This is your work, valued
Your sincere exploitation/malware developer, Cloud Hacking Helper and golang developer. Do what no one has ever done
Attack_Code. 文章 Attack Code 的详细全文。安全和开发总是具有伴生属性,尤其是云的安全方向,本篇文章是希望能帮助到读者的云安全入门材料。Full text of the article Attack Code. Security and development always have concomitant attributes, and this is especially true with the security direction of the cloud. This article is an introduction to cloud security that I hope will help readers.
558sshd_backdoor. /root/.ssh/authorized_keys evil file watchdog with ebpf tracepoint hook.
350k8spider. Zero Privilege Kubernetes Penetration Testing problem solver
274ingressNightmare-CVE-2025-1974-exps. IngressNightmare POC. world first non-blind remote execution exploitation with multi-advanced exploitation methods. allow on disk exploitation. CVE-2025-24514 - auth-url injection, CVE-2025-1097 - auth-tls-match-cn injection, CVE-2025-1098 – mirror UID injection -- all available.
97Gopherus3. Python3 Based gopherus, completely refactored and added more feature.
86Docker-Release-Agent-Escape. Docker 逃逸 Release Agent 利用始末
68My-Cloud-Security. [ALL IN ONE] Everything that I shared to public about Cloud Security is here.
66yapi-rce-webshell. Yapi mock script RCE another version. Webshell way. 另一种 Webshell 方式的 Yapi 命令执行的方法 相比于其他的利用方式 更加微操和可控 影响更小
66public-nuclei-template. Esonhugh self-maintained-nuclei-templates public version. Use this as ~/nuclei-templates/local/esonhugh-public-nuclei, nuclei will add automatically when scanning and never conflict to other nuclei template.
59ProxyInBrowser. Open Source XSS exploitation tool. using http proxy to access the browser which executed js. [Engineering Experimental]
42KubernetesCS. Kubernetes has its “ADCS” -- How To Backdoor a Kubernetes in silence and more persistent?
40SpringCloudHeapdump. anonymous to cluster-admin via Heapdump.
30sliver-stage-helper. Let sliver use msf payload!
25TicketMaster. Here is useful scripts collections. You can forge tickets locally with secret keys or certificates. It's useful when you want backdoor/persistence with opsec
19flipper_kdf. Flipper zero NFC is mystery. KDF is the simple one in complicated
13ebpf_cilium_starter. cilium ebpf common starter template for go.
12macOSWXAutoPatcher. 自动化 macOS 微信 devtools Patcher 工具
12KubernetesCRInjection. Here is a common vulnerability when Kubernetes Controller designed.
10Self-Metasploit. Self collected Metasploit module (include self maintaining)
10Spider-in-the-Pod-How-to-Penetrate-Kubernetes-with-Low-or-No-Privileges. Document of Spider in the Pod - How to Penetrate Kubernetes with Low or No Privileges
10WizEKSClusterGame. Wp
10ChatGPT-Web-Setting-Funny-Abuse. Play with ChatGPT-Web and found the HTML rendering in description settings. [Add Custom js and html in the XSS payload to enhanced ChatGPT-Web]
9AI-Enhanced-hacking. AI Enhanced hacking and Osint Article
9OpenAI-Platform-API. [DEPRECATED WARNING] Add SecretKey List it and Delete it API SDK
9go-cli-template-v2. A Golang cli template based on Cobra Viper Survey...
8my_durdur. Cilium/ebpf Learning idea from boratanrikulu/durdur
7go-cli-template-v1. Cobra Viper TableWriter ColorCobra survey all in one template
7CloudPolicy. An Cloud PolicyDocument go parsing library for AWS-like Cloud providers
7KFC_Crazy_Thursday_in_metasploit. 肯德基疯狂星期四~~利用~~辅助模块
6AliyunCTF-Email-Spoofing-DKIM-Creator. Aliyun CTF Teapot mail server POC for DKIM
6SelfLinuxKernelDebugging. Based on arm64 linux kernel code using VSCode and qemu debug with gef. Self maintain.Works on KaliLinux in PD(m1 mac).
6sculptor. Flexible and powerful Go library for transforming data from various formats (CSV, JSON, etc.) into desired Go struct types. (Insecure)
5HTB-BusinessCTF-2024-Cloud. My writeup for hackthebox business CTF 2024 cloud part
5apisix-webshell-rce. apisix Authed admin dashboard - RCE with web shell sample -
5OpenShift_IGN_ConfigFileExtractor. Red Team Script for Cloud pentest with private Cloud built with OpenShift. Fast Extrated the config information in bootstrap.ign file
4ShellScriptSnippet. abbr. as sss. This is a Utils designed for Terminal based user for manage, share, logging their Shell Script in one place.
4ebpf_cilium_doc. unofficial guide of cilium/ebpf library. 非官方 cilium ebpf 库踩坑指南
4gitlab_honeypot. CVE-2023-7028 killer
4Nuclei-Template-Backup. Official Nuclei Template and other templates
4tencent-coding-openapi. 腾讯云 Coding CICD Devops 一体化平台 OpenApi 对接 SDK 以及个人或 OAuth Token 利用演示
4-WinAPI-Tricks-backup. from user: https://github.com/vxunderground/WinAPI-Tricks.git and https://github.com/vxunderground/VX-API
3ConsoleHook. Easy Simple Console hook of TamperMonkey
3My-CTF-Challenge. CTF Challenge I designed
2wechat-template. 微信公众号后端的快速开发框架
2customMeterpreterTCPListener. x64 Linux (Kernel > 3.19) custom Meterpreter-like shellcode experiment
2Devstream-ConfigFile-Command-Injection. Devstream Command injection via evil yaml file in plugin gitlab-ce-docker
2EvilSlnProject. Same as csproj powerlessshell but using sln to redirect to csproj file
1justhomework. HDU Help test homework
1update-alternative-java. MacOS - Java version switcher based on PATH environment hijack.(self used)
1