Skip to content
View nanaao's full-sized avatar

Block or report nanaao

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse

Starred repositories

Showing results

目标是成为当下最完善的API挖掘工具,实现自动提取响应敏感信息、URI信息,并且对URI进行自动|手动递归检查

Java 197 7 Updated Jan 7, 2025

【Hello-CTF labs】新手向的ssrf靶场,从协议,场景,绕过等多个ssrf攻击的基础维度展开。

PHP 41 Updated Mar 22, 2025

对shellcode进行xor、aes加解密来绕过杀毒软件的静态查杀

C++ 31 5 Updated May 24, 2023

CoreDNS is a DNS server that chains plugins

Go 12,803 2,195 Updated Mar 24, 2025

CVE-2022-41678: Dangerous MBeans Accessible via Jolokia API in Apache ActiveMQ

3 Updated Nov 28, 2024

使用docker快速搭建各大漏洞靶场,目前可以一键搭建17个靶场。

Shell 2,304 487 Updated Mar 25, 2020

Proof of concept & details for CVE-2025-21298

Rich Text Format 169 46 Updated Jan 20, 2025

This repo offers a tool to reveal password encrypted by MobaXterm.

Python 306 97 Updated Oct 12, 2022

AV/EDR Evasion Lab for Training & Learning Purposes

C++ 1,214 130 Updated Feb 17, 2025

针对JWT渗透开发的漏洞验证/密钥爆破工具,针对CVE-2015-9235/空白密钥/未验证签名攻击/CVE-2016-10555/CVE-2018-0114/CVE-2020-28042的结果生成用于FUZZ,也可使用字典/字符枚举(包括JJWT)的方式进行爆破(JWT Crack)

Go 193 7 Updated Mar 12, 2025

🌐 Modern, lightweight WireGuard VPN web ui panel with a beautiful UI.

HTML 17 Updated Mar 3, 2025

Fileless attack with persistence

C++ 348 57 Updated Nov 28, 2024

OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies.

Java 6,814 1,339 Updated Mar 24, 2025

CVS is a powerful comprehensive attack surface management platform. 森罗万象-强大的网络空间测绘、资产管理、漏洞扫描等全生命漏洞周期的综合攻击面管理平台,化繁为简,以一御百。

125 14 Updated Mar 13, 2025

WgpSec 公开POC WIKI文库 @PeiQi0 师傅

Python 134 50 Updated Jun 28, 2021

备份的漏洞库,3月开始我们来维护

608 218 Updated Mar 24, 2025

一款用于网页敏感信息检测,指纹识别的chrome插件

JavaScript 142 8 Updated Feb 25, 2025
Go 232 19 Updated Nov 21, 2024

一款针对Spring框架的漏洞扫描及漏洞利用图形化工具

165 7 Updated Mar 4, 2025

FastjsonScan4Burp 一款基于burp被动扫描的fastjson漏洞探测插件,可针对数据包中存在json的参数或请求体进行payload测试。旨在帮助安全人员更加便捷的发现、探测、深入利用fastjson漏洞,目前已实现fastjson探测、版本、依赖探测、出网及不出网利用和简易的bypass waf功能

Java 76 4 Updated Mar 13, 2025

SoaPy is a Proof of Concept (PoC) tool for conducting offensive interaction with Active Directory Web Services (ADWS) from Linux hosts.

Python 170 14 Updated Feb 21, 2025
Python 643 87 Updated Mar 4, 2025

Appshark is a static taint analysis platform to scan vulnerabilities in an Android app.

Kotlin 1,602 169 Updated Jan 9, 2025

Docker Remote API Scanner and Exploit

Python 171 38 Updated Nov 13, 2023

jeecgBoot漏洞利用工具

Java 20 2 Updated Feb 1, 2025

FindGPPPasswords, A cross-platform tool to find and decrypt Group Policy Preferences passwords from the SYSVOL share using low-privileged domain accounts.

Go 130 20 Updated Feb 25, 2025

Topic: The Swiss Army Knife of Java Exploitation

20 3 Updated Feb 25, 2025

DISKSPD is a storage load generator / performance test tool from the Windows/Windows Server and Cloud Server Infrastructure Engineering teams

C++ 1,222 222 Updated Jun 14, 2024

Windows Kernel Rootkit in Rust

Rust 515 59 Updated Mar 6, 2025

A small tool built to find and fix common misconfigurations in Active Directory Certificate Services.

PowerShell 1,057 100 Updated Mar 19, 2025
Next
Showing results