yangxiaodi's starred repositories

sqlmap

Automatic SQL injection and database takeover tool

Language:PythonLicense:NOASSERTIONStargazers:31395Issues:1092Issues:5196

jumpserver

An open-source PAM tool alternative to CyberArk. 广受欢迎的开源堡垒机。

Language:PythonLicense:GPL-3.0Stargazers:24691Issues:661Issues:6429

Mobile-Security-Framework-MobSF

Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.

Language:JavaScriptLicense:GPL-3.0Stargazers:16765Issues:573Issues:1469

aiohttp

Asynchronous HTTP client/server framework for asyncio and Python

Language:PythonLicense:NOASSERTIONStargazers:14815Issues:219Issues:2917

requests-html

Pythonic HTML Parsing for Humans™

Language:PythonLicense:MITStargazers:13653Issues:271Issues:407

subfinder

Fast passive subdomain enumeration tool.

browserless

Deploy headless browsers in Docker. Run on our cloud or bring your own. Free for non-commercial uses.

Language:TypeScriptLicense:NOASSERTIONStargazers:8176Issues:64Issues:517

Scanners-Box

A powerful and open-source toolkit for hackers and security automation - 安全行业从业者自研开源扫描器合辑

aquatone

A Tool for Domain Flyovers

Language:GoLicense:MITStargazers:5561Issues:135Issues:0

commix

Automated All-in-One OS Command Injection Exploitation Tool.

Language:PythonLicense:NOASSERTIONStargazers:4421Issues:161Issues:894

subDomainsBrute

A fast sub domain brute tool for pentesters

Some-PoC-oR-ExP

各种漏洞poc、Exp的收集或编写

Language:PythonStargazers:2351Issues:156Issues:0

SSRF-Testing

SSRF (Server Side Request Forgery) testing resources

xsshunter

The XSS Hunter service - a portable version of XSSHunter.com

Language:JavaScriptLicense:MITStargazers:1452Issues:48Issues:21

pbtk

A toolset for reverse engineering and fuzzing Protobuf-based apps

Language:PythonLicense:GPL-3.0Stargazers:1360Issues:41Issues:26

ESD

Enumeration sub domains(枚举子域名)

Language:PythonLicense:GPL-3.0Stargazers:1055Issues:26Issues:61

PasswordDic

2011-2019年Top100弱口令密码字典 Top1000密码字典 服务器SSH/VPS密码字典 后台管理密码字典 数据库密码字典 子域名字典

bugcrowd-levelup-subdomain-enumeration

This repository contains all the material from the talk "Esoteric sub-domain enumeration techniques" given at Bugcrowd LevelUp 2017 virtual conference

freddy

Automatically identify deserialisation issues in Java and .NET applications by using active and passive scans

Language:JavaLicense:AGPL-3.0Stargazers:573Issues:30Issues:18

Paper

Web Security Technology & Vulnerability Analysis Whitepapers

JavaID

java source code static code analysis and danger function identify prog

shelling

SHELLING - a comprehensive OS command injection payload generator

xssless

An automated XSS payload generator written in python.

Language:PythonLicense:GPL-2.0Stargazers:312Issues:21Issues:1

MyBlog

记录和分享学习的旅程!

dnsAutoRebinding

ssrf、ssrfIntranetFuzz、dnsRebinding、recordEncode、dnsPoisoning、Support ipv4/ipv6

Language:PythonLicense:GPL-3.0Stargazers:217Issues:6Issues:1

GitLeak

GitLeak 是一个从 Github 上查找密码信息的小工具

Language:JavaScriptLicense:MITStargazers:133Issues:4Issues:2

dnstricker

A simple dns resolver of dns-record and web-record log server for pentesting

Language:JavaScriptStargazers:133Issues:9Issues:0

ImageTragick_Poc

ImageTragick_Poc

Language:ShellStargazers:5Issues:3Issues:0
Language:JavaScriptStargazers:2Issues:0Issues:0