Github tools
2.73K subscribers
33 photos
2 videos
58 files
361 links
Github useful scripts and tools
Download Telegram
#exploit
1. CVE-2024-42758:
Dokuwiki (indexmenu plugin) XSS
https://github.com/1s1ldur/CVE-2024-42758

2. CVE-2024-36877:
SMM Memory Corruption in MSI firmware
https://jjensn.com/at-home-in-your-firmware
CalcuLatency.pdf
1.3 MB
#Research
"CalcuLatency: Leveraging Cross-Layer Network Latency Measurements to Detect Proxy-Enabled Abuse", 2024.
]-> https://github.com/censoredplanet/calculatency-code
#exploit
1. CVE-2024-7646:
Ingress-NGINX Annotation Validation Bypass
https://www.armosec.io/blog/cve-2024-7646-ingress-nginx-annotation-validation-bypass

2. CVE-2024-38856:
Apache OFBiz Pre-Authentication RCE (Scanner + Exploit)
https://github.com/securelayer7/CVE-2024-38856_Scanner
#tools
#Blue_Team_Techniques
1. ShellSweepX - ML-powered web shell detection and analysis platform
https://github.com/splunk/ShellSweep/wiki/ShellSweepX
2. CVE-2024-38063 mitigation script by disabling ipv6 of all interfaces
https://github.com/diegoalbuquerque/CVE-2024-38063
#exploit
1. CVE-2024-3183:
Kerberos FreeIPA Rosting - Use of Psw Hash With Insufficient Computational Effort
https://github.com/Cyxow/CVE-2024-3183-POC

2. CVE-2024-33895:
Use of Hard-coded Cryptographic Key in Ewon Cosy+ VPN Gateway
https://seclists.org/fulldisclosure/2024/Aug/22
1
#Offensive_security
Ghost in the PPL
Part 1 - BYOVDLL:
https://itm4n.github.io/ghost-in-the-ppl-part-1
Part 2 - From BYOVDLL to Arbitrary Code Execution in LSASS
https://itm4n.github.io/ghost-in-the-ppl-part-2
sync+sync.pdf
1.4 MB
#Research
"Sync+Sync: A Covert Channel Built on fsync with Storage", 2024.
]-> https://github.com/toast-lab/Sync-Sync
👍1
macsec.pdf
17.7 MB
#Research
"Unveiling Mac Security:
A Comprehensive Exploration of Sandboxing and AppData TCC", 2024.
]-> https://github.com/guluisacat/MySlides/tree/main/BlackHatUSA2024_KCon2024
#tools
#OSINT
#WLAN_Security
iSniff GPS - Passive sniffing tool for capturing and visualising WiFi location data disclosed by iOS devices
https://github.com/hubert3/iSniff-GPS
1
SEARCH ENGINES FOR PENTESTERS

01. shodan.io —> (Server , Vulnerabilities)

02. google.com —> (Dorks)

03. wigle.net —> (Wifi Networks)

04. grep.app —> (Codes Search)

05. app.binaryedge.io —> (Threat Intelligence)

06. onyphe.io —> (Server)

07. viz.greynoise.io —> (Threat Intelligence)

08. censys.io —> (Server)

09. hunter.io —> (Email Addresses)

10. fofa.info —> (Threat Intelligence)

11. zoomeye.org —> (Threat Intelligence)

12. leakix.net —> (Threat Intelligence)

13. intelx.io —> (OSINT)

14. app.netlas.io —> (Attack Surface)

15. searchcode.com —> (Code Search)

16. urlscan.io —> (Threat Intelligence)

17. publicwww.com —> (Code Search)

18. fullhunt.io —> (Attack Surface)

19. socradar.io —> (Threat
Intelligence)

20. binaryedge.io —> (Attack Surface)

21. ivre.rocks —> (Server)

22. crt.sh —> (Certificate Search)

23. vulners.com —> (Vulnerabilities)

24. pulsedive.com —> (Threat Intelligence)
1