Thanks to visit codestin.com
Credit goes to github.com

Skip to content
View pwnhxl's full-sized avatar
  • Local

Block or report pwnhxl

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse

Starred repositories

Showing results

A lightweight active and passive scanner that combines the advantages of local and distributed models, supports dynamic external plugin import, and is dedicated to exploring web black-box vulnerabi…

Python 344 29 Updated Jan 3, 2026

复杂请求下的Shiro反序列化利用工具

Java 414 30 Updated Mar 12, 2024

知道创宇研发技能表

Python 842 167 Updated Aug 23, 2024

Chrome-RCE-Poc

HTML 91 17 Updated Aug 24, 2024

一款用于JNDI注入利用的工具,大量参考/引用了Rogue JNDI项目的代码,支持直接植入内存shell,并集成了常见的bypass 高版本JDK的方式,适用于与自动化工具配合使用。

Java 363 29 Updated Sep 6, 2022

A lightweight reverse proxy server that converts TLS traffic to TCP, allowing secure communication between clients and upstream servers.

Go 78 9 Updated Aug 16, 2024

综合漏洞后渗透利用工具

1,631 125 Updated Dec 11, 2025

最好用最智能最可控的目录Fuzz工具 | The most powerful, user-friendly, intelligent, and precise HTTP Fuzzer.

Go 960 65 Updated Dec 9, 2025

华顺信安技术羊皮卷

Jupyter Notebook 169 29 Updated Oct 6, 2025

一个想让你测试加密流量像测试明文一样简单高效的 Burp 插件。 A Burp plugin that makes testing encrypted traffic as simple and efficient as testing plaintext.

Java 1,024 72 Updated Dec 18, 2025

Advanced SQL Injection Techniques for Bug Bounty Hunters

142 81 Updated Feb 10, 2025

阿里云aliyun/腾讯云tencentcloud/华为云huaweicloud/aws等各种云厂商的accesskey运维安全工具,accesskey利用工具,包括但不限于创建ecs、ecs查询和命令执行、oss查询和批量下载等各种功能,aws accesskey rce;remote command execute

Python 486 40 Updated Nov 28, 2025
Python 18 3 Updated Aug 2, 2018

A habit tracker app which treats your goals like a Role Playing Game.

JavaScript 13,609 4,388 Updated Jan 12, 2026
Java 4 Updated Jan 10, 2025

This repository contains a number of insecure self-hosted applications that allows interested security engineers to test vulnerabilities found by Portswigger Research team.

TypeScript 26 1 Updated Apr 30, 2025

A powerful JNDI injection exploitation framework that supports RMI, LDAP and LDAPS protocols, including various bypass methods for high-version JDK restrictions

Java 556 38 Updated Dec 9, 2025

ARL(灯塔系统)替换子域名字典和路径扫描字典

Shell 6 1 Updated Oct 20, 2023

一款提高安全测试效率的工具

JavaScript 462 109 Updated Jun 14, 2023

一个经典的XSS渗透管理平台

PHP 728 199 Updated Feb 15, 2023

爬网站JS文件,自动fuzz api接口,指定api接口(针对前后端分离项目,可指定后端接口地址),回显api响应

Python 751 60 Updated Jul 20, 2023

一款网页批量截图工具

Python 32 1 Updated Jul 19, 2025

WeblogicTool,GUI漏洞利用工具,支持漏洞检测、命令执行、内存马注入、密码解密等(深信服深蓝实验室天威战队强力驱动)

1,767 111 Updated Nov 1, 2023

SafeLine is a self-hosted WAF(Web Application Firewall) / reverse proxy to protect your web apps from attacks and exploits.

Go 20,080 1,274 Updated Nov 5, 2025

Web弱密码爆破工具, 驱动浏览器进行弱密码爆破, 支持所有Web系统. 协程练手项目

Python 40 9 Updated Nov 14, 2022

DOM fuzzer

Python 1,769 287 Updated Nov 26, 2024

🦀️ 一个完全使用Rust编写的代理池工具,从网络搜索socks5代理,检测可用性之后开启socks5代理服务。A proxy pool tool completely written in Rust, which searches for SOCKS5 proxies from the network, and after checking their availability, star…

Rust 87 4 Updated Mar 20, 2023

记录安全方面的笔记/工具/漏洞合集

436 85 Updated May 14, 2025

《Golang修养之路》本书针对Golang专题性热门技术深入理解,修养在Golang领域深入话题,脱胎换骨。

3,884 707 Updated Dec 19, 2023
HTML 3 Updated May 21, 2023
Next