Hacker-One's repositories

Bridge

无回显漏洞测试辅助平台,平台使用Java编写,提供DNSLOG,HTTPLOG等功能,辅助渗透测试过程中无回显漏洞及SSRF等漏洞的验证和利用。

Language:JavaStargazers:3Issues:1Issues:0

PHP-Audit-Labs

一个关于PHP的代码审计项目

Language:PHPStargazers:3Issues:1Issues:0

fastjson_rce_tool

fastjson_rce工具,不用搭建HTTP服务,不受JDK版本限制

shiro_rce

shiro rce 反序列 命令执行 一键工具

SuperWordlist

基于实战沉淀下的各种弱口令字典

Stargazers:2Issues:0Issues:0

LangSrcCurise

SRC子域名资产监控

Language:PythonStargazers:1Issues:0Issues:0

automactc

AutoMacTC: Automated Mac Forensic Triage Collector

Language:PythonLicense:NOASSERTIONStargazers:0Issues:1Issues:0

collection-document

Collection of quality safety articles

Stargazers:0Issues:0Issues:0

CS-checklist

PC客户端(C-S架构)渗透测试checklist / Client side(C-S) penestration checklist

License:MITStargazers:0Issues:1Issues:0

CVE-2019-11043

(PoC) Python version of CVE-2019-11043 exploit by neex

Language:PythonStargazers:0Issues:1Issues:0

CVE-2019-7609

exploit CVE-2019-7609(kibana RCE) on right way by python2 scripts

Language:PythonLicense:MITStargazers:0Issues:1Issues:0

fastjson-1.2.60-rce

autoType enable

Stargazers:0Issues:1Issues:0

GadgetProbe

Probe endpoints consuming Java serialized objects to identify classes, libraries, and library versions on remote Java classpaths.

Language:JavaLicense:MITStargazers:0Issues:1Issues:0

graudit

grep rough audit - source code auditing tool

Language:ShellLicense:GPL-3.0Stargazers:0Issues:1Issues:0

JDSRC-Small-Classroom

京东SRC小课堂系列文章

Stargazers:0Issues:1Issues:0

jumpserver

Jumpserver是全球首款完全开源的堡垒机,是符合 4A 的专业运维审计系统。

Language:JavaScriptLicense:GPL-2.0Stargazers:0Issues:1Issues:0

nps

一款轻量级、功能强大的内网穿透代理服务器。支持tcp、udp流量转发,支持内网http代理、内网socks5代理,同时支持snappy压缩、站点保护、加密传输、多路复用、header修改等。支持web图形化管理,集成多用户模式。

Language:GoLicense:GPL-3.0Stargazers:0Issues:0Issues:0

openrasp

🔥Open source RASP solution

Language:C++License:Apache-2.0Stargazers:0Issues:1Issues:0

owasp-modsecurity-crs

OWASP ModSecurity Core Rule Set (CRS) Project (Official Repository)

Language:PerlLicense:Apache-2.0Stargazers:0Issues:1Issues:0

PoCBox

PoCBox - 赏金猎人的脆弱性测试辅助平台(破300star写重构版本,400star免费线上版本开放【在线食用地址:由于经常被DDOS导致服务器资源恶意被占用 费用过大决定关闭服务 】,1000star开源重构全新版本!)

Language:JavaScriptStargazers:0Issues:1Issues:0

reverse-shell

Reverse Shell as a Service

Language:JavaScriptLicense:MITStargazers:0Issues:1Issues:0

seecode-scanner

SeeCode Scanner 扫描引擎

Language:PythonLicense:GPL-3.0Stargazers:0Issues:1Issues:0

shiro-550-with-NoCC

奇安信北京攻防团队: Shiro-550 不依赖CC链利用工具

License:GPL-3.0Stargazers:0Issues:0Issues:0

Sn1per

Automated pentest framework for offensive security experts

Language:ShellLicense:NOASSERTIONStargazers:0Issues:0Issues:0

SpringBootVulExploit

SpringBoot 相关漏洞学习资料,利用方法和技巧合集,黑盒安全评估 checklist

Language:JavaStargazers:0Issues:1Issues:0

taro

开放式跨端跨框架解决方案,支持使用 React/Vue/Nerv 等框架来开发微信/京东/百度/支付宝/字节跳动/ QQ 小程序/H5 等应用。 https://taro.jd.com/

Language:JavaScriptLicense:MITStargazers:0Issues:1Issues:0

TPscan

一键ThinkPHP漏洞检测

Language:PythonStargazers:0Issues:1Issues:0

wordpress-exploit-framework

A Ruby framework designed to aid in the penetration testing of WordPress systems.

Language:RubyLicense:GPL-3.0Stargazers:0Issues:1Issues:0

wpscan

WPScan is a free, for non-commercial use, black box WordPress Vulnerability Scanner written for security professionals and blog maintainers to test the security of their WordPress websites.

Language:RubyLicense:NOASSERTIONStargazers:0Issues:0Issues:0

xray-crack

xray社区高级版证书生成,仅供学习研究,正常使用请支持正版

Language:GoStargazers:0Issues:0Issues:0