Commit Graph
1962 Commits
Author SHA1 Message Date
copilot-swe-agent[bot] 3f2cbeb8bf docs: add PrismSpace link to README 2026-06-01 13:53:55 +00:00
github-actions[bot] 68be5653c5 docs: 更新 1 篇文章 - 孚盟云CRM Inquiry.aspx SQL注入漏洞 [skip ci] 2026-06-01 04:50:49 +00:00
github-actions[bot] a6d696d4d2 docs: 更新 1 篇文章 - 孚盟云CRM LoadMailAttachFile.aspx 任意文件读取/移动 [skip ci] 2026-05-31 04:21:31 +00:00
dependabot[bot]anddependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> db7fbca5ab Bump urllib3 from 1.26.5 to 2.7.0 in /discuz-ml-rce (#61)
Bumps [urllib3](https://github.com/urllib3/urllib3) from 1.26.5 to 2.7.0.
- [Release notes](https://github.com/urllib3/urllib3/releases)
- [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst)
- [Commits](https://github.com/urllib3/urllib3/compare/1.26.5...2.7.0)

---
updated-dependencies:
- dependency-name: urllib3
  dependency-version: 2.7.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-29 11:51:50 +08:00
Copilotandcopilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com> 65db36acea docs: add TongWeb exploit and plugin links to README (#69)
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
2026-05-29 11:51:18 +08:00
Copilot 68fff2a2db Add CIFSwitch link to Linux privilege escalation section in README (#68) 2026-05-29 10:15:36 +08:00
Copilotcopilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>Mr-xn
ad9d7a3adc docs: add Copy-Fail Kubernetes PoC link to CVE-2026-31431 entries (#66)
Agent-Logs-Url: https://github.com/Mr-xn/Penetration_Testing_POC/sessions/4adc4e93-692f-48d6-9e33-701e8aed23ca

Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: Mr-xn <18260135+Mr-xn@users.noreply.github.com>
2026-05-25 16:17:25 +08:00
Copilotcopilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>Mr-xn
87cce6fcf9 Add CACM (Linux权限维持+后渗透工具) to 提权辅助相关 section in README.md (#65)
Agent-Logs-Url: https://github.com/Mr-xn/Penetration_Testing_POC/sessions/822e18e0-a2c4-4caa-805a-66703dc4e9c1

Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: Mr-xn <18260135+Mr-xn@users.noreply.github.com>
2026-05-23 08:31:34 +08:00
github-actions[bot] 12ce4a2f7b docs: 更新 1 篇文章 - 用友 NC 系统 IMsgCenterWebService SQL注入漏洞 [skip ci] 2026-05-18 04:11:16 +00:00
Copilotcopilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>Mr-xn
05eeb7c991 docs: add zenproxy link to proxy tools list (#63)
Agent-Logs-Url: https://github.com/Mr-xn/Penetration_Testing_POC/sessions/4ce03e50-871c-425d-bb00-862c9e382d83

Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: Mr-xn <18260135+Mr-xn@users.noreply.github.com>
2026-05-17 10:38:18 +08:00
Copilot 95422f6c72 docs: Add CVE-2026-34621 (Adobe Acrobat SSRF/JS injection) and CVE-2026-44578 (Next.js WebSocket SSRF) PoC links (#62) 2026-05-16 10:29:08 +08:00
github-actions[bot] e420f060fe docs: 更新 1 篇文章 - 孚盟云CRM BusiPriceOkPrint.aspx SQL注入漏洞 [skip ci] 2026-05-14 03:54:14 +00:00
github-actions[bot] f13cf8ec96 docs: 更新 1 篇文章 - 孚盟云CRM BusinessPriceReport.aspx SQL注入漏洞 [skip ci] 2026-05-13 03:54:47 +00:00
github-actions[bot] 82a8f01e3c docs: 更新 1 篇文章 - 孚盟云CRM BusinessPriceOk.aspx SQL注入漏洞 [skip ci] 2026-05-12 03:45:37 +00:00
github-actions[bot] dc14de9c3b docs: 更新 1 篇文章 - 天地伟业Easy7 /Easy7/rest/user/getAuthorityByUserId SQL注入漏洞 [skip ci] 2026-05-11 04:02:00 +00:00
github-actions[bot] 881fc93d7c docs: 更新 1 篇文章 - 天地伟业Easy7 /Easy7/rest/user/IsPermissible SQL注入漏洞 [skip ci] 2026-05-10 03:51:38 +00:00
CopilotMr-xncopilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
d25071d77d Add Dirty Frag to the Linux privilege escalation section in README (#60)
* Add dirtyfrag to README

Agent-Logs-Url: https://github.com/Mr-xn/Penetration_Testing_POC/sessions/44248c1a-9d5a-402f-ba64-9036e779bf70

Co-authored-by: Mr-xn <18260135+Mr-xn@users.noreply.github.com>

* Fix Linux privilege escalation label in README

Agent-Logs-Url: https://github.com/Mr-xn/Penetration_Testing_POC/sessions/44248c1a-9d5a-402f-ba64-9036e779bf70

