ShenMingF's starred repositories

PerlinPuzzle-Webshell-PHP

使用分支对抗技术制作的PHP Webshell,截止2024年1月18日,共数十个查杀引擎免杀

Language:PHPLicense:MITStargazers:246Issues:0Issues:0

BurpAPIFinder

攻防演练过程中,我们通常会用浏览器访问一些资产,但很多未授权/敏感信息/越权隐匿在已访问接口过html、JS文件等,该插件能让我们发现未授权/敏感信息/越权/登陆接口等。

Language:JavaStargazers:659Issues:0Issues:0

jjjjjjjjjjjjjs

爬网站JS文件,自动fuzz api接口,指定api接口(针对前后端分离项目,可指定后端接口地址),回显api响应

Language:PythonLicense:MITStargazers:535Issues:0Issues:0
Stargazers:80Issues:0Issues:0

SigThief

Stealing Signatures and Making One Invalid Signature at a Time

Language:PythonLicense:BSD-3-ClauseStargazers:2031Issues:0Issues:0

WeaverExploit_All

泛微最近的漏洞利用工具(PS:2023)

Language:GoStargazers:439Issues:0Issues:0

PRET

Printer Exploitation Toolkit - The tool that made dumpster diving obsolete.

Language:PythonLicense:GPL-2.0Stargazers:3816Issues:0Issues:0

IOXIDResolver

IOXIDResolver.py from AirBus Security

Language:PythonLicense:BSD-3-ClauseStargazers:208Issues:0Issues:0

Template

Next generation RedTeam heuristic intranet scanning | 下一代RedTeam启发式内网扫描

Stargazers:1031Issues:0Issues:0

zookeeper

Apache ZooKeeper

License:Apache-2.0Stargazers:12Issues:0Issues:0

EHole

EHole(棱洞)3.0 重构版-红队重点攻击系统指纹探测工具

Language:GoLicense:Apache-2.0Stargazers:3005Issues:0Issues:0

ImageMagick

🧙‍♂️ ImageMagick 7

Language:CLicense:NOASSERTIONStargazers:11608Issues:0Issues:0

xpoc

为供应链漏洞扫描设计的快速应急响应工具 [快速应急] [漏洞扫描] [端口扫描] [xray2.0进行时] A fast emergency response tool designed for supply chain vulnerability scanning.

License:NOASSERTIONStargazers:917Issues:0Issues:0

xray

一款完善的安全评估工具,支持常见 web 安全问题扫描和自定义 poc | 使用之前务必先阅读文档

Language:VueLicense:NOASSERTIONStargazers:9999Issues:0Issues:0
Language:VueStargazers:10Issues:0Issues:0
Language:GoStargazers:12Issues:0Issues:0
Language:PythonStargazers:554Issues:0Issues:0

CTFCrackTools

China's first CTFTools framework.**国内首个CTF工具框架,旨在帮助CTFer快速攻克难关

Language:JavaLicense:GPL-3.0Stargazers:1814Issues:0Issues:0

DaE

CTFCrackTools 's BurpSuite Plugin - Decode and Encode

Language:JavaLicense:GPL-3.0Stargazers:79Issues:0Issues:0

ApoalypseSecTools

ApoalypseSecTool更新地址

Stargazers:22Issues:0Issues:0

SpringBootScan

扫描网站是否存在SpringBoot API信息泄漏或阿里云存储OSSKEY泄漏

Language:PythonStargazers:18Issues:0Issues:0

Frog-Auth

🐸Unauthorized Detection Framework未授权访问检测框架

Language:PythonStargazers:157Issues:0Issues:0

skyscorpion

新版将不再对外公开发布。天蝎权限管理工具采用Java平台的JavaFX技术开发的桌面客户端,支持跨平台运行,目前基于JDK1.8开发,运行必须安装JDK或JRE 1.8,注意不能是open jdk,只能是oracle的jdk。 天蝎权限管理工具基于冰蝎加密流量进行WebShell通信管理的原理,目前实现了jsp、aspx、php、asp端的常用操作功能,在原基础上,优化了大文件上传下载、Socket代理的问题,修改了部分API接口代码。

Stargazers:355Issues:0Issues:0
Language:PythonStargazers:5Issues:0Issues:0

go-shellcode

Load shellcode into a new process

Language:GoStargazers:757Issues:0Issues:0

linwin-sploit

LinwinSploit is a Penetration testing toolkit for Linux and android Termux. LinwinSploit是一款用于Linux和安卓Termux的渗透测试工具。 It can attack and run trojan virus on target host. 它能够攻击并在目标主机上运行木马。 Use these toolkits carefully. If you don't allow this, you may have a lot of terrible. 用这些工具使的时候小心点,如果你不遵守这条,你可能会有一些麻烦

Language:JavaLicense:GPL-3.0Stargazers:34Issues:0Issues:0

Killer

Killer tool is designed to bypass AV/EDR security tools using various evasive techniques.

Language:C++Stargazers:683Issues:0Issues:0
Language:C#License:Apache-2.0Stargazers:1673Issues:0Issues:0

WeblogicExploit-GUI

Weblogic漏洞利用图形化工具 支持注入内存马、一键上传webshell、命令执行

Stargazers:687Issues:0Issues:0

x64dbg-Plugin-Manager

Plugin manager for x64dbg

Language:C++License:MITStargazers:768Issues:0Issues:0