l3m0n

Elite
@l3m0n

招红队,实习正式都可以,简历请发hr#lichoin[dot]com

pentest_study. 从零开始内网渗透学习

3k

Bypass_Disable_functions_Shell. 一个各种方式突破Disable_functions达到命令执行的shell

1.2k

pentest_tools. 收集一些小型实用的工具

623

linux_information. 自动化收集linux信息

200

whatweb. 更快速的进行Web应用指纹识别

170

WebFuzzAttack. web模糊测试 - 将漏洞可能性放大

144

wooyun-wiki. wiki.wooyun.org的部分快照网页

80

XSS-Filter-Evasion-Cheat-Sheet-CN. XSS_Filter_Evasion_Cheat_Sheet 中文版

75

My_CTF_Challenges. C

41

vulenv. 漏洞测试环境 - 方便写扫描器利用复现

27

vtest. 用于辅助安全工程师漏洞挖掘、测试、复现,集合了mock、httplog、dns tools、xss,可用于测试各类无回显、无法直观判断或特定场景下的漏洞。

23

oauth2. oauth2研究: 实现代码、漏洞利用、修复方案

19

ctf-tools. Some setup scripts for security research tools.

18

WinPirate. Automated sticky keys hack. Post exploitation it grabs browser passwords, history, and network passwords

13

WebShell. Webshell && Backdoor Collection

12

backdoor_rootkit. C

7

1000php. 1000个PHP代码审计案例(2016.7以前乌云公开漏洞)

6

LBlog. 自写的一个小型php_mvc框架的blog,其前端采用bootstrap设计。

5

jd_maotai_seckill. 优化版本的京东茅台抢购神器

5

w8scan. 一款模仿bugscan的漏洞扫描器

5

AD-Attack-Defense. Active Directory Security For Red & Blue Team

5

chromium_for_spider. 为漏扫动态爬虫定制的浏览器

5

ctf_notice. ctf赛事通告

4

CVE-2019-11510. Exploit for Arbitrary File Read on Pulse Secure SSL VPN (CVE-2019-11510)

3

exploits. Python

3

python_certify. python 验证码识别

3

hackhttp. Hackhttp is an HTTP library, written in Python.

2

finalspeed. 高速双边加速软件,在高丢包,延迟环境下仍可达到90%物理带宽利用率.

2

maK_it-Linux-Rootkit. This is a linux rootkit using many of the techniques described on http://r00tkit.me

2

poc. poc from bugscan beebeeto

2

cobra. Cobra(眼镜蛇) - Static code security scanner & analyser (白盒代码安全扫描与分析系统)

2

kunpeng. kunpeng是一个Golang编写的开源POC框架/库,以动态链接库的形式提供各种语言调用,通过此项目可快速开发漏洞检测类的系统。

2

CVE-2016-0051-EXP. CVE-2016-0051 (MS-016) EXP on Win7 x86

2

exploit-CVE-2016-10033. PHPMailer < 5.2.18 Remote Code Execution

1

metinfo. PHP

1

tipi. Thinking In PHP Internals, An open book on PHP Internals

1

docker-vulnerability-environment. Use the docker to build a vulnerability environment

1

jenkins_unauthenticated_remote_code_execution. Jenkins RCE PoC. From unauthenticated user to remote code execution - it's a hacker's dream! (Chaining CVE-2019-1003000, CVE-2018-1999002, and more)

1

EQGRP. Decrypted content of eqgrp-auction-file.tar.xz

1

shelling. SHELLING - an offensive approach to the anatomy of improperly written OS command injection sanitisers

1

shadowbroker. Python

1

PowerSploit. PowerSploit - A PowerShell Post-Exploitation Framework

1

code_notice. 推送各类源码更新以及安全事件,保存每个版本代码到github以方便diff

1

openzeppelin-solidity. OpenZeppelin is a library for secure smart contract development

1

lxhToolHTTPDecrypt. HTTPDecrypt

1

HITCON-Training. For Linux binary Exploitation

1

sqlmap. Automatic SQL injection and database takeover tool

1

SMF. http://download.simplemachines.org/

1

phpyun. PHP

1

gwhatweb. CMS识别 python gevent实现

1

AutomatedLab. AutomatedLab is a provisioning solution and framework that lets you deploy complex labs on HyperV and Azure with simple PowerShell scripts. It supports all Windows operating systems from 2008 R2 to 2016 including Nano Server and various products like AD, Exchange, PKI, IIS, etc.

1

BurpSuite. BurpSuite using the document and some extensions

1

APTnotes. Various public documents, whitepapers and articles about APT campaigns

1

PowerUpSQL. PowerUpSQL: A PowerShell Toolkit for Attacking SQL Server

1

windows-pentest. Windows Pentest Scripts

1
55
Apply