forlin's repositories

CVE-2018-2628

CVE-2018-2628

Language:PythonStargazers:20Issues:3Issues:0

xss_html_dom

HTML DOM事件对象下的XSS

CVE-2018-8174_EXP

CVE-2018-8174_python

Language:PythonStargazers:2Issues:2Issues:0

burpExtender

burp的漏洞检测插件扩展

Language:PythonStargazers:0Issues:2Issues:0

CNVD-C-2019-48814

WebLogic wls9-async反序列化远程命令执行漏洞

Language:PythonStargazers:0Issues:2Issues:0

CVE-2018-14729

Discuz backend getshell

Stargazers:0Issues:2Issues:0

CVE-2018-3191

CVE-2018-3191 payload generator

Stargazers:0Issues:2Issues:0

CVE-2018-9206

A Python PoC for CVE-2018-9206

Language:PythonStargazers:0Issues:2Issues:0

CVE-2019-11581

Atlassian JIRA Template injection vulnerability RCE

Stargazers:0Issues:1Issues:0
Language:PythonStargazers:0Issues:1Issues:0

easyXssPayload

XssPayload List . Usage:

Language:PythonStargazers:0Issues:2Issues:0

EventCleaner

A tool mainly to erase specified records from Windows event logs, with additional functionalities.

Language:C++Stargazers:0Issues:2Issues:0

fuzzDicts

Web Pentesting Fuzz 字典,一个就够了。

Language:PythonStargazers:0Issues:1Issues:0

HTTPHeadModifer

一款快速修改HTTP数据包头的Burp Suite插件

Language:JavaStargazers:0Issues:2Issues:0

insight

洞察-宜信集应用系统资产管理、漏洞全生命周期管理、安全知识库管理三位一体的平台。

Language:JavaScriptLicense:GPL-3.0Stargazers:0Issues:2Issues:0

Intranet_Penetration_Tips

2018年初整理的一些内网渗透TIPS,后面更新的慢,所以公开出来希望跟小伙伴们一起更新维护~

Stargazers:0Issues:1Issues:0

K8tools

K8工具合集(内网渗透/提权工具/远程溢出/漏洞利用/Exploit/APT/0day/Shellcode/Payload/priviledge/OverFlow/WebShell/PenTest)

Language:PowerShellStargazers:0Issues:2Issues:0

laravel-poc-CVE-2018-15133

PoC for CVE-2018-15133 (Laravel unserialize vulnerability)

Language:DockerfileStargazers:0Issues:2Issues:0

LaZagne

Credentials recovery project

Language:PythonLicense:LGPL-3.0Stargazers:0Issues:2Issues:0
Language:JavaScriptStargazers:0Issues:2Issues:0

NodeJS-Red-Team-Cheat-Sheet

NodeJS Red-Team Cheat Sheet

Stargazers:0Issues:2Issues:0

pentest

渗透测试用到的东东

Stargazers:0Issues:1Issues:0
Language:JavaStargazers:0Issues:2Issues:0

rdpy

Remote Desktop Protocol in Twisted Python

Language:PythonLicense:GPL-3.0Stargazers:0Issues:2Issues:0

redis-rogue-getshell

利用redis 4.x/5.x master/slave 模式getshell

Language:CLicense:Apache-2.0Stargazers:0Issues:1Issues:0

SecLists

SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more.

Language:PHPLicense:MITStargazers:0Issues:2Issues:0

sh00t

Security Testing is not as simple as right click > Scan. It's messy, a tough game. What if you had missed to test just that one thing and had to regret later? Sh00t is a highly customizable, intelligent platform that understands the life of bug hunters and emphasizes on manual security testing.

Language:JavaScriptLicense:MITStargazers:0Issues:2Issues:0

SSRFmap

Automatic SSRF fuzzer and exploitation tool

Language:PythonLicense:MITStargazers:0Issues:2Issues:0

vulhub

Docker-Compose file for vulnerability environment

Language:ShellLicense:GPL-3.0Stargazers:0Issues:2Issues:0

zimbra_poc

Zimbra XXE+SSRF+UPLOAD Poc

Language:PythonStargazers:0Issues:2Issues:0