Pinned Repositories
-svg-onload-alert-1-
<svg/onload=alert`2`>
230-OOB
An Out-of-Band XXE server for retrieving file contents over FTP.
chunked-coding-converter
Burp suite 分块传输辅助插件
Mobile-Security-Framework-MobSF
Mobile Security Framework is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing framework capable of performing static analysis, dynamic analysis, malware analysis and web API testing.
Papers-1
Some papers about cyber security
weblogic-framework
weblogic-framework
webshell
This is a webshell open source project
selfEVO's Repositories
selfEVO/wordbrutepress
Wordpress Brute Force Multithreading with standard and xml-rpc login
selfEVO/go-derper
Memcache hacking tool.
selfEVO/cve-2017-7269
fixed msf module for cve-2017-7269
selfEVO/papers
my security summit papers
selfEVO/SecPaper
SecurityPaper For http://www.polaris-lab.com/
selfEVO/SuperSQLInjectionV1
超级SQL注入工具 简介: 超级SQL注入工具(SSQLInjection)是一款基于HTTP协议自组包的SQL注入工具,采用C#开发,程序采用自写代码来操作HTTP交互,支持出现在HTTP协议任意位置的SQL注入,支持各种类型的SQL注入,支持HTTPS模式注入;支持以盲注、错误显示、Union注入等方式来获取数据;支持Access/MySQL/SQLServer/Oracle等数据库;支持手动灵活的进行SQL注入绕过,可自定义进行字符替换等绕过注入防护。本工具为渗透测试人员、信息安全工程师等掌握SQL注入技能的人员设计,需要使用人员对SQL注入有一定了解。 工具特点: 1.支持任意地点出现的任意SQL注入 2.支持全自动识别注入标记,也可人工识别注入并标记。 3.支持各种语言环境。大多数注入工具在盲注下,无法获取中文等多字节编码字符内容,本工具可完美解决。 4.支持注入数据发包记录。让你了解程序是如何注入,有助于快速学习和找出注入问题。 5.依靠关键字/时间等进行盲注,可通过HTTP相应状态码判断,还可以通过关键字取反功能,反过来取关键字。 6.程序采用自编码操作HTTP请求,HTTP发包和获取速度较快。
selfEVO/iniscan
A php.ini scanner for best security practices
selfEVO/tools
security and hacking tools, exploits, proof of concepts, shellcodes, scripts
selfEVO/crack
crack login and pass
selfEVO/scan
selfEVO/liffy
Local File Inclusion Exploitation Tool (mirror)
selfEVO/XXEinjector
Tool for automatic exploitation of XXE vulnerability using direct and different out of band methods.
selfEVO/jdwp-shellifier
selfEVO/IoTSeeker
Created by Jin Qian via the GitHub Connector
selfEVO/XssApp
本项目是一个Xss跨站脚本测试平台,适用于白帽子对各大厂商进行Xss跨站脚本测试
selfEVO/weakfilescan
动态多线程敏感信息泄露检测工具
selfEVO/gopl-zh
:books: Go语言圣经中文版
selfEVO/pentestEr_Fully-automatic-scanner
定向全自动化渗透测试
selfEVO/dvws
Damn Vulnerable Web Services is an insecure web application with multiple vulnerable web service components that can be used to learn real world web service vulnerabilities.
selfEVO/sandcastle
A simple and powerful sandbox for running untrusted JavaScript.
selfEVO/ps1encode
Script used to generate and encode a PowerShell based Metasploit payloads.
selfEVO/ABPTTS
TCP tunneling over HTTP/HTTPS for web application servers
selfEVO/Some-PoC-oR-ExP
各种漏洞poc、Exp的收集或编写
selfEVO/xtunnel
selfEVO/BadTunnel_exp
Usage: python badtunnel.py wpad_server_ip
selfEVO/vulnerable-node
A very vulnerable web site written in NodeJS with the purpose of have a project with identified vulnerabilities to test the quality of security analyzers tools tools
selfEVO/IntruderPayloads
A collection of Burpsuite Intruder payloads, fuzz lists and file uploads
selfEVO/webshell
This is a webshell open source project
selfEVO/MCIR
The Magical Code Injection Rainbow! MCIR is a framework for building configurable vulnerability testbeds. MCIR is also a collection of configurable vulnerability testbeds.
selfEVO/htpwdScan
A python HTTP weak pass scanner