👾KEYWORD SERVICE 🏷#exploit
Name: Project-Lucifer
Github: https://github.com/haries-dev/Project-Lucifer
Name: Project-Lucifer
Github: https://github.com/haries-dev/Project-Lucifer
GitHub
GitHub - haries-dev/Project-Lucifer: Lucifer is a immortal spyware developed by Haries Palaniappan, Like Pegasus is able to exploit…
Lucifer is a immortal spyware developed by Haries Palaniappan, Like Pegasus is able to exploit any infrastructure through a zero-click exploit. Used for Penetration testing for company's In...
** fscan ** 🔧Tool update
Tools name:fscan
Tools url:https://github.com/shadow1ng/fscan/commit/38e48ba4205196e042db8f832a7789b76ee61c5e
commitUpdate log:
Merge pull request #225 from evilAdan0s/main
去除弱特征:过时UA头
Tools name:fscan
Tools url:https://github.com/shadow1ng/fscan/commit/38e48ba4205196e042db8f832a7789b76ee61c5e
commitUpdate log:
Merge pull request #225 from evilAdan0s/main
去除弱特征:过时UA头
GitHub
Merge pull request #225 from evilAdan0s/main · shadow1ng/fscan@38e48ba
去除弱特征:过时UA头
👾KEYWORD SERVICE 🏷#rce
Name: burp_log4j_rce_scaner
Github: https://github.com/secxh/burp_log4j_rce_scaner
Name: burp_log4j_rce_scaner
Github: https://github.com/secxh/burp_log4j_rce_scaner
GitHub
GitHub - secxh/burp_log4j_rce_scaner
Contribute to secxh/burp_log4j_rce_scaner development by creating an account on GitHub.
👾KEYWORD SERVICE 🏷#exploit
Name: BeEF-en-ubuntu-22.04
Github: https://github.com/demontaim/BeEF-en-ubuntu-22.04
Name: BeEF-en-ubuntu-22.04
Github: https://github.com/demontaim/BeEF-en-ubuntu-22.04
GitHub
GitHub - demontaim/BeEF-en-ubuntu-22.04: Guía de instalación de BeEF Browser Exploitation Framework en una máquina Ubuntu 22.04
Guía de instalación de BeEF Browser Exploitation Framework en una máquina Ubuntu 22.04 - GitHub - demontaim/BeEF-en-ubuntu-22.04: Guía de instalación de BeEF Browser Exploitation Framework en una m...
👾KEYWORD SERVICE 🏷#webshell
Name: terro-php-webshell
Github: https://github.com/grabowskiadrian/terro-php-webshell
Name: terro-php-webshell
Github: https://github.com/grabowskiadrian/terro-php-webshell
GitHub
GitHub - grabowskiadrian/terro-php-webshell: Simple PHP webshell. Functions: Execute commands on linux server, Browse files and…
Simple PHP webshell. Functions: Execute commands on linux server, Browse files and directories, Read files, Upload files, phpinfo output, check active Apache2 services - GitHub - grabowskiadrian/te...
👾CVE SERVICE 🏷#CVE
Mumber: CVE-2022-31692
Github: https://github.com/SpindleSec/CVE-2022-31692
Describe:
Spring Security, versions 5.7 prior to 5.7.5 and 5.6 prior to 5.6.9 could be susceptible to authorization rules bypass via forward or include dispatcher types. Specifically, an application is vulnerable when all of the following are true: The application expects that Spring Security applies security to forward and include dispatcher types. The application uses the AuthorizationFilter either manually or via the authorizeHttpRequests() method. The application configures the FilterChainProxy to apply to forward and/or include requests (e.g. spring.security.filter.dispatcher-types = request, error, async, forward, include). The application may forward or include the request to a higher privilege-secured endpoint.The application configures Spring Security to apply to every dispatcher type via authorizeHttpRequests().shouldFilterAllDispatcherTypes(true)
Mumber: CVE-2022-31692
Github: https://github.com/SpindleSec/CVE-2022-31692
Describe:
Spring Security, versions 5.7 prior to 5.7.5 and 5.6 prior to 5.6.9 could be susceptible to authorization rules bypass via forward or include dispatcher types. Specifically, an application is vulnerable when all of the following are true: The application expects that Spring Security applies security to forward and include dispatcher types. The application uses the AuthorizationFilter either manually or via the authorizeHttpRequests() method. The application configures the FilterChainProxy to apply to forward and/or include requests (e.g. spring.security.filter.dispatcher-types = request, error, async, forward, include). The application may forward or include the request to a higher privilege-secured endpoint.The application configures Spring Security to apply to every dispatcher type via authorizeHttpRequests().shouldFilterAllDispatcherTypes(true)
GitHub
GitHub - blipzip/cve-2022-31692: A project demonstrating an app that is vulnerable to Spring Security authorization bypass CVE…
A project demonstrating an app that is vulnerable to Spring Security authorization bypass CVE-2022-31692 - blipzip/cve-2022-31692