 16, 2024Updated last year
- ❄️冰蝎客户端源码-V4.0.6🔞☆941Jul 8, 2025Updated 8 months ago
- 冰蝎 哥斯拉 WebShell bypass☆763Jan 15, 2026Updated 2 months ago
- Weblogic漏洞利用图形化工具 支持注入内存马、一键上传webshell、命令执行☆775Apr 20, 2022Updated 3 years ago
- 一款基于BurpSuite的被动式FastJson检测插件☆1,237Oct 1, 2022Updated 3 years ago
- ☆43Nov 14, 2022Updated 3 years ago
- 这是一个用于IP和域名碰撞匹配访问的小工具优化版,能减少碰撞中出来的误报,旨意用来匹配出渗透过程中需要绑定hosts才能访问的弱主机或内部系统。☆48Nov 18, 2021Updated 4 years ago
- OneForAll-WebUI☆34Jan 6, 2023Updated 3 years ago
- ☆34Sep 19, 2022Updated 3 years ago
- 用于帮助企业内部快速扫描log4j2的jndi漏洞的burp插件☆212Apr 18, 2023Updated 2 years ago
- 在网传的哥斯拉&冰蝎源码基础上加了一点注释☆258May 16, 2022Updated 3 years ago
- 输入一个域名,输出ICP备案所有关联域名☆257Dec 4, 2022Updated 3 years ago
- cve-2019-0808-poc☆48Mar 25, 2019Updated 6 years ago
- 跟.net相关的学习☆88Jun 24, 2024Updated last year
- 🚀 一款为了学习go而诞生的漏洞利用工具☆451Jun 14, 2022Updated 3 years ago
- 伪造Myslq服务端,并利用Mysql逻辑漏洞来获取客户端的任意文件反击攻击者☆363Apr 24, 2022Updated 3 years ago
- 渗透测试有关的POC、EXP、脚本、提权、小工具等---About penetration-testing python-script poc getshell csrf xss cms php-getshell domainmod-xss csrf-webshell co…☆7,273Updated this week
- thinkphp v5.x 远程代码执行漏洞-POC集合☆25Aug 6, 2019Updated 6 years ago
- 该项目是通过go语言实现防止rmi利用被反置的问题。☆44Dec 30, 2021Updated 4 years ago