Pinned Repositories
Gofreeproxy
自用的动态代理小工具
subsocks
A Socks5 proxy that encapsulates Socks5 in other security protocols
Bundler-bypass
免杀捆绑器,过国内主流杀软。A Bundler bypass anti-virus
cf-backup
云环境利用框架(Cloud exploitation framework)主要用来方便红队人员在获得 AK 的后续工作。
ClashX
CVE-2024-26026
CVE-2024-26026: BIG-IP Next Central Manager API UNAUTHENTICATED SQL INJECTION
FakeToa
TCP IP伪造,建议使用 ubuntu 22.04
MemShell-1
Tomcat的Filter型免杀内存马,主要思路是Bypass各种检查手段
QVD-2023-6271
Alibab Nacos <= 2.2.0 Unauthorized Login POC EXP
httpx
httpx is a fast and multi-purpose HTTP toolkit that allows running multiple probes using the retryablehttp library.
passwa11's Repositories
passwa11/PhpPassWaf
Php免杀学习
passwa11/baijiang
万户oa poc综合扫描
passwa11/CVE-2023-3519
passwa11/Hikvision
passwa11/CitriDish
Python Script to quickly check if a host is running NetScaler Gateway and/or AAA
passwa11/CVE-2023-20887
VMWare vRealize Network Insight Pre-Authenticated RCE (CVE-2023-20887)
passwa11/CVE-2023-27997-check
Safely detect whether a FortiGate SSL VPN instance is vulnerable to CVE-2023-27997 based on response timing
passwa11/CVE-2023-37582_EXPLOIT
Apache RocketMQ Arbitrary File Write Vulnerability Exploit
passwa11/DudePoc
Dude Suite Web 渗透测试工具专用漏洞验证样本
passwa11/exp_and_poc_archive
Used for archiving some useless EXP and PoC scripts.
passwa11/Goby_POC1
在公网收集的gobypoc+部分自己加的poc
passwa11/GobypassAV-shellcode
shellcode免杀加载器,使用go实现,免杀bypass火绒、360、核晶、def等主流杀软
passwa11/HackJava
《Java安全-只有Java安全才能拯救宇宙》Only Java Security Can Save The Universe.
passwa11/In-Swor
一个简单内网渗透工具免杀 目前mimikatz,frp,elevationstationbypassuac。360报毒qvm20请更换exe图标资源。
passwa11/Incloud_scan
passwa11/IOT-POC
IOT vulnerability
passwa11/Java-Shellcode-Loader
基于Java实现的Shellcode加载器
passwa11/NacosRce
Nacos JRaft Hessian 反序列化 RCE 加载字节码 注入内存马 不出网利用
passwa11/nginxWebUI
Nginx Web page configuration tool. Use web pages to quickly configure Nginx. Nginx网页管理工具,使用网页来快速配置与管理nginx单机与集群
passwa11/qq-tim-elevation
passwa11/QueryTools
IP/域名资产验证神器(补天|权重、CNVD|注册资金)-功能(IP反查域名、域名备案、ICP资产、公司注册资金、权重、IP定位)快速验证是否为需求资产
passwa11/RancidCrisco
PoC for CVE-2023-20126
passwa11/sec-books-part1
passwa11/SGK_Sites_and_Bots
社工库分享。免费好用的 社工库网站 和 Telegram社工库机器人,查询帐号、密码、邮箱、手机号、身份证及各种隐私数据是否泄露。
passwa11/ShiroExp
shiro综合利用工具
passwa11/smartbi
passwa11/SpringBootAdmin-thymeleaf-SSTI
SpringBootAdmin-thymeleaf-SSTI which can cause RCE
passwa11/ThinkphpGUI_new
passwa11/ultimaste-nuclei-templates
极致攻防实验室 nuclei 检测 POC
passwa11/WeaverScan
泛微oa漏洞利用工具