This is your work, valued

e-mail: neargle@vulhub.org

neargle

Elite
@neargle

🌱 资深“安全从业焦虑”研究员 | RedTeam | Cloud Native | ACG | @cdk-team | @opensec-cn

re0-kubernetes-sec-archive. :atom: [WIP] 整理过去我和K8s、容器、虚拟化相关的分享 🧐

3.2k

win-powerup-exp-index. 🚄 火车上写的,2015年的代码和数据了

129

ver-observer. 🐽 Detection version of framework \ CMS \ dev-dependence on target website.

98

cloud_native_security_test_case. 🌶 一些和容器化/容器编排/服务网格等技术相关的安全代码片段[自用备份]

81

PIL-RCE-By-GhostButt. Exploiting Python PIL Module Command Execution Vulnerability

55

tips-note. 做过的实验,踩过的坑

39

cdk_document. 🌏 [WIP]整理好了之后迁移到 cdk-team/document,包含各类容器、K8s攻防场景的CDK文档。

26

Go-Get-RCE-CVE-2018-6574-POC. CVE-2018-6574 POC : golang 'go get' remote command execution during source code build

24

public-dns-list. Public Verified DNS List (Keep updating).

21

SecNewsBak. 背景: https://weibo.com/5084870733/E6GfkarzQ

21

django-cve-hub. 复现Django漏洞时的部分环境,推荐使用virtualenv还原部分漏洞

12

syslog. Golang - 获取Windows & Linux登录日志并正则解析

9

hacking-extensions. Hacking chrome extensions!

7

npm_evil_package. npm_evil_package

6

wooyun_articles. drops.wooyun.org 乌云Drops文章备份

6

neargle.github.io. 用于分享技术和交友的博客 https://blog.neargle.com/

6

CDK. CDK is an open-sourced container penetration toolkit, offering stable exploitation in different slimmed containers without any OS dependency. It comes with useful net-tools and many powerful PoCs/EXPs helps you to escape container and takeover K8s cluster easily.

6

neargle. ✨special ✨? Simple message from neargle.

4

1000php. 1000个PHP代码审计案例(2016.7以前乌云公开漏洞)

3

awesome-security-weixin-official-accounts. 网络安全类公众号推荐

3

BlueLotus_XSSReceiver. XSS平台 CTF工具 Web安全工具

3

beego. beego is an open-source, high-performance web framework for the Go programming language.

2

crx-scouter. 🕵️‍♂️ 🔎 🕸️ I Know U Have Installed These Chrome Extensions Below.

2

WebShell. WebShell Collect

2

PCShare. PCShare是一款强大的远程控制软件,可以监视目标机器屏幕、注册表、文件系统等。

2

nps. 一款轻量级、功能强大的内网穿透代理服务器。支持tcp、udp流量转发,支持内网http代理、内网socks5代理,同时支持snappy压缩、站点保护、加密传输、多路复用、header修改等。支持web图形化管理,集成多用户模式。

2

Blasting_dictionary. 爆破字典

2

xxxx. XXXX

2

beats. :tropical_fish: Beats - Lightweight shippers for Elasticsearch & Logstash

1

F-MiddlewareScan. A vulnerability detection scripts for middleware services

1

OWAduit.

1

betterdefaultpasslist.

1

pyvulhunter. python audit tool 审计 注入 inject

1

Mind-Map. 各种安全相关思维导图整理收集

1

IncExtensiveList. 从扫描器结果分离出的一些大公司泛解析ip列表

1

windows-kernel-exploits. windows-kernel-exploits Windows平台提权漏洞集合

1

brutemachine. A Go library which main purpose is giving an interface to loop over a dictionary and use those words/lines as input for some custom logic such as HTTP file bruteforcing, DNS bruteforcing, etc.

1