The earth

whw1sfb

Elite
@whwlsfb

A Security Researcher & Developer & Geeker

JDumpSpider. HeapDump敏感信息提取工具

1.7k

BurpCrypto. BurpCrypto is a collection of burpsuite encryption plug-ins, support AES/RSA/DES/ExecJs(execute JS encryption code in burpsuite). 支持多种加密算法或直接执行JS代码的用于爆破前端加密的BurpSuite插件

1.6k

Log4j2Scan. Log4j2 RCE Passive Scanner plugin for BurpSuite

836

ViewState-Cracker. ASP.net ViewState密钥被动扫描爆破BurpSuite插件

237

cve-2022-22947-godzilla-memshell. CVE-2022-22947 注入Godzilla内存马

210

SpringSpider. Spring Actuator端点的BurpSuite被动扫描插件。

202

pty_bind_shell. Pty bind shell for golang 一款基于SSH协议的远控程序

48

CVE-2021-22205. CVE-2021-22205 Gitlab 未授权远程代码执行漏洞 EXP, 移除了对djvumake & djvulibre的依赖,可在win平台使用

23

BurpCrypto-JsLibrary. BurpCrypto officially confirms the supported JS library (BurpCrypto官方确认支持的JS库).

12

ExploitDBHelper. ExploitDB toolkit ExploitDB辅助工具

11

SwaggerHelper. 用于启动本地保存的api-docs.json文档。

9

CryptoWatcher. 一个简单的虚拟货币盯盘程序,行情数据来源于火币交易所。

5

RandomIDCard. 随机身份证号码生成器

4

agentcrack. 不那么一样的 Java Agent 内存马

3

BurpSuite-collections. 有关burpsuite的插件(非商店),文章以及使用技巧的收集(此项目不再提供burpsuite破解文件,如需要请在博客mrxn.net下载)---Collection of burpsuite plugins (non-stores), articles and tips for using Burpsuite, no crack version file

3

telegram_media_downloader. Download media files from a telegram conversation/chat/channel

2

hscan. 用于网站状况检测、通知的脚本。

2

HLSpider. 基于Scrapy的页面敏感词检测工具

1

log4j-payload-generator. Log4j jndi injects the Payload generator

1

jar-analyzer. Jar Analyzer - 一个JAR包分析工具,批量分析搜索,方法调用关系搜索,字符串搜索,Spring分析,CFG分析,JVM Stack Frame分析等众多功能

1

viewgen. Viewgen is a ViewState tool capable of generating both signed and encrypted payloads with leaked validation keys

1

anti-portscan. 使用 iptables 防止端口扫描

1

dnslog-2. dnslog dns / dns rebinding platform

1

F-Scrack. 一款python编写的轻量级弱口令检测脚本,目前支持以下服务:FTP、MYSQL、MSSQL、MONGODB、REDIS、TELNET、ELASTICSEARCH、POSTGRESQL。

1

CDK. CDK is an open-sourced container penetration toolkit, offering stable exploitation in different slimmed containers without any OS dependency. It comes with penetration tools and many powerful PoCs/EXPs helps you to escape container and takeover K8s cluster easily.

1

onedev. Super Easy All-In-One DevOps Platform

1

goby_poc. goby poc or exp,分享goby最新网络安全漏洞检测或利用代码

1

revsuit. RevSuit is a flexible and powerful reverse connection platform designed for receiving connection from target host in penetration.

1

frp. A fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet.

1
29
Apply