Exploit refers to a piece of code or technique that takes advantage of a security vulnerability in a system, application, or network to cause unintended behavior. Exploits can be used by attackers to gain unauthorized access, escalate privileges, execute arbitrary code, or cause a denial of service. This topic covers the various types of exploits, such as zero-day exploits, remote code execution, and privilege escalation. It also explores the lifecycle of an exploit, from discovery and development to deployment and mitigation, and highlights the importance of vulnerability management and patching in preventing exploits.
#Awesome#This repository is primarily maintained by Omar Santos (@santosomar) and includes thousands of resources related to ethical hacking, bug bounties, digital forensics and incident response (DFIR), artif...
翻译 - 该存储库主要由Omar Santos维护,并包含与道德黑客/渗透测试,数字取证和事件响应(DFIR),漏洞研究,漏洞利用开发,逆向工程等相关的数千种资源。
#夺旗赛 (CTF) 和网络安全资源#A collection of hacking / penetration testing resources to make you better!
翻译 - 一系列骇客/渗透测试资源,可助您一臂之力!
#夺旗赛 (CTF) 和网络安全资源#CTF framework and exploit development library
翻译 - CTF框架和漏洞利用开发库
Exploitation Framework for Embedded Devices
翻译 - 嵌入式设备的开发框架
该仓库提供了精选的 Nuclei 模板。Nuclei 是一个基于YAML模板,自定义的漏洞扫描工具。
windows-kernel-exploits Windows平台提权漏洞集合
A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.
翻译 - 概念证明工具,用于生成利用不安全的Java对象反序列化的有效负载。
GEF (GDB Enhanced Features) - a modern experience for GDB with advanced debugging capabilities for exploit devs & reverse engineers on Linux
翻译 - GEF-针对漏洞利用开发者和反向者的GDB增强功能
一个自动化Linux root提权工具
📡 PoC auto collect from GitHub. ⚠️ Be careful Malware.
翻译 - 📡POC自动收集GitHub。⚠️要仔细恶意软件。
渗透测试有关的POC、EXP、脚本、提权、小工具等---About penetration-testing python-script poc getshell csrf xss cms php-getshell domainmod-xss csrf-webshell cobub-razor cve rce sql sql-poc poc-exp bypass oa-getshell cve-cm...
Yakit是基于yak语言开发的网络安全单兵工具,旨在打造一个覆盖渗透测试全流程的网络安全工具库。
#速查表 cheatsheets#One place for all the default credentials to assist the Blue/Red teamers identifying devices with default password 🛡️
翻译 - 所有默认凭据的一个地方,可以帮助蓝色/红色团队成员活动查找具有默认密码password️的设备
K8工具合集(内网渗透/提权工具/远程溢出/漏洞利用/扫描工具/密码破解/免杀工具/Exploit/APT/0day/Shellcode/Payload/priviledge/BypassUAC/OverFlow/WebShell/PenTest) Web GetShell Exploit(Struts2/Zimbra/Weblogic/Tomcat/Apache/Jboss/DotNetNuke...
Linux privilege escalation auditing tool
A collection of links related to Linux kernel security and exploitation
翻译 - 一堆与Linux内核开发有关的链接
linux-kernel-exploits Linux平台提权漏洞集合