Stars
python3写的综合扫描工具,主要用来存活验证,敏感文件探测(目录扫描/js泄露接口/html注释泄露),WAF/CDN识别,端口扫描,指纹/服务识别,操作系统识别,POC扫描,SQL注入,绕过CDN,查询旁站等功能,主要用来甲方自测或乙方授权测试,请勿用来搞破坏。
Collection of CTF Web challenges I made
XSS spider - 66/66 wavsep XSS detected
Takes a URL and checks the system for the tilde enum vuln and then find the files.
The Browser Exploitation Framework Project
Encodes a PowerShell script in the pixels of a PNG file and generates a oneliner to execute
g0tmi1k / SecLists
Forked from danielmiessler/SecListsSecLists is the security tester's companion. It is a collection of multiple types of lists used during security assessments. List types include usernames, passwords, URLs, sensitive data grep strin…
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
PowerSploit - A PowerShell Post-Exploitation Framework
lgandx / Responder
Forked from SpiderLabs/ResponderResponder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authenticat…
Impacket is a collection of Python classes for working with network protocols.