Lists (1)
Sort Name ascending (A-Z)
Stars
⬆️ ☠️ 🔥 Automatic Linux privesc via exploitation of low-hanging fruit e.g. gtfobins, pwnkit, dirty pipe, +w docker.sock
一款适用于以HW行动/红队/渗透测试团队为场景的移动端(Android、iOS、WEB、H5、静态网站)信息收集扫描工具,可以帮助渗透测试工程师、攻击队成员、红队成员快速收集到移动端或者静态WEB站点中关键的资产信息并提供基本的信息输出,如:Title、Domain、CDN、指纹信息、状态信息等。
sqlmap Xplus 基于 sqlmap,对经典的数据库注入漏洞利用工具进行二开!
TInjA is a CLI tool for testing web pages for template injection vulnerabilities and supports 44 of the most relevant template engines for eight different programming languages.
The Template Injection Playground allows to test a large number of the most relevant template engines for template injection possibilities.
Differential testing framework for HTTP implementations
A python script to scan for Apache Tomcat server vulnerabilities.
APIDetector: Efficiently scan for exposed Swagger endpoints across web domains and subdomains. Supports HTTP/HTTPS, multi-threading, and flexible input/output options. Ideal for API security testing.
Cruzzer is a coverage-guided fuzzer combining a web application crawler.
API Security Project aims to present unique attack & defense methods in API Security field
This repository will contain many mindmaps for cyber security technologies, methodologies, courses, and certifications in a tree structure to give brief details about them
This repo is a PoC with to exploit CVE-2023-51467 and CVE-2023-49070 preauth RCE vulnerabilities found in Apache OFBiz.
A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.
This repository contain a lot of web and api vulnerability checklist , a lot of vulnerability ideas and tips from twitter
A collection of awesome penetration testing resources, tools and other shiny things
An awesome list of cybersecurity educational resources
Automated Penetration Testing Agentic Framework Powered by Large Language Models
Command-line program to download videos from YouTube.com and other video sites
Master the command line, in one page
😎 Awesome lists about all kinds of interesting topics
Outline Server, developed by Jigsaw. The Outline Server is a proxy server that runs a Shadowsocks instance and provides a REST API for access key management.
pagodo (Passive Google Dork) - Automate Google Hacking Database scraping and searching