python安全和代码审计相关资料收集 resource collection of python security and code review
各种安全大会PPT PDF
A burp extension that add some useful function to Context Menu 添加一些右键菜单让burp用起来更顺畅
A Domain Name & Email Address Collection Tool
domain_hunter的高级版本,SRC挖洞、HW打点之必备!自动化资产收集;快速Title获取;外部工具联动;等等
reCAPTCHA = REcognize CAPTCHA: A Burp Suite Extender that recognize CAPTCHA and use for intruder payload 自动识别图形验证码并用于burp intruder爆破模块的插件
A Burp Suite Extension that try to find all sub-domain, similar-domain and related-domain of an organization automatically! 基于流量自动收集整个企业或组织的子域名、相似域名、相关域名的burp插件
可以自定义规则的密码字典生成器,支持图形界面 A password-generator that base on the rules that you specified
burp插件开发指南
xmind\code\articles for my personal blog 个人博客上的资源备份存储,也是个人分享的汇总
Unicode To Chinese -- U2C : A burpsuite Extender That Convert Unicode To Chinese 【Unicode编码转中文的burp插件】
Java 反序列化学习的实验代码 Java_deserialize_vuln_lab
A burp extender that recalculate signature value automatically after you modified request parameter value.
Burp Suite Collaborator HTTP API
DNSLog 是一款监控 DNS 解析记录和 HTTP 访问记录的工具。
Burp_Extender_para_encrypter
a Burp Extender that add an random X-Forward-For IP address for each request
common methods that used by my burp extension projects
解答开发关于安全漏洞的常见问题
数据提取和处理工具
save burp traffic to redis 将burp的流量保存到redis
Add Scan Task To WVS
theHarvester that change from https://github.com/laramies/theHarvester. add proxy option to cross GFW
To Find Possibe ID Card Number
准确率99.9%的ip地址定位库,0.0x毫秒级查询,数据库文件大小只有1.5M,提供了java,php,c,python,nodejs,golang,c#查询绑定和Binary,B树,内存三种查询算法,妈妈再也不用担心我的ip地址定位!
WSDL Parser extension for Burp
A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.
XSS平台 CTF工具 Web安全工具
To Recalculate sign in http request
一个帮你总结所有类型的上传漏洞的靶场
HTTP Basic Auth Bruter
整理收集Struts2漏洞环境
Cknife
The Leading Security Assessment Framework for Android.
巡风是一款适用于企业内网的漏洞快速应急,巡航扫描系统。
JWT brute force cracker written in C
A free, powerful, multi-purpose tool that helps you monitor system resources, debug software and detect malware.
poc from bugscan beebeeto
To Load Github Scripts From Xmind Index
Java常见通用漏洞和修复的代码以及利用payload
DNS-Discovery is a multithreaded subdomain bruteforcer.
wooyun_all_bugs
A byte code analyzer for finding deserialization gadget chains in Java applications
一个包含php,java,python,C#等各种语言版本的XXE漏洞Demo
Simple reverse ICMP shell
GitHub 泄露监控系统
解密好的AWVS10.5 data/script/目录下的脚本
NSA finest tool
A framework used for Vulnerability scanning
Exploit code for CVE-2014-7920 and CVE-2014-7921 - code-exec in mediaserver up to Android 5.1
Fast subdomains enumeration tool for penetration testers
被动式漏洞扫描系统
Manage your website via terminal
SQLI labs to test error based, Blind boolean based, Time based.
Fast and customizable vulnerability scanner based on simple YAML based DSL.
Community curated list of templates for the nuclei engine to find security vulnerabilities.
基于frida的安卓hook框架,提供了很多frida自身不支持的功能,将hook安卓变成简单便捷,人人都会的事情
Hackhttp is an HTTP library, written in Python.
Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application security people work and allow them perform an automatic authorization tests
Shiro550/Shiro721 一键化利用工具,支持多种回显方式
Decode Fortify Rule Bin File Get XML File
无状态子域名爆破工具
Behinder source code
FuzzDomain
My LCX, PortMaper. used in Windows,Linux,Android,Mac
EW重构计划
EarthWorm/Termite 停止更新
A python script that finds endpoints in JavaScript files
Exported from https://code.google.com/archive/p/hookme/
a open source remote administrator tool
java source code static code analysis and danger function identify prog
ShadowsocksR update rss, SSR organization
A PoC Java Stager which can download, compile, and execute a Java file in memory.
A static byte code analyzer for Java deserialization gadget research
SoapUI pro 破解 你懂的
The Shadow Brokers "Lost In Translation" leak
Simple socket-based gateway to the Burp Collaborator
A python reverse shell that uses DNS as the c2 channel
webshell writen in python
Archive of leaked Equation Group materials
SignEveryDay
基于http代理的web漏洞扫描器的实现
Decrypted content of odd.tar.xz.gpg, swift.tar.xz.gpg and windows.tar.xz.gpg
SRCMS企业应急响应与缺陷管理系统
A `.git` folder disclosure exploit
Switch hosts quickly!
The official Exploit Database repository
编程语言 | 排名 | 好于 | 星星数 |
---|---|---|---|
Ruby | 14 | 99.92% | 825 |
Java | 213 | 99.77% | 3292 |
Python | 242 | 99.73% | 1355 |
PHP | 2878 | 88.49% | 4 |
C | 3344 | 93.23% | 7 |