cr1f's Stars
swisskyrepo/PayloadsAllTheThings
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
acmesh-official/acme.sh
A pure Unix shell script implementing ACME client protocol
nikic/PHP-Parser
A PHP parser written in PHP
angristan/openvpn-install
Set up your own OpenVPN server on Debian, Ubuntu, Fedora, CentOS or Arch Linux.
frohoff/ysoserial
A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.
yeyintminthuhtut/Awesome-Red-Teaming
List of Awesome Red Teaming Resources
xmendez/wfuzz
Web application fuzzer
epinna/tplmap
Server-Side Template Injection and Code Injection Detection and Exploitation Tool
tomnomnom/waybackurls
Fetch all the URLs that the Wayback Machine knows about for a domain
blechschmidt/massdns
A high-performance DNS stub resolver for bulk lookups and reconnaissance (subdomain enumeration)
laurentj/slimerjs
A scriptable browser like PhantomJS, based on Firefox
hannob/snallygaster
Tool to scan for secret files on HTTP servers
kost/dvcs-ripper
Rip web accessible (distributed) version control systems: SVN/GIT/HG...
RenwaX23/XSS-Payloads
List of XSS Vectors/Payloads
l3m0n/Bypass_Disable_functions_Shell
一个各种方式突破Disable_functions达到命令执行的shell
avevlad/russia-it-podcast
Список русскоязычных подкастов на тему информационных технологий
bl4de/security-tools
My collection of various security tools created mostly in Python and Bash. For CTFs and Bug Bounty.
NickstaDB/BaRMIe
Java RMI enumeration and attack tool.
HoLyVieR/prototype-pollution-nsec18
Content released at NorthSec 2018 for my talk on prototype pollution
Bo0oM/PHP_imap_open_exploit
Bypassing disabled exec functions in PHP (c) CRLF
a2u/CVE-2018-7600
💀Proof-of-Concept for CVE-2018-7600 Drupal SA-CORE-2018-002
Bo0oM/ParamPamPam
Tools2/Zend-Decoder
还原ZendGuard处理后的php代码
breenmachine/dnsftp
Client/Server scripts to transfer files over DNS. Client scripts are small and only use native tools on the host OS.
beched/php_disable_functions_bypass
procfs-based PHP sandbox bypass
firefart/CVE-2018-7600
CVE-2018-7600 - Drupal 7.x RCE
paralax/Awesome-Pentest-1
Awesome Penetration Testing A collection of awesome penetration testing resources
nikic/Phuzzy
Fuzzer for PHP internal functions
bucefal91/php-async
Framework for asynchronous executing shell command in PHP.
winstrool/pas-4.1.1b_source_code
Так как автор шелла P.A.S приостановил разработку в связи с нашумевшими событиями, возможно, кто то захочет продолжать его доробатывать, для этих целей выкладываю исходный код который взял с шела https://github.com/wordfence/grizzly/blob/master/pas-4.1.1b/P.A.S.v.4.1.1b.php