Pinned Repositories
1earn
ffffffff0x 团队维护的安全知识框架,内容包括不仅限于 web安全、工控安全、取证、应急、蓝队设施部署、后渗透、Linux安全、各类靶机writup
Bug-Project-Framework
漏洞利用框架模块分享仓库
CTF-Training
收集各大比赛的题目和Writeup
jsfuck
Write any JavaScript with 6 Characters: []()!+
TheFatRat
Thefatrat a massive exploiting tool : Easy tool to generate backdoor and easy tool to post exploitation attack like browser attack,dll . This tool compiles a malware with popular payload and then the compiled malware can be execute on windows, android, mac . The malware that created with this tool also have an ability to bypass most AV software protection .
ThinkPHP-Vuln
关于ThinkPHP框架的历史漏洞分析集合
webCodeMonitor
Monitor the website source code,if it changed the program will play sound to alert you
WorkingTime
xsser
Cross Site "Scripter" (aka XSSer) is an automatic -framework- to detect, exploit and report XSS vulnerabilities in web-based applications.
Sholway's Repositories
Sholway/All-Defense-Tool
本项目集成了全网优秀的攻防工具项目,包含自动化利用,子域名、敏感目录、端口等扫描,各大中间件,cms漏洞利用工具以及应急响应等资料。
Sholway/kms
KMS 激活服务,slmgr 命令激活 Windows 系统、Office
Sholway/Penetration_Testing_POC
渗透测试有关的POC、EXP、脚本、提权、小工具等---About penetration-testing python-script poc getshell csrf xss cms php-getshell domainmod-xss csrf-webshell cobub-razor cve rce sql sql-poc poc-exp bypass oa-getshell cve-cms
Sholway/nuclei
Fast and customizable vulnerability scanner based on simple YAML based DSL.
Sholway/SmsForwarder
短信转发器——监控Android手机短信、来电、APP通知,并根据指定规则转发到其他手机:钉钉机器人、企业微信群机器人、飞书机器人、企业微信应用消息、邮箱、bark、webhook、Telegram机器人、Server酱、PushPlus、手机短信等。包括主动控制服务端与客户端,让你轻松远程发短信、查短信、查通话、查话簿、查电量等。(V3.0 新增)PS.这个APK主要是学习与自用,如有BUG请提ISSUE,同时欢迎大家提PR指正
Sholway/DogCs4.4
4.4修改版
Sholway/Ciphey
⚡ Automatically decrypt encryptions without knowing the key or cipher, decode encodings, and crack hashes ⚡
Sholway/NEW_xp_CAPTCHA
xp_CAPTCHA(瞎跑 白嫖版) burp 验证码 识别 burp插件
Sholway/Library-POC
基于Pocsuite3、goby编写的漏洞poc&exp存档
Sholway/goby-poc
Sholway/httpx
httpx is a fast and multi-purpose HTTP toolkit allows to run multiple probers using retryablehttp library, it is designed to maintain the result reliability with increased threads.
Sholway/subfinder
Subfinder is a subdomain discovery tool that discovers valid subdomains for websites. Designed as a passive framework to be useful for bug bounties and safe for penetration testing.
Sholway/RedTeam_BlueTeam_HW
红蓝对抗以及护网相关工具和资料,内存shellcode(cs+msf)和内存马查杀工具
Sholway/shiro_killer
批量ShiroKey检测爆破工具
Sholway/v2board
🚀A multiple proxy protocol manage panel application interface
Sholway/dirsearch
Web path scanner
Sholway/1earn
ffffffff0x 团队维护的安全知识框架,内容包括不仅限于 web安全、工控安全、取证、应急、蓝队设施部署、后渗透、Linux安全、各类靶机writup
Sholway/Yasso
强大的内网渗透辅助工具集-让Yasso像风一样 支持rdp,ssh,redis,postgres,mongodb,mssql,mysql,winrm等服务爆破,快速的端口扫描,强大的web指纹识别,各种内置服务的一键利用(包括ssh完全交互式登陆,mssql提权,redis一键利用,mysql数据库查询,winrm横向利用,多种服务利用支持socks5代理执行)
Sholway/webEye
快速批量检测IP上指定端口的Web站点存活信息,获取其Title,红队信息搜集、蓝队资产探测梳理。
Sholway/heapdump_tool
heapdump敏感信息查询工具,例如查找 spring heapdump中的密码明文,AK,SK等
Sholway/JDumpSpider
HeapDump敏感信息提取工具
Sholway/moonwalk
Cover your tracks during Linux Exploitation by leaving zero traces on system logs and filesystem timestamps.
Sholway/dsq
Commandline tool for running SQL queries against JSON, CSV, Excel, Parquet, and more.
Sholway/ShiroExp
shiro综合利用工具
Sholway/netspy
netspy是一款快速探测内网可达网段工具(深信服深蓝实验室天威战队强力驱动)
Sholway/Bark
Bark is an iOS App which allows you to push custom notifications to your iPhone
Sholway/CTFever
A toolkit for CTF fevers
Sholway/curlconverter
Generate code from cURL commands
Sholway/GetSubdomain
使用在线工具获取子域名信息
Sholway/PentestDB
各种数据库的利用姿势