GitHub 红队武器库🚨
14.2K subscribers
26 photos
9 videos
26.8K links
​📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
​⚠️ 本频道仅供安全研究与授权测试使用。
Download Telegram
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Shellcode #Execute

📦 项目名称: roprop
👤 项目作者: Tendarkness
🛠 开发语言: Python
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-25 01:57:49

📝 项目描述:
ROP chain filter & shellcode helper for exploit developers — built for OSED/OSCE3

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Shellcode #Execute

📦 项目名称: shell-functions
👤 项目作者: ReedClanton
🛠 开发语言: Shell
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-25 01:36:44

📝 项目描述:
This contains a number of shell functions that may be of use. The intention is for the root of this repository to be cloned to an area in a user's home directory. Then `shellFunctionSetup.sh` should be run with `eval "$(/path/to/shellFunctionSetup.sh)"` by the user's shell configuration.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #CVE

📦 项目名称: Penetration-Test-SNMP-Exploitation-on-Windows-Server-2008-R2
👤 项目作者: nikul0022
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-25 06:01:37

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #Remote Code Execution

📦 项目名称: Smol-TryHackMe-Walkthrough
👤 项目作者: anurag-rvnkr1
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-25 06:05:25

📝 项目描述:
Professional TryHackMe Smol walkthrough documenting WordPress enumeration, jsmol2wp LFI, wp-config disclosure, PHP backdoor analysis, RCE, reverse-shell access, credential-based lateral movement, SSH key abuse, encrypted backup analysis, and Linux privilege escalation.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #CVE

📦 项目名称: CVE-Vulnerability-Penetration-Testing-CTF-Labs-Hands-On-Cybersecurity
👤 项目作者: sifatnotes
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-25 06:14:48

📝 项目描述:
Hands-on cybersecurity CTF labs covering SQL injection, SSRF, XSS, MITM, race conditions, path traversal, authorization bypasses, OS command injection, and authorized network security testing.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #CVE

📦 项目名称: Digital-Forensics-OSINT-CVE-Security-Labs-Hands-On-Cybersecurity-CTF
👤 项目作者: sifatnotes
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-25 06:09:03

📝 项目描述:
Hands-on cybersecurity and CTF labs covering email forensics, Windows Registry and Shimcache analysis, PST/OST triage, mobile verification, authorized OSINT, partition recovery, SQL injection, SSRF, and CVSS v3.1 assessment.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: SentinelAPI
👤 项目作者: tanishqueagrawal
🛠 开发语言: JavaScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-25 06:16:20

📝 项目描述:
Zero-Trust API Vulnerability Scanner for automated API security analysis.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit

📦 项目名称: CVE-2026-93399
👤 项目作者: murrez
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-25 07:53:48

📝 项目描述:
Unauthenticated IDOR in Bookly ≤ 28.2: bookly_get_form_id + bookly_render_complete leak any order’s bookly_order token; bookly_add_to_calendar exposes appointments; bookly_rollback_order cancels/deletes non-completed bookings. CVSS 9.1. Python check/exploit PoC — pocbit.org/pocs/cve-2026-93399

🔗 点击访问项目地址
👍1
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit

📦 项目名称: CVE-2026-89055
👤 项目作者: murrez
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-25 07:49:27

📝 项目描述:
Unauthenticated authorization bypass in Customer Reviews for WooCommerce ≤ 5.120.0: holders of a public /cusrev/{formId}/ review link can POST cr_local_forms_submit with arbitrary Media Library attachment IDs in items[].media. Linked files are permanently deleted when the review comment is purged. Python check/exploit PoC (PoCbit catalog).

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit

📦 项目名称: CVE-2026-14281
👤 项目作者: murrez
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-25 07:44:09

📝 项目描述:
Unauthenticated privilege escalation in WordPress WAWP (Automation Web Platform) ≤ 4.8.6 via public REST signup and unsanitized wawp_custom_fields → admin. Python check/exploit PoC (PoCbit).

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: vulnlock
👤 项目作者: sriharifortitude
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-25 08:39:20

📝 项目描述:
Known-vulnerability scanner for npm, Go and Python lockfiles, against the real OSV.dev database. Real CVSS v3.1 scoring, waivers, SARIF. Python, MIT.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: SSRF3r
👤 项目作者: MaestraSoprano
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-25 08:24:42

📝 项目描述:
无描述

🔗 点击访问项目地址
👍1
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: jack-sparrow
👤 项目作者: Pabl0l
🛠 开发语言: Rust
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-25 07:37:14

📝 项目描述:
web hacking sharp-tool kit. XSS, SSRF, IDOR...

