Skip to content
View zz1900's full-sized avatar

Block or report zz1900

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

上传漏洞fuzz字典生成脚本

Python 1,277 250 Updated Apr 1, 2021

Information Security (Web Security/Penetration Testing Direction) Interview Questions/Solutions 信息安全(Web安全/渗透测试方向)面试题/解题思路

479 100 Updated Jul 25, 2019

绕过CDN查找网站的真实IP地址

Python 214 33 Updated Nov 22, 2022

EHole(棱洞)魔改。可对路径进行指纹识别;支持识别出来的重点资产进行漏洞检测(支持从hunter和fofa中提取资产)支持对ftp服务识别及爆破

Go 965 62 Updated Mar 6, 2024

In-depth attack surface mapping and asset discovery

Go 14,746 2,138 Updated Apr 17, 2026

Tips and Tutorials for Bug Bounty and also Penetration Tests.

2,075 448 Updated Oct 7, 2025

This repository contain a lot of web and api vulnerability checklist , a lot of vulnerability ideas and tips from twitter

3,553 832 Updated Feb 10, 2024

CaA - Collector and Analyzer, Insight into information, exploring with intelligence in a thousand ways. 信息洞察,智探千方!

Java 1,501 83 Updated May 25, 2026

HaE - Highlighter and Extractor, Empower ethical hacker for efficient operations. 赋能白帽,高效作战!

Java 4,219 308 Updated Jun 9, 2026

OneScan 是一款用于递归目录扫描的 BurpSuite 插件

Java 1,249 77 Updated Jun 24, 2025

AWS云平台 AccessKey 泄漏利用工具

Python 396 47 Updated Jul 18, 2023

高性能 HTTP 正向代理工具 | A high-performance http tunneling tool

Go 2,743 255 Updated Feb 2, 2026

Godzilla插件|内存马|Suo5内存代理|jmg for Godzilla

244 8 Updated Jun 6, 2024

一款支持自定义的 Java 内存马生成工具|A customizable Java in-memory webshell generation tool.

Java 2,212 231 Updated Aug 21, 2025

恶意代码逃逸源代码 http://payloads.online

C++ 757 126 Updated Mar 7, 2022

从零开始学免杀

439 53 Updated Mar 30, 2022

奇安信 Hunter SDK

Python 5 Updated Jan 21, 2022

一款基于各大企业信息API的工具,解决在遇到的各种针对国内企业信息收集难题。一键收集控股公司ICP备案、APP、小程序、微信公众号等信息聚合导出。支持MCP接入

Go 4,463 426 Updated Mar 30, 2026

Vulmap 是一款 web 漏洞扫描和验证工具, 可对 webapps 进行漏洞扫描, 并且具备漏洞验证功能

Python 3,524 573 Updated Apr 26, 2023

Exphub[漏洞利用脚本库] 包括Webloigc、Struts2、Tomcat、Nexus、Solr、Jboss、Drupal的漏洞利用脚本,最新添加CVE-2020-14882、CVE-2020-11444、CVE-2020-10204、CVE-2020-10199、CVE-2020-1938、CVE-2020-2551、CVE-2020-2555、CVE-2020-2883、CVE-…

Python 4,279 1,082 Updated Apr 4, 2021

APIKit:Discovery, Scan and Audit APIs Toolkit All In One.

Java 2,270 181 Updated Apr 2, 2024

Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application security people work and allow them perform an automa…

Python 1,161 253 Updated Mar 21, 2026

Python ProxyPool for web spider

Python 23,424 5,389 Updated Jun 15, 2026

信息收集自动化工具

Python 4,014 591 Updated Jun 13, 2024

信息收集自动化工具

Python 1 Updated Jan 5, 2022

404StarLink - 推荐优质、有意义、有趣、坚持维护的安全开源项目

10,750 943 Updated Mar 11, 2026

大宝剑-边界资产梳理工具(红队、蓝队、企业组织架构、子域名、Web资产梳理、Web指纹识别、ICON_Hash资产匹配)

Python 924 142 Updated Feb 8, 2022

一款甲方资产巡航扫描系统。系统定位是发现资产,进行端口爆破。帮助企业更快发现弱口令问题。主要功能包括: 资产探测、端口爆破、定时任务、管理后台识别、报表展示

Go 1,835 309 Updated Apr 19, 2022

reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines, recon data correlation and organization, continuous …

HTML 8,701 1,330 Updated Mar 21, 2026

Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the …

Go 29,304 3,501 Updated Jun 22, 2026
Next