Stars
Kscan是一款纯go开发的全方位扫描器,具备端口扫描、协议检测、指纹识别,暴力破解等功能。支持协议1200+,协议指纹10000+,应用指纹20000+,暴力破解协议10余种。
greg-wu / zhao
Forked from programthink/zhao【编程随想】整理的《太子党关系网络》,专门揭露赵国的权贵
Java漏洞学习笔记 Deserialization Vulnerability
Welcome to the page where you will find each trick/technique/whatever I have learnt in CTFs, real life apps, and reading researches and news.
A versatile and portable proxy for capturing, manipulating, and replaying HTTP/HTTPS traffic on the go.
《深入理解Vue.js实战》- 介绍Vue.js框架的出现、设计和使用,结合实战让读者更深入理解Vue.js框架,掌握使用方法。
Faster xss scanner,support reflected-xss and dom-xss
Packer Fuzzer is a fast and efficient scanner for security detection of websites constructed by javascript module bundler such as Webpack.
JexBoss: Jboss (and Java Deserialization Vulnerabilities) verify and EXploitation Tool
Collect JSP webshell of various implementation methods. 梳理和发现的JSP Webshell各种姿势
BurpCrypto is a collection of burpsuite encryption plug-ins, support AES/RSA/DES/ExecJs(execute JS encryption code in burpsuite). 支持多种加密算法或直接执行JS代码的用于爆破前端加密的BurpSuite插件
Web Fuzzing Box - Web 模糊测试字典与一些Payloads
Neo-reGeorg is a project that seeks to aggressively refactor reGeorg
JNDI注入测试工具(A tool which generates JNDI links can start several servers to exploit JNDI Injection vulnerability,like Jackson,Fastjson,etc)
Litch1-v / ysoserial
Forked from kingkaki/ysoserialA proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.
kingkaki / ysoserial
Forked from frohoff/ysoserialA proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.
A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.
Shiro550/Shiro721 一键化利用工具,支持多种回显方式
SpringBoot 相关漏洞学习资料,利用方法和技巧合集,黑盒安全评估 check list
Exphub[漏洞利用脚本库] 包括Webloigc、Struts2、Tomcat、Nexus、Solr、Jboss、Drupal的漏洞利用脚本,最新添加CVE-2020-14882、CVE-2020-11444、CVE-2020-10204、CVE-2020-10199、CVE-2020-1938、CVE-2020-2551、CVE-2020-2555、CVE-2020-2883、CVE-…
GoReplay is an open-source tool for capturing and replaying live HTTP traffic into a test environment in order to continuously test your system with real data. It can be used to increase confidence…