5up3rc Goto Github PK
Name: Cy95
Type: User
Bio: Programmer,Security Go,PHP,Python
Location: Xiamen,China
Blog: https://blog.webvul.me
Name: Cy95
Type: User
Bio: Programmer,Security Go,PHP,Python
Location: Xiamen,China
Blog: https://blog.webvul.me
Fast subdomains enumeration tool for penetration testers
A Powerful Subdomain Takeover Tool
External pentest tool that performs subdomain enumeration through various techniques. In addition, SubScraper will provide information such as HTTP & DNS lookups to aid in potential next steps.
[Linux] Two Privilege Escalation techniques abusing sudo token
A tool to identify and exploit sudo rules' misconfigurations and vulnerabilities within sudo
Example of hooking a linux systemcall
超级SQL注入工具 简介: 超级SQL注入工具(SSQLInjection)是一款基于HTTP协议自组包的SQL注入工具,采用C#开发,程序采用自写代码来操作HTTP交互,支持出现在HTTP协议任意位置的SQL注入,支持各种类型的SQL注入,支持HTTPS模式注入;支持以盲注、错误显示、Union注入等方式来获取数据;支持Access/MySQL/SQLServer/Oracle等数据库;支持手动灵活的进行SQL注入绕过,可自定义进行字符替换等绕过注入防护。本工具为渗透测试人员、信息安全工程师等掌握SQL注入技能的人员设计,需要使用人员对SQL注入有一定了解。 工具特点: 1.支持任意地点出现的任意SQL注入 2.支持全自动识别注入标记,也可人工识别注入并标记。 3.支持各种语言环境。大多数注入工具在盲注下,无法获取中文等多字节编码字符内容,本工具可完美解决。 4.支持注入数据发包记录。让你了解程序是如何注入,有助于快速学习和找出注入问题。 5.依靠关键字/时间等进行盲注,可通过HTTP相应状态码判断,还可以通过关键字取反功能,反过来取关键字。 6.程序采用自编码操作HTTP请求,HTTP发包和获取速度较快。
微信电脑客户端多开工具,支持防消息撤销
Suricata git repository maintained by the OISF
平时抓包写的suricata规则,会慢慢更新
A REST API security testing framework.
An example rootkit that gives a root shell
An LKM rootkit targeting Linux 2.6/3.x on x86(_64), and ARM
simple script to extract all web resources by means of .SVN folder exposed over network.
用于扫描git,svn泄露
svn>1.7时,dump源码工具
swap_digger is a tool used to automate Linux swap analysis during post-exploitation or forensics. It automates swap extraction and searches for Linux user credentials, web forms credentials, web forms emails, http basic authentication, Wifi SSID and keys, etc.
端口复用工具,能让HTTP/HTTPS/SSH/RDP/SOCKS5/HTTPProxy/Other跑在同一个端口上,支持复用本地或远程端口
结合swoole扩展和Yaf框架,使用swoole的内置http_server
Automatic Discrepancy Discovery for DPI Elusion
A tcp syn flood attack tool
A TCP SYN flood client written in Rust, powered by libpnet
Just a proof of concept Linux rootkit that reads from syscalls.
The system call intercepting library
Golang - 获取Windows & Linux登录日志并正则解析
Sysmon configuration file template with default high-quality event tracing
A repository of sysmon configuration modules
a monitor for getting machine system info alarming
A declarative, efficient, and flexible JavaScript library for building user interfaces.
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
An Open Source Machine Learning Framework for Everyone
The Web framework for perfectionists with deadlines.
A PHP framework for web artisans
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
Some thing interesting about web. New door for the world.
A server is a program made to process requests and deliver data to clients.
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
Some thing interesting about visualization, use data art
Some thing interesting about game, make everyone happy.
We are working to build community through open source technology. NB: members must have two-factor auth.
Open source projects and samples from Microsoft.
Google ❤️ Open Source for everyone.
Alibaba Open Source for everyone
Data-Driven Documents codes.
China tencent open source team.