🔗 点击访问项目地址
👍1
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: ghostlock-mrx-w09
👤 项目作者: 0ch4
🛠 开发语言: C
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-25 09:50:19

📝 项目描述:
CVE-2026-43499 (GhostLock) port: working root on the Huawei MatePad Pro MRX-W09 (Kirin 990, EMUI 11, Linux 4.14.116) - disassembly-proven write primitive, perf cred leak, and a source-derived HKIP bypass

🔗 点击访问项目地址
Forwarded from Channel Help
🔤🔤🔤🔤🔤🔤🔤🔤
😍 超级爆率提款秒到尽在凯旋
1️⃣1️⃣1️⃣1️⃣1️⃣1️⃣1️⃣1️⃣1️⃣
1️⃣1️⃣1️⃣1️⃣1️⃣1️⃣1️⃣1️⃣1️⃣
😍 新人:首存500即送68$
😍 反水:实时领电子反水1.3%起
🩷❤️🧡💛💚🩵💙💜🖤🩶
🌶 实力保障: 链上储备公开可查
🌶代理55%返佣!无套路秒结算
👠麻将1 麻将2 赏金大对决
👠2026首创:PA真人秒提112万U,秒到账
👠秀翻全场: BBIN赌神附体单笔提款125万U
👠运气爆棚:木牌大佬PP电子爆奖90万U
👠拍案叫绝:西港某主管BBIN狂揽115万U
1️⃣1️⃣1️⃣1️⃣1️⃣1️⃣1️⃣1️⃣
😂 官网: KX.TOP
😍 客服:@KXOK8
😍 招商:@KX999
😍 频道:@KXGGG
Please open Telegram to view this post
VIEW IN TELEGRAM
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #templates

📦 项目名称: nuclei-fast-templates
👤 项目作者: reewardius
🛠 开发语言: Unknown
⭐ Star数量: 21 | 🍴 Fork数量: 8
📅 更新时间: 2026-09-25 09:52:14

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored

📦 项目名称: smoothwall-express-dhcp-static-gui-fixes
👤 项目作者: petter5
🛠 开发语言: Perl
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-25 09:45:35

📝 项目描述:
Bug fixes for Smoothwall Express 3.1's DHCP static-assignments GUI (garbled IP/MAC display, a related stored-XSS, and stale Active status), found while running the DHCP-WoL mod.

🔗 点击访问项目地址
Forwarded from 金银
This media is not supported in your browser
VIEW IN TELEGRAM
⚡️⚡️⚡️⚡️😂😂😂😂
2026世界杯官方指定投注平台

➡️ 豪礼大放送、高端嫩模、劳力士手表、奔驰E300 加入 #182体育 等你领取, 电子可拉2万一注

🌐182体育官网: 182268.com
TG玩家首选人民币台 不限ip 免实名免绑卡手机号码

🌐8K国际官网: 8k2769.com
TG玩家首选U台 U存U提出款稳,福利好反水无上限


😀😀😀😀😀😀😀😀😀😀😀😀😀

1.PG电子赏金女王一举斩获830万并成功提现
2
.PA真人豪赢644万一路长虹一天实现暴富
3
.PG电子爆890万并以成功提现实现财富自由
4
.大哥在PA真人百家乐累计盈利突破1000万

🔤🔤🔤🔤 以及C币,K豆,OKpay、👌微信,👌支付宝,银行卡等30多种存取款方式,通畅便捷

大额出款额外奖励8888-128888,双重日存彩金128888+4688每日送,周流水彩金68888每周送,双重签到彩金16888+3888送不停

😅😏😃😃🙃😢😅😚😍😀😏😝
【 182体育 全网独此一家】
公平、公正、公开、 信誉第一、服务第一
不限ip、 免实名、免绑卡、免绑手机号码

🤩🤩🤩🤩🤩🤩🤩🤩🤩🤩🤩🤩
官方频道: @vip182ty
体育推荐:
@tytj182ty
专属客服:
@vipkf_182ty
双向联系:
@vipkf_182ty_bot


🌐 8K国际网址:
8k2769.com
🌐182体育网址:
182268.com
Please open Telegram to view this post
VIEW IN TELEGRAM
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #RCE

📦 项目名称: Kestra-cve-2026-53576
👤 项目作者: AtlasVector
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-25 10:24:11

📝 项目描述:
End-to-end reproduction and cross-layer detection of CVE-2026-53576, the unauthenticated RCE in Kestra — taken past the base PoC to show how a common Docker-socket misconfiguration turns container-root into full host compromise.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Spring #CVE

📦 项目名称: watchdog
👤 项目作者: impressionistic-permeation7619
🛠 开发语言: TypeScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-25 11:00:15

📝 项目描述:
Automate OSINT data collection and case management with machine-driven monitoring and human-in-the-loop decision making.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: VulnScan
👤 项目作者: hacksudo
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-25 10:39:46

📝 项目描述:
A powerful, containerized Web Vulnerability Scanner featuring industry-standard security tools (Nmap, Nikto, SSLScan, TestSSL). Fully packaged into a self-contained Docker deployment that sets up in seconds.

🔗 点击访问项目地址