A reliable exploit + write-up to elevate privileges to root. (Tested on Ubuntu 22.04)
A Bash script for automating domain reconnaissance and XSS vulnerability detection.
A practical Web shooting range integrating multiple languages to aid in penetration testing and code auditing.
A CTF platform aimed at collecting various RCE techniques for practice and learning.
vulhub/java-chains is a platform for generating Java Payloads and testing vulnerabilities for security researchers.
基于CTFd 3.5.3 版本开发,整合多种插件的CTFd一键部署版,提供便利的比赛平台。
A repository containing web and API vulnerability checklists, ideas, and tips from Twitter.
安全手册,企业安全实践、攻防与安全研究知识库.
Nuclei AI is a browser extension for rapid generation of vulnerability templates from any webpage.
一个漏洞扫描器粘合剂,支持多种扫描工具的自动调用与结果聚合。
A fully automated, aggressive URL discovery and vulnerability scanning script for Bug Bounty & Penetration Testing.
JShunter is a command-line tool for analyzing JavaScript files and extracting sensitive data and endpoints.