Skip to content
View yhy0's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report yhy0

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Stars

exp

6 repositories

Nacos JRaft Hessian 反序列化 RCE 加载字节码 注入内存马 不出网利用

Java 848 91 Updated Jul 7, 2023

一款针对Vcenter的综合利用工具,包含目前最主流的CVE-2021-21972、CVE-2021-21985以及CVE-2021-22005、One Access的CVE-2022-22954、CVE-2022-22972/31656以及log4j,提供一键上传webshell,命令执行或者上传公钥使用SSH免密连接

Go 1,464 167 Updated Apr 25, 2024

云资产管理工具 目前工具定位是云安全相关工具,目前是两个模块 云存储工具、云服务工具, 云存储工具主要是针对oss存储、查看、删除、上传、下载、预览等等 云服务工具主要是针对rds、服务器的管理,查看、执行命令、接管等等

1,138 77 Updated Nov 28, 2024

用java实现构造openwire协议,利用activeMQ < 5.18.3 RCE 回显利用 内存马注入

Java 288 26 Updated Nov 20, 2023

基于 jdwp-shellifier 的进阶JDWP漏洞利用脚本(动态执行Java/Js代码并获得回显)

Python 321 31 Updated Dec 22, 2024

⬆️ ☠️ 🔥 Automatic Linux privesc via exploitation of low-hanging fruit e.g. gtfobins, pwnkit, dirty pipe, +w docker.sock

Go 7,111 679 Updated Mar 12, 2024