yaoxiaodai's starred repositories

notable

The Markdown-based note-taking app that doesn't suck.

nishang

Nishang - Offensive PowerShell for red team, penetration testing and offensive security.

Language:PowerShellLicense:NOASSERTIONStargazers:8773Issues:397Issues:59

Behinder

“冰蝎”动态二进制加密网站管理客户端

Cobra

Source Code Security Audit (源代码安全审计)

Language:PythonLicense:MITStargazers:3147Issues:156Issues:980

JSFinder

JSFinder is a tool for quickly extracting URLs and subdomains from JS files on a website.

JavaThings

Share Things Related to Java - Java安全漫谈笔记相关内容

fofa_viewer

A simple FOFA client written in JavaFX. Made by WgpSec, Maintained by f1ashine.

Language:JavaLicense:MITStargazers:1584Issues:20Issues:145

bylibrary

白阁文库是白泽Sec安全团队维护的一个漏洞POC和EXP公开项目

FastjsonExploit

Fastjson vulnerability quickly exploits the framework(fastjson漏洞快速利用框架)

SharpDecryptPwd

对密码已保存在 Windwos 系统上的部分程序进行解析,包括:Navicat,TeamViewer,FileZilla,WinSCP,Xmangager系列产品(Xshell,Xftp)。源码:https://github.com/RowTeam/SharpDecryptPwd

thinkphp-RCE-POC-Collection

thinkphp v5.x 远程代码执行漏洞-POC集合

Decrypt_Weblogic_Password

搜集了市面上绝大部分weblogic解密方式,整理了7种解密weblogic的方法及响应工具。

sec-admin

分布式资产安全扫描核心管理系统(弱口令扫描,漏洞扫描)

Language:PythonLicense:GPL-3.0Stargazers:600Issues:5Issues:21

Adinfo

域信息收集工具

cve-2019-1003000-jenkins-rce-poc

Jenkins RCE Proof-of-Concept: SECURITY-1266 / CVE-2019-1003000 (Script Security), CVE-2019-1003001 (Pipeline: Groovy), CVE-2019-1003002 (Pipeline: Declarative)

Language:JavaScriptLicense:MITStargazers:310Issues:4Issues:4

InjectJDBC

注入JVM进程 动态获取目标进程连接的数据库

PassList

👍 Awesome password to hack

CVE-2021-22205

CVE-2021-22205& GitLab CE/EE RCE

ysoserial

A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.优化了一些东西。

Language:JavaLicense:MITStargazers:214Issues:9Issues:0

WSPIH

Website Sensitive Personal Information Hunter 网站个人敏感信息文件扫描器

Language:PythonLicense:MITStargazers:205Issues:6Issues:0

dnstunnel

dns tunnel backdoor DNS隧道后门

MatryoshkaDollTool

MatryoshkaDollTool-程序加壳/捆绑工具

Language:PythonStargazers:148Issues:4Issues:0

F-Scrack

一款python编写的轻量级弱口令检测脚本,目前支持以下服务:FTP、MYSQL、MSSQL、MONGODB、REDIS、TELNET、ELASTICSEARCH、POSTGRESQL。

Language:PythonLicense:GPL-3.0Stargazers:137Issues:4Issues:0

heartbleed-PoC

:broken_heart: Hearbleed exploit to retrieve sensitive information CVE-2014-0160 :broken_heart:

tencent_exmail

获取腾讯企业邮箱通讯录

spring-boot-actuator-cloud-vul

Spring Boot Actuator + Spring Cloud Vul Env

Language:JavaStargazers:19Issues:2Issues:0

dingtalk_webhook

CobaltStrike上线之钉钉提醒

Stargazers:1Issues:0Issues:0