Skip to content
View zhifana's full-sized avatar

Block or report zhifana

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse

Starred repositories

Showing results

二开KillWxapkg项目,添加实时检测和开启web端服务

Go 31 Updated Nov 7, 2024

Automatically detect potential vulnerabilities and analyze repository metrics to prioritize open source security research targets

Go 146 15 Updated Nov 7, 2024

🧿 AutorizePro是一款强大越权检测 Burp 插件,通过增加 AI 辅助分析 && 进一步优化检测逻辑,大幅降低误报率,提升越权漏洞检出效率。 [ AutorizePro is a authorization enforcement detection extension for burp suite. By adding Ai-assisted analysis, it sign…

Python 269 9 Updated Nov 5, 2024

Get acquisitions by scraping titles of crunchbase.

Python 11 2 Updated Jun 26, 2024

此项目用来提取收集以往泄露的密码中符合条件的强弱密码

Python 1,108 311 Updated Apr 1, 2019

A cheatsheet for exploiting server-side SVG processors.

693 92 Updated Jul 2, 2020

一款代码审计辅助插件

Kotlin 217 18 Updated Nov 5, 2024

一款用于JNDI注入利用的工具,大量参考/引用了Rogue JNDI项目的代码,支持直接植入内存shell,并集成了常见的bypass 高版本JDK的方式,适用于与自动化工具配合使用。

Java 283 23 Updated Sep 6, 2022

best tool for finding SQLi,CRLF,XSS,LFi,OpenRedirect

Python 529 131 Updated Nov 3, 2024

JSNinja is a powerful tool designed for security researchers and developers looking to extract sensitive information and Urls from JavaScript files.

Python 68 17 Updated Oct 22, 2024

riverPass 是一个用Go编写的瑞数WAF绕过工具。它利用了WebSocket协议,将请求发送的自身浏览器中,从而绕过了瑞数WAF的检测。

Go 163 13 Updated Oct 18, 2024

ShodanX is a tool to gather information of targets using shodan dorks⚡.

Python 169 26 Updated Apr 18, 2024

Burp插件,快速探测可能存在SQL注入的请求并标记,提高测试效率

Java 80 6 Updated Nov 5, 2024

AutoBypass403-BurpSuite 插件二开重构,优化执行逻辑

Java 227 9 Updated Oct 12, 2024

Looks for parameters in urls

Python 29 3 Updated Oct 14, 2024

CSPTPlayground is an open-source playground to find and exploit Client-Side Path Traversal (CSPT).

JavaScript 80 6 Updated Oct 7, 2024

服务端配置错误情况下用于伪造ip地址进行测试的Burp Suite插件

Java 1,439 232 Updated Sep 29, 2022

“铲子”是一款简单易用的JAVA SAST工具,旨在为安全工程师提供一款简单、好用、价格厚道的代码安全扫描产品,支持语言: java(Servlet、spring、dubbo、thirft、mybatis、jsp) ,采用轻量级污点分析,铲子会将java、xml(mybatis、dubbo)等统一构建数据流图,然后进行污点分析,无需编译,也可以反编译扫描jar或class,内置了 sql 注…

265 7 Updated Nov 8, 2024

目标是成为当下最完善的API挖掘工具,实现自动提取响应敏感信息、URI信息,并且对URI进行自动|手动递归检查

Java 149 6 Updated Nov 1, 2024

This tool will check for Sensitive Data Leakage with some useful patterns/RegEx. The patterns are mostly targeted on waybackdata and filter everything accordingly.

Shell 188 48 Updated Aug 14, 2024

SubOwner - A Simple tool check for subdomain takeovers.

Python 98 24 Updated Oct 18, 2024

Chrome extension for automating CSPT discovery

TypeScript 47 2 Updated Oct 7, 2024

A tech enumeration toolkit focused on 404 Not found pages.

Go 24 2 Updated Oct 6, 2024

dirsx 是一款能够自动化过滤扫描结果的目录扫描工具

Go 84 4 Updated Oct 29, 2024

The Ultimate Information Gathering Toolkit

Python 1,147 126 Updated Oct 8, 2024

yuque 语雀知识库下载

TypeScript 619 99 Updated Nov 8, 2024

🔥🕷️ Crawl4AI: Open-source LLM Friendly Web Crawler & Scrapper

Python 15,760 1,146 Updated Nov 9, 2024

This repository will contain many mindmaps for cyber security technologies, methodologies, courses, and certifications in a tree structure to give brief details about them

7,093 1,366 Updated Sep 25, 2024

Improve your recon with this list of the most used subdomains for each ccTLD.

4 3 Updated Oct 21, 2024

Provides public bug bounty programs in-scope data that offer rewards and monitors public bug bounty programs assets.

46 7 Updated Nov 9, 2024
Next