E-mails, subdomains and names Harvester - OSINT
A Python program to scrape secrets from GitHub through usage of a large repository of dorks.
🚀Vulfocus 是一个漏洞集成平台,将漏洞环境 docker 镜像,放入即可使用,开箱即用。
渗透测试有关的POC、EXP、脚本、提权、小工具等---About penetration-testing python-script poc getshell csrf xss cms php-getshell domainmod-xss csrf-webshell cobub-razor cve rce sql sql-poc poc-exp bypass oa-getshell cve…
PowerSploit - A PowerShell Post-Exploitation Framework
A GUI client for Windows, Linux and macOS, support Xray and sing-box and others
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
Penetration tests guide based on OWASP including test cases, resources and examples.
windows-kernel-exploits Windows平台提权漏洞集合
👮🏻♂️ XSS attack playground,there are answers in issues. XSS 攻防靶场,issues 有答案
SQLI labs to test error based, Blind boolean based, Time based.
An advanced web directory & file scanning tool that will be more powerful than DirBuster, Dirsearch, cansina, and Yu Jian.一个高级web目录、文件扫描工具,功能将会强于DirBuster、Dirsearch、cansina、御剑。
Tools to work with android .dex and java .class files
A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.
Shiro550/Shiro721 一键化利用工具,支持多种回显方式
An exploit for Apache Struts CVE-2017-9805