Skip to content
View XuansGG's full-sized avatar

Block or report XuansGG

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

ActiveMQ RCE (CVE-2023-46604) 回显利用工具

Java 8 3 Updated Sep 13, 2024

A list for Web Security and Code Audit

972 174 Updated Dec 3, 2024

收集整理漏洞EXP/POC,大部分漏洞来源网络,目前收集整理了1300多个poc/exp,长期更新。

4,343 921 Updated Dec 14, 2024

A fast, simple, recursive content discovery tool written in Rust.

Rust 6,054 504 Updated Sep 15, 2024

一个Go版(更强大)的TideFinger指纹识别工具,可对web和主机指纹进行识别探测,整合梳理互联网指纹2.3W余条,在效率和指纹覆盖面方面进行了平衡和优化。

250 12 Updated Dec 21, 2023

整理了基于Go的16种API免杀测试、8种加密测试、反沙盒测试、编译混淆、加壳、资源修改等免杀技术,并搜集汇总了一些资料和工具。

Go 1,097 174 Updated Aug 23, 2022

HVNC for Cobalt Strike

C 1,171 183 Updated Dec 7, 2023
Python 440 120 Updated Aug 14, 2023

这是一个面向中文社区,分析市面上智能合约应用的架构与实现的仓库。

Solidity 1,575 345 Updated Dec 4, 2024

New generation of wmiexec.py

Python 1,023 123 Updated Nov 23, 2024

dubbo快速利用exp,基本上老版本覆盖100%。

Java 102 14 Updated Jan 8, 2024

去中心化远程控制工具(Decentralized Remote Administration Tool),通过ENS实现了配置文件分发的去中心化,通过Telegram实现了服务端的去中心化

Go 793 53 Updated Mar 14, 2023

Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the …

Go 21,030 2,535 Updated Dec 13, 2024

面向红队的, 高度可控可拓展的自动化引擎

Go 1,525 146 Updated Dec 3, 2024

基于C#实现的获取微信数据库密钥的小工具

C# 476 76 Updated May 20, 2024

基于Java实现的图形化微信聊天记录解密查看器

569 68 Updated May 20, 2024

微信客户端取证,可获取用户个人信息(昵称/账号/手机/邮箱/数据库密钥(用来解密聊天记录));支持获取多用户信息,不定期更新新版本偏移,目前支持所有新版本、正式版本

C# 4,252 605 Updated Apr 25, 2024

StandIn is a small .NET35/45 AD post-exploitation toolkit

C# 716 121 Updated Dec 2, 2023

dotnet 反序列化学习笔记

438 46 Updated Oct 19, 2023

Just another Powerview alternative

Python 469 49 Updated Dec 15, 2024

一个利用ASM对字节码进行污点传播分析的静态代码审计应用(添加了大量代码注释,适合大家进行源码学习)。也加入了挖掘Fastjson反序列化gadget chains和SQLInject(JdbcTemplate、MyBatis、JPA、Hibernate、原生jdbc等)静态检测功能。并且加入了很多功能以方便进行漏洞自动化挖掘。

Java 444 58 Updated Mar 24, 2022

WebSocket 内存马/Webshell,一种新型内存马/WebShell技术

Java 1,418 225 Updated Apr 10, 2023

Proxylogon & Proxyshell & Proxyoracle & Proxytoken & All exchange server history vulns summarization :)

C# 521 106 Updated Dec 7, 2023

A proof of concept exploit for CVE-2022-40684 affecting Fortinet FortiOS, FortiProxy, and FortiSwitchManager

Python 341 90 Updated Oct 13, 2022

Find specific users in active directory via their username and logon IP address

C# 374 54 Updated Mar 21, 2020

星球伴侣(无限下载版) - 知识星球助手

HTML 213 64 Updated Feb 26, 2022

Weblogic漏洞利用图形化工具 支持注入内存马、一键上传webshell、命令执行

715 82 Updated Apr 20, 2022

Active Directory certificate abuse.

C# 1,538 217 Updated Aug 12, 2024

A simple POC that abuses Backup Operator privileges to remote dump SAM, SYSTEM, and SECURITY

Python 79 17 Updated Feb 16, 2022

利用任意文件下载漏洞循环下载反编译 Class 文件获得网站 Java 源代码

Python 697 94 Updated May 10, 2021
Next