This is your work, valued

in Cloud

Esonhugh Skyworship

Elite
@Esonhugh

Your sincere exploitation/malware developer, Cloud Hacking Helper and golang developer. Do what no one has ever done

Attack_Code. 文章 Attack Code 的详细全文。安全和开发总是具有伴生属性,尤其是云的安全方向,本篇文章是希望能帮助到读者的云安全入门材料。Full text of the article Attack Code. Security and development always have concomitant attributes, and this is especially true with the security direction of the cloud. This article is an introduction to cloud security that I hope will help readers.

558

sshd_backdoor. /root/.ssh/authorized_keys evil file watchdog with ebpf tracepoint hook.

350

k8spider. Zero Privilege Kubernetes Penetration Testing problem solver

274

ingressNightmare-CVE-2025-1974-exps. IngressNightmare POC. world first non-blind remote execution exploitation with multi-advanced exploitation methods. allow on disk exploitation. CVE-2025-24514 - auth-url injection, CVE-2025-1097 - auth-tls-match-cn injection, CVE-2025-1098 – mirror UID injection -- all available.

97

Gopherus3. Python3 Based gopherus, completely refactored and added more feature.

86

Docker-Release-Agent-Escape. Docker 逃逸 Release Agent 利用始末

68

My-Cloud-Security. [ALL IN ONE] Everything that I shared to public about Cloud Security is here.

66

yapi-rce-webshell. Yapi mock script RCE another version. Webshell way. 另一种 Webshell 方式的 Yapi 命令执行的方法 相比于其他的利用方式 更加微操和可控 影响更小

66

public-nuclei-template. Esonhugh self-maintained-nuclei-templates public version. Use this as ~/nuclei-templates/local/esonhugh-public-nuclei, nuclei will add automatically when scanning and never conflict to other nuclei template.

59

ProxyInBrowser. Open Source XSS exploitation tool. using http proxy to access the browser which executed js. [Engineering Experimental]

42

KubernetesCS. Kubernetes has its “ADCS” -- How To Backdoor a Kubernetes in silence and more persistent?

40

SpringCloudHeapdump. anonymous to cluster-admin via Heapdump.

30

sliver-stage-helper. Let sliver use msf payload!

25

TicketMaster. Here is useful scripts collections. You can forge tickets locally with secret keys or certificates. It's useful when you want backdoor/persistence with opsec

19

flipper_kdf. Flipper zero NFC is mystery. KDF is the simple one in complicated

13

ebpf_cilium_starter. cilium ebpf common starter template for go.

12

macOSWXAutoPatcher. 自动化 macOS 微信 devtools Patcher 工具

12

KubernetesCRInjection. Here is a common vulnerability when Kubernetes Controller designed.

10

Self-Metasploit. Self collected Metasploit module (include self maintaining)

10

Spider-in-the-Pod-How-to-Penetrate-Kubernetes-with-Low-or-No-Privileges. Document of Spider in the Pod - How to Penetrate Kubernetes with Low or No Privileges

10

WizEKSClusterGame. Wp

10

ChatGPT-Web-Setting-Funny-Abuse. Play with ChatGPT-Web and found the HTML rendering in description settings. [Add Custom js and html in the XSS payload to enhanced ChatGPT-Web]

9

AI-Enhanced-hacking. AI Enhanced hacking and Osint Article

9

OpenAI-Platform-API. [DEPRECATED WARNING] Add SecretKey List it and Delete it API SDK

9

go-cli-template-v2. A Golang cli template based on Cobra Viper Survey...

8

my_durdur. Cilium/ebpf Learning idea from boratanrikulu/durdur

7

go-cli-template-v1. Cobra Viper TableWriter ColorCobra survey all in one template

7

CloudPolicy. An Cloud PolicyDocument go parsing library for AWS-like Cloud providers

7

KFC_Crazy_Thursday_in_metasploit. 肯德基疯狂星期四~~利用~~辅助模块

6

AliyunCTF-Email-Spoofing-DKIM-Creator. Aliyun CTF Teapot mail server POC for DKIM

6

SelfLinuxKernelDebugging. Based on arm64 linux kernel code using VSCode and qemu debug with gef. Self maintain.Works on KaliLinux in PD(m1 mac).

6

sculptor. Flexible and powerful Go library for transforming data from various formats (CSV, JSON, etc.) into desired Go struct types. (Insecure)

5

HTB-BusinessCTF-2024-Cloud. My writeup for hackthebox business CTF 2024 cloud part

5

apisix-webshell-rce. apisix Authed admin dashboard - RCE with web shell sample -

5

OpenShift_IGN_ConfigFileExtractor. Red Team Script for Cloud pentest with private Cloud built with OpenShift. Fast Extrated the config information in bootstrap.ign file

4

ShellScriptSnippet. abbr. as sss. This is a Utils designed for Terminal based user for manage, share, logging their Shell Script in one place.

4

ebpf_cilium_doc. unofficial guide of cilium/ebpf library. 非官方 cilium ebpf 库踩坑指南

4

gitlab_honeypot. CVE-2023-7028 killer

4

Nuclei-Template-Backup. Official Nuclei Template and other templates

4

tencent-coding-openapi. 腾讯云 Coding CICD Devops 一体化平台 OpenApi 对接 SDK 以及个人或 OAuth Token 利用演示

4

-WinAPI-Tricks-backup. from user: https://github.com/vxunderground/WinAPI-Tricks.git and https://github.com/vxunderground/VX-API

3

ConsoleHook. Easy Simple Console hook of TamperMonkey

3

My-CTF-Challenge. CTF Challenge I designed

2

wechat-template. 微信公众号后端的快速开发框架

2

customMeterpreterTCPListener. x64 Linux (Kernel > 3.19) custom Meterpreter-like shellcode experiment

2

Devstream-ConfigFile-Command-Injection. Devstream Command injection via evil yaml file in plugin gitlab-ce-docker

2

EvilSlnProject. Same as csproj powerlessshell but using sln to redirect to csproj file

1

justhomework. HDU Help test homework

1

update-alternative-java. MacOS - Java version switcher based on PATH environment hijack.(self used)

1