Pinned Repositories
0day
各种CMS、各种平台、各种系统、各种软件漏洞的EXP、POC 该项目将不断更新
1000php
1000个PHP代码审计案例(2016.7以前乌云公开漏洞)
1earn
ffffffff0x 团队维护的安全知识框架,内容包括不仅限于 web安全、工控安全、取证、应急、蓝队设施部署、后渗透、Linux安全、各类靶机writup
2021_Hvv
2021 hw
2021hvv_vul
2021hvv漏洞汇总
CodeReviewTools
通过正则搜索、批量反编译特定Jar包中的class名称
FindShell
内存马查杀工具,尤其针对Agent型,原理是dump出JVM当前的class并进行字节码分析,并加入自动修复的功能
java
Java设计模式详解系列
shiro_attack
shiro反序列化漏洞综合利用,包含(回显执行命令/注入内存马)
XSS-Payloads
List of advanced XSS payloads
geekmc's Repositories
geekmc/apkinfo
安卓apk信息提取,敏感信息搜集
geekmc/awesome-cheatsheets
超级速查表 - 编程语言、框架和开发工具的速查表,单个文件包含一切你需要知道的东西 :zap:
geekmc/CloudKeyKiller
阿里云AK泄露利用工具
geekmc/codemillx
codemillx is a tool for CodeQL, extract the comments in the code and generate codeql module. codemillx是一款CodeQL辅助工具,通过提取代码中的注释,并可生成codeql ql模块。
geekmc/CodeQL-1
《深入理解CodeQL》Finding vulnerabilities with CodeQL.
geekmc/CodeQLRule
个人使用CodeQL编写的一些规则
geekmc/CryptoVulhub
Analyze and reproduce attack events or vulnerabilities in the blockchain world.
geekmc/dirsearch
Web path scanner
geekmc/ENScan_GO
一款基于各大企业信息API的工具,解决在遇到的各种针对国内企业信息收集难题。一键收集控股公司ICP备案、APP、小程序、微信公众号等信息聚合导出。
geekmc/ffuf
Fast web fuzzer written in Go
geekmc/follina.py
POC to replicate the full 'Follina' Office RCE vulnerability for testing purposes
geekmc/GBByPass
冰蝎 哥斯拉 WebShell bypass
geekmc/GitHack
A `.git` folder disclosure exploit
geekmc/manticore
Symbolic execution tool
geekmc/mythril
Security analysis tool for EVM bytecode. Supports smart contracts built for Ethereum, Hedera, Quorum, Vechain, Roostock, Tron and other EVM-compatible blockchains.
geekmc/OneListForAll
Rockyou for web fuzzing
geekmc/penetration-suite-toolkit
本项目制作的初衷是帮助渗透新手快速搭建工作环境,工欲善其事,必先利其器。
geekmc/PrivacySentry
Android隐私合规检测,注解+Asm修改字节码的检测方案
geekmc/ReZeroBypassAV
从零开始学免杀
geekmc/s2-062
远程代码执行S2-062 CVE-2021-31805验证POC
geekmc/secguide
面向开发人员梳理的代码安全指南
geekmc/sizedwaitgroup
SizedWaitGroup has the same role and close to the same API as the Golang sync.WaitGroup but it adds a limit on the amount of goroutines started concurrently.
geekmc/SpringBootExploit
项目是根据LandGrey/SpringBootVulExploit清单编写,目的hvv期间快速利用漏洞、降低漏洞利用门槛。
geekmc/SpringCore0day
SpringCore0day from https://share.vx-underground.org/
geekmc/SWC-registry
Smart Contract Weakness Classification and Test Cases
geekmc/TraceInfoCrawl
geekmc/vue-admin-template
a vue2.0 minimal admin template
geekmc/wechat_info_collect
调查取证 | 针对微信客户端的信息收集工具, 自动化提取本地PC所有的微信信息, 包括微信号, 手机号等
geekmc/Wwaf
Wwaf is a small tool for identifying Web application firewall (WAF) products.
geekmc/xssfinder
xss discovery tool(under development)