This is your work, valued

brianwrf

Elite
@brianwrf

Security Researcher

hackUtils. It is a hack tool kit for pentest and web security research.

519

WinSystemHelper. A tool that checks and downloads scripts that will aid with privilege escalation on a Windows system.

172

HackRequests. It is a dedicated requests lib that supports cookie, headers, get/post, etc. And it also supports rendering the response (e.g. Javascript, CSS, etc.) of GET requests by using PhantomJs enginee.

86

WordPress_4.9.8_RCE_POC. A simple PoC for WordPress RCE (author priviledge), refer to CVE-2019-8942 and CVE-2019-8943.

74

SambaHunter. It is a simple script to exploit RCE for Samba (CVE-2017-7494 ).

57

ysoserial. A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.

48

RootHelper. A Bash script that downloads and unzips scripts that will aid with privilege escalation on a Linux system.

47

CVE-2018-11788. Apache Karaf XXE Vulnerability (CVE-2018-11788)

37

S2-053-CVE-2017-12611. A simple script for exploit RCE for Struts 2 S2-053(CVE-2017-12611)

37

myPadBuster. It is a Python+Perl script to exploit ASP.net Padding Oracle vulnerability.

18

CVE-2017-4878-Samples. CVE-2017-4878 Samples - http://blog.talosintelligence.com/2018/02/group-123-goes-wild.html

17

RTEmulation. It is a repository for Red Team emulation based on MITRE ATT&CK.

16

S2-057-CVE-2018-11776. A simple exploit for Apache Struts RCE S2-057 (CVE-2018-11776)

16

Mind-Map. 各种安全相关思维导图整理收集

12

CVE-2016-0051. BSoD PoC for CVE-2016-0051 (MS-016)

10

CVE-2018-11761. Apache Tika Denial of Service Vulnerability (CVE-2018-11761)

9

openvpn-easy-config. openvpn easy config for Ubuntu ONLY

8

Joomla3.7-SQLi-CVE-2017-8917. Joomla 3.7 SQL injection (CVE-2017-8917)

7

BlueLotus_XSSReceiver. XSS平台 CTF工具 Web安全工具

7

TechArticles. A set of tech articles.

7

Magento-CVE-2016-4010. Magento Unauthorized Remote Code Execution (CVE-2016-4010)

6

CVE-2019-6690. It is a simple PoC of Improper Input Validation in python-gnupg 0.4.3 (CVE-2019-6690).

6

xsshunter. The XSS Hunter service - a portable version of XSSHunter.com

5

cve-2006-6184. This is a python-based standalone exploit for CVE-2006-6184. This exploit triggers a stack-based buffer overflows in Allied Telesyn TFTP Server (AT-TFTP) 1.9, and possibly earlier, allow remote attackers to cause a denial of service or execute arbitrary code.

5

Scanners-Box. 安全行业从业人员自研开源扫描器合集(不收录w3af、brakeman等知名扫描工具)

4

fileBatchUpload. 基于菜刀PHP一句话实现单个文件批量上传

4

Awesome-Red-Teaming. List of Awesome Red Teaming Resources

3

DeathStar. Automate getting Domain Admin using Empire (https://github.com/EmpireProject/Empire)

3

BlueKeep. Proof of concept for CVE-2019-0708

3

checkVT. This is Python script to calculate SH256 for all files under the defined file path and check the scanning results on VirusTotal.com

3

NagaScan. NagaScan is a distributed passive vulnerability scanner for Web application.

3

awesome-jenkins-rce-2019. There is no pre-auth RCE in Jenkins since May 2017, but this is the one!

3

AwesomeSOC. This repository is a set of articles about what SOC is and how SOC is working in a big Internet firm.

3

awesome-pentest. A collection of awesome penetration testing resources, tools and other shiny things

2

ctf-tools. Some setup scripts for security research tools.

2

antSword. 中国蚁剑是一款跨平台的开源网站管理工具

2

fame. FAME Automates Malware Evaluation

2

jdwp-shellifier. Python

2

awesome-python-cn. Python资源大全中文版,包括:Web框架、网络爬虫、模板引擎、数据库、数据可视化、图片处理等,由伯乐在线持续更新。

2

assetnote. Push notifications for passive DNS data

2

exploits. Python

2

VulScritp. 内网渗透脚本

2

QuasarRAT. Remote Administration Tool for Windows

2

MS17-010. MS17-010

2

Awsome-Redis-Rogue-Server. Redis-Rogue-Server Implement

2

Java-Deserialization-Cheat-Sheet. The cheat sheet about Java Deserialization vulnerabilities

2

Infosec_Reference. An Information Security Reference That Doesn't Suck

2

pocscan. Will to be a niubility scan-framework

2

CDK. CDK is an open-sourced container penetration toolkit, offering stable exploitation in different slimmed containers without any OS dependency. It comes with penetration tools and many powerful PoCs/EXPs helps you to escape container and takeover K8s cluster easily.

1

CVE-2020-0683. CVE-2020-0683 - Windows MSI “Installer service” Elevation of Privilege

1

security-research. This project hosts security advisories and their accompanying proof-of-concepts related to research conducted at Google which impact non-Google owned code.

1

WMImplant. This is a PowerShell based tool that is designed to act like a RAT. Its interface is that of a shell where any command that is supported is translated into a WMI-equivalent for use on a network/remote machine. WMImplant is WMI based.

1

PayloadsAllTheThings. A list of useful payloads and bypass for Web Application Security and Pentest/CTF

1

XXEinjector. Tool for automatic exploitation of XXE vulnerability using direct and different out of band methods.

1

meltdown-exploit. C

1

process_doppelganging. My implementation of enSilo's Process Doppelganging (PE injection technique)

1

red-team-scripts. A collection of Red Team focused tools, scripts, and notes

1

monkey. Infection Monkey - An automated pentest tool

1