Skip to content
View rabbitsafe's full-sized avatar

Block or report rabbitsafe

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
35 results for forked starred repositories
Clear filter

FofaMap是一款基于Python3开发的跨平台FOFA API数据采集器,支持普通查询、网站存活检测、统计聚合查询、Host聚合查询、网站图标查询、批量查询等查询功能。同时FofaMap还能够自定义查询FOFA数据,并根据查询结果自动去重和筛选关键字,生成对应的Excel表格。另外春节特别版还可以调用Nuclei对FofaMap查询出来的目标进行漏洞扫描,让你在挖洞路上快人一步。

Python 17 2 Updated Oct 26, 2025

各种CMS、各种平台、各种系统、各种软件漏洞的EXP、POC 该项目将不断更新

C 9 1 Updated Mar 30, 2022

2022 护网行动 POC 整理

Go 3 2 Updated Aug 2, 2022

分支出了些问题,无法合并到main,迁移至https://github.com/hktalent/scan4all

Go 17 2 Updated Dec 18, 2023

一个用于隐藏C2的、开箱即用的反向代理服务器。旨在省去繁琐的配置Nginx服务的过程。

Go 81 12 Updated Feb 14, 2022

This is a dockerized application that is vulnerable to the Spring4Shell vulnerability (CVE-2022-22965).

Python 107 76 Updated Aug 4, 2022

批量发送钓鱼邮箱

Java 1 1 Updated Jul 26, 2021

在线cms识别|旁站|c段|信息泄露|工控|系统|物联网安全|cms漏洞扫描|nmap端口扫描|子域名获取|待续..

Python 10 5 Updated Apr 23, 2019

用于记录分享一些有趣的案例

1 Updated Oct 23, 2020

此项目用来提取收集以往泄露的密码中符合条件的强弱密码

Python 18 18 Updated Apr 1, 2019

参数 | 字典 collections

Python 2 2 Updated Aug 4, 2021

爆破字典

Python 20 15 Updated Nov 15, 2017
Python 1 Updated Sep 22, 2018

A list of interesting payloads, tips and tricks for bug bounty hunters.

2 2 Updated Oct 22, 2018

上传漏洞fuzz字典生成脚本

Python 1 1 Updated Nov 6, 2018

Misc dictionaries for directory/file enumeration, username enumeration, password dictionary/bruteforce attacks

7 5 Updated Dec 1, 2018

SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, se…

PHP 2 3 Updated Dec 11, 2018

弱口令,敏感目录,敏感文件等渗透测试常用攻击字典

6 6 Updated Jan 10, 2019

Send output from subjs to LinkFinder

Shell 7 2 Updated Feb 6, 2019

Ghazi is a BurpSuite Plugins For Testing various PayLoads Like "XSS,SQLi,SSTI,SSRF,RCE and LFI" through Different tabs , Where Each Tab Will Replace Every GET or POST Parameters With Selected TAB i…

Java 1 1 Updated Feb 11, 2019

"Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.

1 Updated Mar 2, 2019

这是一个用于IP和域名碰撞匹配访问的小工具,旨意用来匹配出渗透过程中需要绑定hosts才能访问的弱主机或内部系统。

Python 3 1 Updated Apr 30, 2019

一个fuzzdb扩展库

HTML 1 2 Updated May 1, 2019

List of Awesome Asset Discovery Resources

5 1 Updated Jun 5, 2019

Burp Bounty (Scan Check Builder in BApp Store) is a extension of Burp Suite that allows you, in a quick and simple way, to improve the active and passive scanner by means of personalized rules thro…

Java 2 Updated Jun 12, 2019

This is a webshell open source project

PHP 1 1 Updated Jun 22, 2019

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Python 3 3 Updated Jul 14, 2019

Take a list of domains and probe for working HTTP and HTTPS servers

Go 2 Updated Jul 26, 2019

Generates permutations, alterations and mutations of subdomains and then resolves them

Python 1 Updated Jul 29, 2019
Next