Co-authored-by: Mr-xn <18260135+Mr-xn@users.noreply.github.com>

---------

Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: Mr-xn <18260135+Mr-xn@users.noreply.github.com>
2026-05-09 22:51:06 +08:00
github-actions[bot] 80cab04226 docs: 更新 1 篇文章 - 天地伟业Easy7 /Easy7/rest/user/getAuthorityByUserId SQL注入漏洞 [skip ci] 2026-05-09 03:35:51 +00:00
github-actions[bot] 4622982057 docs: 更新 1 篇文章 - 天地伟业Easy7 /Easy7/rest/file/download 文件读取漏洞 [skip ci] 2026-05-08 03:35:42 +00:00
github-actions[bot] bff8f1fe13 docs: 更新 1 篇文章 - 天地伟业Easy7 /Easy7/rest/file/deleteFile 文件删除漏洞 [skip ci] 2026-05-07 03:41:32 +00:00
github-actions[bot] 806f6470b1 docs: 更新 1 篇文章 - 天地伟业Easy7 /Easy7/rest/file/uploadFile 文件上传漏洞 [skip ci] 2026-05-06 03:41:59 +00:00
Copilot 70006014fc docs: add Pentest-Swarm-AI to README tools section (#59) 2026-05-03 12:16:56 +08:00
Copilotcopilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>Mr-xn
793ee1744a docs: add GBitsTools, GbitsGen, ghost-bits-lab, BLACKHAT_Asia2026 to README (#58)
Agent-Logs-Url: https://github.com/Mr-xn/Penetration_Testing_POC/sessions/0849d964-f623-4c6b-ba08-14871344023b

Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: Mr-xn <18260135+Mr-xn@users.noreply.github.com>
2026-05-01 14:11:12 +08:00
github-actions[bot] db611dcf17 docs: 更新 1 篇文章 - 孚盟云CRM BusinessPriceListList.aspx SQL注入漏洞 [skip ci] 2026-05-01 03:54:57 +00:00
东方有鱼名为咸 46e8295c0b add Asia-26-Bai-Cast-Attack-Ghost-Bits-4.23.pdf
Update README with RSS / update-readme (push) Has been cancelled
2026-04-30 20:44:55 +08:00
CopilotMr-xncopilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>东方有鱼名为咸
e0a901b72a Add Java Ghost Bits (Black Hat Asia 2026) links to IOT section (#57)
* add Cast Attack Ghost Bits links to IOT section in README

Agent-Logs-Url: https://github.com/Mr-xn/Penetration_Testing_POC/sessions/2e561877-1b4a-42d6-bac7-b9c5b95a091e

