xxlegend

Elite
@shengqi158

xxlegend.com

fastjson-remote-code-execute-poc. fastjson remote code execute poc 直接用intellij IDEA打开即可 首先编译得到Test.class,然后运行Poc.java

402

pyvulhunter. python audit tool 审计 注入 inject

183

Jackson-databind-RCE-PoC. Java

83

CVE-2018-2628. CVE-2018-2628 & CVE-2018-2893

78

svn_git_scanner. 用于扫描git,svn泄露

77

S2-055-PoC. S2-055的环境,基于rest-show-case改造

37

weak_password_detect. 多线程探测弱密码程序

32

RSA-Crypto-Burp-Extention. burp 插件 用于RSA 数据包加解密

28

svnhack. 用于还原svn仓库,支持1.6,1.7

26

IsIPInChina. 判断ip是否在中国,judge the ip if in china or not

6

english-level-up-tips-for-Chinese. 可能是让你受益匪浅的英语进阶指南

5

is_proxy_ok. is_proxy_ok.py 主要用于判断proxy是否可用,如果可用写入proxy_ok.txt中

5

shengqi158.github.io. HTML

4

restore_backup. 用于数据库的备份和还原的shell脚本

3

java-deserialization-exploits. A collection of curated Java Deserialization Exploits

3

Mind-Map. 各种安全相关思维导图整理收集

3

Chinese-Names-Corpus. 中文人名语料库

3

Some-PoC-oR-ExP. 各种漏洞poc、Exp的收集或编写

2

ThreadPool. 一个通用的线程池, general threadpool

2

BurpSuite. Python

2

myphpvulhunter. PHP

2

xunfeng. 巡风是一款适用于企业内网的漏洞快速应急,巡航扫描系统。

1

ml_hackers. Machine Learning For Hackers 中文版

1

gadgetinspector. A byte code analyzer for finding deserialization gadget chains in Java applications

1

WAFNinja. WAFNinja is a tool which contains two functions to attack Web Application Firewalls.

1

SerialWriter. SerialWriter is an incomplete implementation of Java serialization for study of Java deserialization vulnerabilities.

1

PayloadsAllTheThings. A list of useful payloads and bypass for Web Application Security and Pentest/CTF

1

JavaDeserH2HC. Sample codes written for the Hackers to Hackers Conference magazine 2017 (H2HC).

1

linux-kernel-exploits. linux-kernel-exploits Linux平台提权漏洞集合

1

vulhub. Docker-Compose file for vulnerability environment

1

PythonPool. Python 代码池

1

jd_spider. 两只蠢萌京东的分布式爬虫.

1

awesome-web-security. 🐶 A curated list of Web Security materials and resources.

1

Java-Deserialization-Cheat-Sheet. The cheat sheet about Java Deserialization vulnerabilities

1

ColdFusionPwn. Exploitation Tool for CVE-2017-3066 targeting Adobe Coldfusion 11/12

1

jmet. Java Message Exploitation Tool

1

JDK. JDK源码(1.7/1.8),方便在没IDE时查看源码;可调式JDK源码的rt_debug.jar

1

cupp. Common User Passwords Profiler (CUPP)

1

gitscan. Python

1

open_url_in_browser. 批量用浏览器打开文档中的url

1

MobileApp-Pentest-Cheatsheet. The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration testing topics.

1
41
Apply