zzhsec Goto Github PK
Type: User
Bio: 大道至简,知行合一
Blog: https://www.zzhsec.com/
Type: User
Bio: 大道至简,知行合一
Blog: https://www.zzhsec.com/
《互联网企业安全高级指南》思维脑图
各种CMS、各种平台、各种系统、各种软件漏洞的EXP、POC ,该项目将持续更新
新版零组资料文库离线漏洞名搜索,功能:更新 、查询 (不包含漏洞详情)
[windows]pe -> shellcode -> shellcodeLoader -> (pe2shellcode go on?)
100-Days-of-Hacking
功能齐全的Web指纹识别和分享平台,基于vue3+django前后端分离的web架构,并集成了长亭出品的rad爬虫的功能,内置了一万多条互联网开源的指纹信息。
2021hvv漏洞汇总
2022 护网行动 POC 整理
Get a job from Xuanwu Lab in 365 days
365-Stealer is the tool written in python3 which steals data from victims office365 by using access_token which we get by phishing. It steals outlook mails, attachments, OneDrive files, OneNote notes and injects macros.
Automation Recon tool which works with Large & Medium scopes. It performs more than 20 tasks and gets back all the results in separated files.
403/401 Bypass Methods + Bash Automation + Your Support ;)
针对 403 页面的 fuzz 脚本
把msf生成的安卓远控附加进普通的app中,并进行加固隐藏特征。可以绕过常见的手机安全管家。
对安卓APP注入MSF PAYLOAD,并且对手机管家进行BYPASS。
基于前端vue框架的JavaFx图形化GUI漏洞扫描工具,支持一键扫描vue-manage-system系统前端泄露的未授权目录接口漏洞,并且对扫描的暴露目录进行逐一测试和验证,方便渗透人员快速确定未授权接口。还添加了出口IP地址信息本地DNS信息等的查询,方便清楚自身出口IP。
自研JavaFX图形化漏洞扫描工具,支持ThinkPHP 2.x RCE,Thinkphp5 5.0.22/5.1.29RCE,ThinkPHP5 5.0.23RCE和ThinkPHP5 SQL注入漏洞和敏感信息泄露漏洞的漏洞检测,以及命令执行的功能。漏洞POC基本适用ThinkPHP全版本漏洞。
一个旨在通过应用场景 / 标签对 Github 红队向工具 / 资源进行分类收集,降低红队技术门槛的手册【持续更新】
Everything for pentest. | 用于渗透测试的 payload 和 bypass 字典.
使用Golang批量分析Java的class文件以辅助挖洞
A compilation of network scanning strategies to find vulnerable devices
小型主动防御引擎
Retrieve AD accounts description and search for password in it
一个收集优秀攻防工具的项目,集百家之所长,融百家之所思,扬百家之所名
A cheat sheet that contains advanced queries for SQL Injection of all types.
a burp extension for dynamic payload generation to detect injection flaws (RCE, LFI, SQLi), creates access matrix based user sessions to spot authentication/authorization issues, and converts Http requests to Javascript for further XSS exploitation and more.
aggressor-script 中文翻译 aggressor-script 使用
A declarative, efficient, and flexible JavaScript library for building user interfaces.
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
An Open Source Machine Learning Framework for Everyone
The Web framework for perfectionists with deadlines.
A PHP framework for web artisans
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
Some thing interesting about web. New door for the world.
A server is a program made to process requests and deliver data to clients.
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
Some thing interesting about visualization, use data art
Some thing interesting about game, make everyone happy.
We are working to build community through open source technology. NB: members must have two-factor auth.
Open source projects and samples from Microsoft.
Google ❤️ Open Source for everyone.
Alibaba Open Source for everyone
Data-Driven Documents codes.
China tencent open source team.