Co-authored-by: Mr-xn <18260135+Mr-xn@users.noreply.github.com>

* Update README with new links and resources

* Update README with new CVE links and descriptions

---------

Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: Mr-xn <18260135+Mr-xn@users.noreply.github.com>
Co-authored-by: 东方有鱼名为咸 <Mr-xn@users.noreply.github.com>
2026-04-30 20:23:42 +08:00
github-actions[bot] eb74e0c978 docs: 更新 1 篇文章 - 孚盟云CRM BusinessPrice.aspx SQL注入漏洞 [skip ci] 2026-04-30 03:42:16 +00:00
github-actions[bot] 0451098613 docs: 更新 1 篇文章 - 孚盟云CRM ClientNameCard.aspx SQL注入漏洞 [skip ci] 2026-04-29 03:40:54 +00:00
github-actions[bot] 9dc3e13da4 docs: 更新 1 篇文章 - 孚盟云CRM CustomizeReportSelectMould.aspx SQL注入漏洞 [skip ci] 2026-04-28 03:43:08 +00:00
github-actions[bot] 40804140d2 docs: 更新 1 篇文章 - 天地伟业Easy7 /Easy7/rest/file/uploadIdsHttpFile SSRF+文件写入漏洞 [skip ci] 2026-04-27 03:38:30 +00:00
github-actions[bot] bba9ddc6ec docs: 更新 1 篇文章 - 天地伟业Easy7 /Easy7/rest/file/downloadFile 文件读取漏洞 [skip ci] 2026-04-26 03:34:37 +00:00
github-actions[bot] 3aa177c891 docs: 更新 1 篇文章 - 天地伟业Easy7 /Easy7/rest/file/delete 文件删除漏洞 [skip ci] 2026-04-25 02:56:06 +00:00
github-actions[bot] abc6deb9f8 docs: 更新 1 篇文章 - 天地伟业Easy7 uploadLedImage 文件上传漏洞 [skip ci] 2026-04-24 03:27:41 +00:00
github-actions[bot] 3ba9403508 docs: 更新 1 篇文章 - 天地伟业Easy7 capture 命令执行漏洞 [skip ci] 2026-04-23 03:25:20 +00:00
github-actions[bot] b530c68d19 docs: 更新 1 篇文章 - 天地伟业Easy7 getConfigInfoList SQL注入漏洞 [skip ci] 2026-04-22 03:21:56 +00:00
github-actions[bot] d68b23a952 docs: 更新 1 篇文章 - 天地伟业Easy7 isHashCameraAuth SQL注入漏洞 [skip ci] 2026-04-21 03:23:23 +00:00
Copilot 6568d59c42 Add UnDefend Windows Defender DOS tool to README after RedSun entry (#56)
Update README with RSS / update-readme (push) Has been cancelled
2026-04-20 19:35:42 +08:00
github-actions[bot] a94ecb72f9 docs: 更新 1 篇文章 - V2Board 信息泄露漏洞至权限绕过接管账户(CVE-2026-39912)分析复现 [skip ci] 2026-04-20 03:31:46 +00:00
github-actions[bot] d1d9dfa08f docs: 更新 1 篇文章 - 天地伟业Easy7 getInquestRoomChannelInfo SQL注入漏洞 [skip ci] 2026-04-19 03:29:25 +00:00
Copilot 99c6ce643e Add raptor to tools section in README (#55) 2026-04-19 10:16:40 +08:00
东方有鱼名为咸 af1242f9a2 Add link to ultimate code audit checklist
Update README with RSS / update-readme (push) Has been cancelled
2026-04-18 21:24:11 +08:00
Copilot cbaa44afc6 docs: 补充 CVE-2026-0827 和 BlueSAM 到 README (#54)
Update README with RSS / update-readme (push) Has been cancelled
README.md 新增 2 条工具/漏洞链接
1. 提权辅助相关 章节末尾新增
CVE-2026-0827(ZeroMemoryEx/CVE-2026-0827)
Lenovo LdeApi.Server.exe 无模拟写文件本地提权漏洞
低权限用户可创建 NTFS junction,使服务以 SYSTEM 权限向任意位置写文件
归类于 Windows 本地提权漏洞
2. tools 工具集 章节(BOF-RegSave 条目之后)新增
BlueSAM(incursi0n/BlueSAM)
BlueHammer 的 Cobalt Strike Beacon Object File (BOF) 移植版
利用 Windows Defender 更新/VSS 行为获取 SAM 数据库副本
可在 Beacon 中直接离线解析注册表数据,获取系统凭据
2026-04-18 11:07:56 +08:00
github-actions[bot] 0d086bdec4 docs: 更新 1 篇文章 - 天地伟业Easy7 getInquestIdByRoomId SQL注入漏洞 [skip ci] 2026-04-18 02:54:11 +00:00
github-actions[bot] d6cb39a114 docs: 更新 1 篇文章 - 天地伟业Easy7 GetOtherDomainServer.jsp SSRF漏洞 [skip ci] 2026-04-17 03:22:35 +00:00
Copilot cb896221ac Add RedSun Windows Defender privilege escalation link to README (#53) 2026-04-17 09:49:25 +08:00
github-actions[bot] 582a9726a7 docs: 更新 1 篇文章 - mdserver-web(夸父面板)≤0.18.4 多处未授权访问 + 信息泄露 + RCE 漏洞分析 [skip ci] 2026-04-16 14:01:47 +00:00
github-actions[bot] 2dfb62b8f5 docs: 更新 1 篇文章 - 天地伟业Easy7 UploadOwnerImage.jsp 文件上传漏洞 [skip ci] 2026-04-16 03:27:45 +00:00
Copilotcopilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>Mr-xn
e23ed5b544 Add anything-analyzer to tools section in README (#52)
Agent-Logs-Url: https://github.com/Mr-xn/Penetration_Testing_POC/sessions/0d7c52b9-4dce-4210-bb28-f0d780fbaee4

Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: Mr-xn <18260135+Mr-xn@users.noreply.github.com>
2026-04-15 22:48:42 +08:00
CopilotMr-xncopilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
213bb5caaa Add nano-analyzer and Tomcat JMX→RCE resources to README (#51)
* Add nano-analyzer and Tomcat JMX Proxy RCE resources to README

Agent-Logs-Url: https://github.com/Mr-xn/Penetration_Testing_POC/sessions/10587f92-8a1b-4275-bb6b-c0472d2e5efd

Co-authored-by: Mr-xn <18260135+Mr-xn@users.noreply.github.com>

* Append jmx2rce exploit tool link to existing Tomcat JMX entry in README

Agent-Logs-Url: https://github.com/Mr-xn/Penetration_Testing_POC/sessions/0084ec9b-4dfc-4ef7-83f6-9b35c9422faa

Co-authored-by: Mr-xn <18260135+Mr-xn@users.noreply.github.com>

---------

Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: Mr-xn <18260135+Mr-xn@users.noreply.github.com>
2026-04-15 16:35:17 +08:00
github-actions[bot] c9c71cecd6 docs: 更新 1 篇文章 - 天地伟业Easy7 queryRoomConfigs SQL注入漏洞 [skip ci] 2026-04-15 03:19:27 +00:00