xxlegend.com
fastjson-remote-code-execute-poc. fastjson remote code execute poc 直接用intellij IDEA打开即可 首先编译得到Test.class,然后运行Poc.java
402pyvulhunter. python audit tool 审计 注入 inject
183Jackson-databind-RCE-PoC. Java
83CVE-2018-2628. CVE-2018-2628 & CVE-2018-2893
78svn_git_scanner. 用于扫描git,svn泄露
77S2-055-PoC. S2-055的环境,基于rest-show-case改造
37weak_password_detect. 多线程探测弱密码程序
32RSA-Crypto-Burp-Extention. burp 插件 用于RSA 数据包加解密
28svnhack. 用于还原svn仓库,支持1.6,1.7
26IsIPInChina. 判断ip是否在中国,judge the ip if in china or not
6english-level-up-tips-for-Chinese. 可能是让你受益匪浅的英语进阶指南
5is_proxy_ok. is_proxy_ok.py 主要用于判断proxy是否可用,如果可用写入proxy_ok.txt中
5shengqi158.github.io. HTML
4restore_backup. 用于数据库的备份和还原的shell脚本
3java-deserialization-exploits. A collection of curated Java Deserialization Exploits
3Mind-Map. 各种安全相关思维导图整理收集
3Chinese-Names-Corpus. 中文人名语料库
3Some-PoC-oR-ExP. 各种漏洞poc、Exp的收集或编写
2ThreadPool. 一个通用的线程池, general threadpool
2BurpSuite. Python
2myphpvulhunter. PHP
2xunfeng. 巡风是一款适用于企业内网的漏洞快速应急,巡航扫描系统。
1ml_hackers. Machine Learning For Hackers 中文版
1gadgetinspector. A byte code analyzer for finding deserialization gadget chains in Java applications
1WAFNinja. WAFNinja is a tool which contains two functions to attack Web Application Firewalls.
1SerialWriter. SerialWriter is an incomplete implementation of Java serialization for study of Java deserialization vulnerabilities.
1PayloadsAllTheThings. A list of useful payloads and bypass for Web Application Security and Pentest/CTF
1JavaDeserH2HC. Sample codes written for the Hackers to Hackers Conference magazine 2017 (H2HC).
1linux-kernel-exploits. linux-kernel-exploits Linux平台提权漏洞集合
1vulhub. Docker-Compose file for vulnerability environment
1PythonPool. Python 代码池
1jd_spider. 两只蠢萌京东的分布式爬虫.
1awesome-web-security. 🐶 A curated list of Web Security materials and resources.
1Java-Deserialization-Cheat-Sheet. The cheat sheet about Java Deserialization vulnerabilities
1ColdFusionPwn. Exploitation Tool for CVE-2017-3066 targeting Adobe Coldfusion 11/12
1jmet. Java Message Exploitation Tool
1JDK. JDK源码(1.7/1.8),方便在没IDE时查看源码;可调式JDK源码的rt_debug.jar
1cupp. Common User Passwords Profiler (CUPP)
1gitscan. Python
1open_url_in_browser. 批量用浏览器打开文档中的url
1MobileApp-Pentest-Cheatsheet. The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration testing topics.
1