Highlights
🥘 WebSec
shiro反序列化漏洞综合利用,包含(回显执行命令/注入内存马)修复原版中NoCC的问题 https://github.com/j1anFen/shiro_attack
An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.
专为CTF设计的Jinja2 SSTI全自动绕WAF脚本 | A Jinja2 SSTI cracker for bypassing WAF, designed for CTF
HaE - Highlighter and Extractor, Empower ethical hacker for efficient operations.
An integrated BurpSuite vulnerability detection plug-in.
Extract and decrypt browser data, supporting multiple data types, runnable on various operating systems (macOS, Windows, Linux).
A heapdump leaks Shiro key causing RCE vulnerability environment.
Deserialization payload generator for a variety of .NET formatters
Study Notes For Web Hacking / Web安全学习笔记
SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, se…
一个各种方式突破Disable_functions达到命令执行的shell
dddd是一款使用简单的批量信息收集,供应链漏洞探测工具,旨在优化红队工作流,减少伤肝的机械性操作。支持从Hunter、Fofa批量拉取目标