BlockChain Fans
2018-BlackHat-Tools-List. 2018 BlackHat Tools List
388BlockChain-Security-List. BlockChain-Security-List
106Issue-198327. A Webkit RCE exploit and an SBX bug
35Powershell-Attack-Guide. Powershell攻击指南----黑客后渗透之道
28poc-2. PowerShell
20CVE-2018-3191. CVE-2018-3191 反弹shell
16Powerful-Plugins. Powerful plugins and add-ons for hackers
10sploits. C++
7Modlishka-Phishing-NG. Modlishka. Reverse Proxy. 2FA authentication Phishing NG.
6Prowl. Python
5Redmine-CVE-2019-18890. CVE-2019-18890 POC (Proof of Concept)
4gitleaks-git-repos-for-secrets. Audit git repos for secrets 🔑
3svnExploit. SvnExploit支持SVN源代码泄露全版本Dump源码
3takeover. Shell
3virtualbox_e1000_0day. VirtualBox E1000 Guest-to-Host Escape
3Awesome-Fuzzing. A curated list of fuzzing resources ( Books, courses - free and paid, videos, tools, tutorials and vulnerable applications to practice on ) for learning Fuzzing and initial phases of Exploit Development like root cause analysis.
2CVE-2020-17382. PoC exploits for CVE-2020-17382
2Can-my-iPhone-crash. A iOS 12 and 11 webkit exploit
2Windows-10-Exploit. Windows 10 Exploit
2Awesome-Hacking-Resources. A collection of hacking / penetration testing resources to make you better!
2awesome-browser-exploit. awesome list of browser exploitation tutorials
2android_app_security_checklist. Android App Security Checklist
2CORScanner. 🍻 Fast CORS misconfiguration vulnerabilities scanner
2iOSREBook. 《iOS应用逆向与安全》随书源码
2CVE-2018-7601-Exploit-for-Drupal-7. Exploit for Drupal 7 <= 7.57 CVE-2018-7600
2solidity-security-blog. Comprehensive list of known attack vectors and common anti-patterns
2BHR_Labs. Black Hat Ruby book | all labs files
1naabu. A fast port scanner written in go with focus on reliability and simplicity. Designed to be used in combination with other tools for attack surface discovery in bug bounties and pentests
1onekeyhq.github.io. onekeyhq.github.io
1medusa_combo_files. Combinations of default usernames and passwords for the Medusa password cracker
1nosqli-sql. NoSql Injection CLI tool
1CVE-Reverse. Python
1Fully-Undetectable-Techniques. C
1HackBrowserData. Decrypt passwords/cookies/history/bookmarks from the browser. 一款支持全平台的浏览器数据(Passwords | History | Bookmarks | Cookies)导出工具
1bombus. 合规审计平台
1Middleware-Vulnerability-detection. CVE、CMS、中间件漏洞检测利用合集 Since 2019-9-15
1jfrog-npm-tools. Python
1OktaPostExToolkit. Python
1fscan-Intranet. Go
1Ladon-for-CobaltStrike. Ladon for Cobalt Strike, Large Network Penetration Scanner, vulnerability / exploit / detection / MS17010 / password/brute-force/psexec/atexec/sshexec/webshell/smbexec/netcat/osscan/netscan/struts2Poc/weblogicExp
1fhe-toolkit-linux. IBM Fully Homomorphic Encryption Toolkit For Linux. This toolkit is a Linux based Docker container that demonstrates computing on encrypted data without decrypting it! The toolkit ships with two demos including a fully encrypted Machine Learning inference with a Neural Network and a Privacy-Preserving key-value search.
1unauthorized-check. 扫描常见未授权访问(改)(redis、mongodb、memcached、elasticsearch、zookeeper、ftp、CouchDB、docker、Hadoop)
1Dictionary-Of-Pentesting. Dictionary collection project such as Pentesing, Fuzzing, Bruteforce and BugBounty. 渗透测试、SRC漏洞挖掘、爆破、Fuzzing等字典收集项目。
1Miscellaneous. 百宝箱
1cotopaxi. Set of tools for security testing of Internet of Things devices using specific network IoT protocols
1IntelOwl. Intel Owl: analyze files, domains, IPs in multiple ways from a single API at scale
1Dirscan. 🎃 目录扫描工具 Dirscan
1JNDI-Exploit-Bypass-Demo. Demo code for post <Restrictions of JNDI Manipulation RCE & Bypass>
1FRIDA-DEXDump. Fast search and dump dex on memory.
1owasp-mstg. The Mobile Security Testing Guide (MSTG) is a comprehensive manual for mobile app security development, testing and reverse engineering.
1linbingVulScanner. 本系统是对目标进行漏洞扫描的一个系统,前端采用vue技术,后端采用flask.核心原理是扫描主机的开放端口情况,然后根据端口情况逐个去进行poc检测,poc有110多个,包含绝大部分的中间件漏洞,本系统的poc皆来源于网络或在此基础上进行修改,在centons7环境下使用nginx和uwsgi部署,部署起来可能有点麻烦,烦请多点耐心
1