uknowsec / SharpSQLDump
内网渗透中快速获取数据库所有库名,表名,列名。具体判断后再去翻数据,节省时间。适用于mysql,mssql。
☆199Updated 5 years ago
Alternatives and similar repositories for SharpSQLDump:
Users that are interested in SharpSQLDump are comparing it to the libraries listed below
- reGeorg的特殊版本,适用于老版本weblogic。☆154Updated 4 years ago
- 本项目是一篇NTLM中高级进阶进阶文章,后续我也会在Github和Gitbook对此文进行持续性的更新NTLM以及常见的协议中高级进阶并计划开源部分协议调试工具,望各位issue勘误。☆114Updated 4 years ago
- ☆289Updated 5 years ago
- GUI Exploit Tool For RedTeam☆7Updated 3 years ago
- 利用长亭xray高级版的回显Gadget重写的一个shiro反序列化利用工具。☆123Updated 4 years ago
- A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.☆102Updated 4 years ago
- .NET后渗透下的权限维持,附下载DLL☆202Updated 6 years ago
- ☆156Updated 4 years ago
- 🐸fingerprint detect framework 批量深度指纹识别框架☆119Updated 2 years ago
- Spring Cloud SnakeYAML 反序列化一键注入cmdshell和reGeorg☆132Updated 4 years ago
- 修改的SweetPotato,使之可以用于CobaltStrike v4.0☆240Updated 4 years ago
- Shiro RCE (Padding Oracle Attack)☆143Updated 5 years ago
- Weblogic Vuln POC EXP cve-2020-2551 cve-2020-2555 cve-2020-2883 ,。。。☆90Updated 2 years ago
- .net 命令执行的webshell☆98Updated 3 years ago
- 用于WebLogic poc及exp测试的基础脚本,后续将集成各版本poc库☆93Updated 4 years ago
- A JSP backdoor that enables under Tomcat hiding arbitrary JSP files, in addition to their access logs.☆215Updated 5 years ago
- bypass JEP290 RaspHook code☆62Updated 4 years ago
- bypassD盾、安全狗、云锁☆107Updated 3 years ago
- Source code of Behinder, a shell manager.冰蝎源码,反编译,当前版本3.0 Beta6,支持内存马注入☆90Updated 3 years ago
- ☆77Updated 3 years ago
- Shiro_721 exp 纯手工实现Padding Oracle整个过程☆68Updated 5 years ago
- WebLogic EJBTaglibDescriptor XXE漏洞(CVE-2019-2888)☆58Updated 5 years ago
- A simple python script to generate XML payloads works for XMLDecoder based on ProcessBuilder and Runtime exec☆149Updated 4 years ago
- 鱼儿在cs上线后自动收杆|Automatically stop fishing in javascript after the fish is hooked☆134Updated 4 years ago
- 一款用于攻击spring boot actuator的集成环境,目前集成三种攻击方式,支持1.x、2.x☆85Updated 3 years ago
- This tool generates gopher link for exploiting SSRF and gaining RCE in redis with password.用于生成附带密码认证的gopher内容,用于SSRF等利用。☆112Updated 5 years ago
- fastjson 1.2.68 版本 autotype bypass☆140Updated 2 years ago
- 通过burp代理流量寻找shiro站点☆60Updated 4 years ago
- SpringBoot Actuator未授权自动化利用,支持信息泄漏/RCE☆233Updated 4 years ago
- SpringBoot_Actuator_RCE☆97Updated 4 years ago