0neatsec Goto Github PK
Name: 0ne
Type: User
Bio: Ctrl C+V coder
Name: 0ne
Type: User
Bio: Ctrl C+V coder
各种CMS、各种平台、各种系统、各种软件漏洞的EXP、POC 该项目将不断更新
2021 hw
403/401 Bypass Methods + Bash Automation + Your Support ;)
404StarLink Project 2.0 - 推荐真正优质、有意义、有趣、坚持维护的开源项目
对安卓APP注入MSF PAYLOAD,并且对手机管家进行BYPASS。
把msf生成的安卓远控附加进普通的app中,并进行加固隐藏特征。可以绕过常见的手机安全管家。
一个旨在通过应用场景 / 标签对 Github 红队向工具 / 资源进行分类收集,降低红队技术门槛的手册【持续更新】
用于渗透测试和红队基础设施建设的 payload 和 bypass 字典。A list of payload and bypass lists for penetration and red team infrastructure build.
个人域渗透学习笔记
一款用于攻击spring boot actuator的集成环境,目前集成三种攻击方式,支持1.x、2.x
A tool to escalate privileges in an active directory network by coercing authenticate from machine accounts and relaying to the certificate service.
official repo for the AdHuntTool (part of the old RedTeamCSharpScripts repo)
AK利用工具,AccessKey AccessKeySecret,利用AK获取资源信息和操作资源,ECS/CVM操作,OSS/COS管理,RDS管理,域名管理,添加RAM账号等
阿里云AccessKey泄漏利用工具
**蚁剑是一款跨平台的开源网站管理工具。AntSword is a cross-platform website management toolkit.
一款适用于以HW行动/红队/渗透测试团队为场景的移动端(Android、iOS、WEB、H5、静态网站)信息收集扫描工具,可以帮助渗透测试工程师、攻击队成员、红队成员快速收集到移动端或者静态WEB站点中关键的资产信息并提供基本的信息输出,如:Title、Domain、CDN、指纹信息、状态信息等。
A simple ARP spoofer for Windows
本软件首先集成危害性较大框架和部分主流cms的rce(无需登录,或者登录绕过执行rce)和反序列化(利用链简单)。上传getshell。sql注入等高危漏洞直接就可以拿权限出数据。其次对一些构造复杂exp漏洞进行检测。傻瓜式导入url即可实现批量测试,能一键getshell检测绝不sql注入或者不是只检测。其中thinkphp 集成所有rce Exp Struts2漏洞集成了shack2 和k8 漏洞利用工具所有Exp并对他们的exp进行优化和修复此工具的所集成漏洞全部是基于平时实战中所得到的经验从而写入到工具里。例如:通达oA一键getshell实战测试 struts2一键getshell 等等
TimelineSec ATT&CK 工具库
记录自己对《代码审计》的理解和总结,对危险函数的深入分析以及在p牛的博客和代码审计圈的收获
掩日 - 免杀执行器生成工具
Defences against Cobalt Strike
本仓库展示一些事物的本质、原理、奇奇怪怪的和安全相关的东西。可能有些形式科学(如数学), 研究抽象概念; 自然科学(如生物学、物理学、医学), 在最宽泛的意义上研究自然; 以及社会科学(如经济学、心理学、社会学), 研究个体与社会.
A collection of various awesome lists for hackers, pentesters and security researchers
AntSword 自定义编(解)码器分享
AntSword Shell 脚本分享/示例
“冰蝎”动态二进制加密网站管理客户端
爆破字典
A declarative, efficient, and flexible JavaScript library for building user interfaces.
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
An Open Source Machine Learning Framework for Everyone
The Web framework for perfectionists with deadlines.
A PHP framework for web artisans
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
Some thing interesting about web. New door for the world.
A server is a program made to process requests and deliver data to clients.
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
Some thing interesting about visualization, use data art
Some thing interesting about game, make everyone happy.
We are working to build community through open source technology. NB: members must have two-factor auth.
Open source projects and samples from Microsoft.
Google ❤️ Open Source for everyone.
Alibaba Open Source for everyone
Data-Driven Documents codes.
China tencent open source team.