update vuln and tools

This commit is contained in:
Mrxn
2023-05-27 20:36:50 -07:00
parent 5a6dd04646
commit f9a272d88b
+25
View File
@@ -62,6 +62,8 @@
- [WLAN-AP-WEA453e RCE:三星路由器远程命令执行漏洞](./WLAN-AP-WEA453e%20RCE三星路由器远程命令执行漏洞.md)
- [Buffer overflow in Xiongmai DVRs](https://blog.ret2.me/post/2022-01-26-exploiting-xiongmai-dvrs/)|[备份](https://web.archive.org/web/20221129205148/https://blog.ret2.me/post/2022-01-26-exploiting-xiongmai-dvrs/)
- [CVE-2023-27350: PaperCut NG身份验证绕过导致的RCE](https://github.com/horizon3ai/CVE-2023-27350)
- [ivms-8700-0day-poc: 海康威视iVMS-8700综合安防管理平台任意文件上传漏洞](https://github.com/spmonkey/ivms-8700-0day-poc)
- [badspin: Android Kernel内存错误引用漏洞](https://github.com/0xkol/badspin)
## <span id="head4">Web APP</span>
@@ -303,6 +305,10 @@
- [Alibab-Nacos-Unauthorized-Login: Alibab Nacos <= 2.2.0 未授权访问「默认key生成jwt token」](https://github.com/Al1ex/Alibab-Nacos-Unauthorized-Login)|[Nacos-Authentication-Bypass-Poc ](https://github.com/atk7r/Nacos-Authentication-Bypass-Poc)|[nacos_vul: Nacos身份验证绕过批量检测(QVD-2023-6271)+ 直接添加用户](https://github.com/Pizz33/nacos_vul)
- [CVE-2023-27524: Apache Superset中不安全的默认配置](https://github.com/horizon3ai/CVE-2023-27524)
- [CVE-2023-1671: Sophos Web Appliance 远程命令执行漏洞](https://github.com/W01fh4cker/CVE-2023-1671-POC)
- [CVE-2023-28771-PoC: Zyxel firewalls 命令注入漏洞](https://github.com/BenHays142/CVE-2023-28771-PoC)
- [CVE-2023-25690-POC: Apache HTTP Server 请求走私漏洞](https://github.com/dhmosfunk/CVE-2023-25690-POC)
- [realor-sql-Injection-exp: 瑞友天翼应用虚拟化-远程代码执行/sql注入](https://github.com/hkxueqi/realor-sql-Injection-exp)
- [Apache-Solr-8.3.1-RCE: Apache Solr 8.3.1 admin panel RCE (Windows)](https://github.com/scrt/Apache-Solr-8.3.1-RCE)
## <span id="head5"> 提权辅助相关</span>
@@ -372,6 +378,8 @@
- [【Windows 提权】PetitPotato:通过PetitPotam进行本地提权](https://github.com/wh0Nsq/PetitPotato)
- [LocalPotato:一个使用新potato技术来进行windows本地提权](https://github.com/decoder-it/LocalPotato)
- [EfsPotatoExploit for EfsPotato(MS-EFSR EfsRpcOpenFileRaw with SeImpersonatePrivilege local privalege escalation vulnerability)](https://github.com/zcgonvh/EfsPotato)
- [【Linux 提权】CVE-2023-32233: Linux Kernel 权限提升漏洞](https://github.com/Liuk3r/CVE-2023-32233)
- [【Linux 提权】CVE-2023-0386: Linux OverlayFS权限提升漏洞](https://github.com/veritas501/CVE-2023-0386)
## <span id="head6"> PC</span>
@@ -577,6 +585,10 @@
- [Hades-C2: python开发的C2工具](https://github.com/Lavender-exe/Hades-C2)
- [CVE-2023-27363: Foxit PDF Reader及Editor任意代码执行漏洞](https://github.com/j00sean/SecBugs/tree/main/CVEs/CVE-2023-27363)
- [keepass-password-dumper: CVE-2023-32784 KeePass 信息泄露漏洞](https://github.com/vdohney/keepass-password-dumper)
## <span id="head7"> tools-小工具集版本合</span>
@@ -1777,6 +1789,19 @@
- [frpCracker: 一款golang编写的,批量检测frp server未授权访问、弱token的工具](https://github.com/SleepingBag945/frpCracker)
- [exec2shell: 将PE、ELF或Mach-O可执行文件的TEXT部分提取为shellcode](https://github.com/Binject/exec2shell)
- [unauthorized_com: 未授权检测的命令行版,支持批量检测](https://github.com/xk11z/unauthorized_com)
- [HiddenDesktop: 隐藏桌面,适用于Cobalt Strike使用VNC的时候隐藏桌面操作](https://github.com/WKL-Sec/HiddenDesktop)
- [ProxyPoolxSocks: Socks代理池服务端自动化搭建工具](https://github.com/Anyyy111/ProxyPoolxSocks)
- [npsmodify: ps的魔改,进行了流量特征的魔改,并且进行了漏洞的修复](https://github.com/Q16G/npsmodify)
- [BOFRunPortable: BOF内存运行exe](https://github.com/9bie/BOFRunPortable)
- [SSH-Harvester: 从OpenSSH服务器上自动获取密码](https://github.com/jm33-m0/SSH-Harvester)
- [ChYing: 一款安全工具箱,集成了目录扫描、JWT、Swagger 测试、编/解码、轻量级 BurpSuite、杀软辅助功能](https://github.com/yhy0/ChYing)
- [taiE: 一键getshell集成化工具](https://github.com/1f3lse/taiE)
- [gsocket: 穿透防火墙或NAT进行通信](https://github.com/hackerschoice/gsocket)
- [KeymouseGo: 类似按键精灵的鼠标键盘录制和自动化操作 模拟点击和键入](https://github.com/taojy123/KeymouseGo)
- [ghauri: 类似sqlmap的sql注入自动化利用工具](https://github.com/r0oth3x49/ghauri)
- [weiquan: cs维权插件](https://github.com/kasjhkjaSD/weiquan)
- [cloudSec: 云平台AK/SK-WEB利用工具](https://github.com/libaibaia/cloudSec)
- [udpx: UDPX是一个用Go语言编写的单包UDP扫描器,速度快,重量轻,支持发现超过45个服务,并能添加自定义服务](https://github.com/nullt3r/udpx)
## <span id="head8"> 文章/书籍/教程相关</span>