Cream

@cream492

Cream 暂无简介

所有 个人的 我参与的
Forks 暂停/关闭的

    Cream/Security

    Cream/XSS-Platform

    XSS-Platform

    Cream/exp

    收集各种各样的exp

    Cream/AD-Pentest-Script

    Active Directory pentest scripts

    Cream/xssprobe

    xss probe to steal page info: browser, ua, lang, referer, location, toplocation, cookie, domain, title, screen, flash, etc.

    Cream/Get-MS14-068

    Quick and simple powershell script to scan event logs for possible indicators of MS14-068 exploitation

    Cream/Pentest-tools-2

    Intranet penetration tools

    Cream/JavaLearnVulnerability

    Java漏洞学习笔记 Deserialization Vulnerability

    Cream/BurpSuite-collections

    有关burpsuite的插件(非商店),文章以及使用技巧的收集(此项目不再提供burpsuite破解文件,如需要请在博客mrxn.net下载)---Collection of burpsuite plugins (non-stores), articles and tips for using Burpsuite, no crack version file

    Cream/CSPlugins

    Cobaltstrike Plugins

    Cream/CDK

    CDK is an open-sourced container penetration toolkit, offering stable exploitation in different slimmed containers without any OS dependency. It comes with penetration tools and many powerful PoCs/EXPs helps you to escape container and takeover K8s cluster easily.

    Cream/WhetherMysqlSham

    检测目标Mysql数据库是不是蜜罐

    Cream/AllAboutBugBounty

    All about bug bounty (bypasses, payloads, and etc)

    Cream/SharpSocks5

    Tunnellable HTTP/HTTPS socks5 proxy written in C#

    Cream/domainTools

    内网域渗透小工具

    Cream/AttackWebFrameworkTools

    本软件首先集成危害性较大前台rce(无需登录,或者登录绕过执行rce)。反序列化(利用链简单)。上传getshell。sql注入等高危漏洞直接就可以拿权限出数据。其次对一些构造复杂exp漏洞进行检测。傻瓜式导入url即可实现批量测试,能一键getshell检测绝不sql注入或者不是只检测。其中thinkphp 集成所有rce Exp Struts2漏洞集成了shack2 和k8 漏洞利用工具所有Exp并对他们的exp进行优化和修复此工具的所集成漏洞全部是基于平时实战中所得到的经验从而写入到工具里。例如:通达oA一键getshell实战测试 struts2一键getshell 等等

    Cream/Kernelhub

    :palm_tree:Windows Kernel privilege escalation vulnerability collection, with compilation environment, demo GIF map, vulnerability details, executable file

    Cream/BypassAv-web

    nim一键免杀

    Cream/DuckMemoryScan

    检测绝大部分所谓的内存免杀马

    Cream/github-cve-monitor

    监控github上新增的cve编号项目漏洞,推送钉钉或者server酱

搜索帮助