awesome-repositories.com
博客
MCP
awesome-repositories.com

通过 AI 驱动的搜索,发现最优秀的开源仓库。

探索精选搜索开源替代品自托管软件博客网站地图
项目MCP 服务器关于排名机制媒体报道
法律隐私政策服务条款
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
zhzyker avatar

zhzyker/exphub

0
View on GitHub↗
4,282 星标·1,082 分支·Python·11 次浏览

Exphub

Exphub 是一个 CVE 利用脚本库和企业软件漏洞套件,旨在验证和利用 WebLogic、Struts2、Tomcat 和 JBoss 等服务器环境中的已知安全漏洞。它作为一个远程代码执行工具包和 Web Shell 部署框架,用于触发未经授权的命令执行并在远程系统上建立持久访问。

该项目包含用于内网侦察的专用工具,特别是利用服务端请求伪造(SSRF)来扫描开放端口和服务。它还提供了绕过访问控制以及执行未经授权的文件读取和上传的机制。

该套件涵盖了广泛的功能领域,包括漏洞评估、渗透测试以及执行概念验证(PoC)脚本以确认安全漏洞的存在。

Features

  • Remote Code Execution Tools - Provides a toolkit designed to achieve and manage arbitrary code execution on remote target systems.
  • Vulnerability Proofs of Concept - Provides a library of executable proof-of-concept scripts to demonstrate the exploitability of specific CVEs.
  • Port Scanning - Identifies active hosts and open services on internal networks by leveraging SSRF vulnerabilities.
  • Port Scanning Tools - Identifies open ports and network services within internal networks using server-side request forgery.
  • Proof Of Concept Exploits - Maintains a collection of security research and functional exploit code for various CVEs.
  • Software Vulnerability Exploits - Provides a library of proof-of-concept exploits targeting enterprise server environments.
  • Vulnerability Exploitation Frameworks - Provides a framework for detecting and exploiting security flaws in middleware and application frameworks.
  • Web Application Exploits - Employs specialized payloads to verify web-layer vulnerabilities and gain unauthorized server access.
  • Web Shells - Deploys web shells to compromised servers to establish persistent remote access and command control.
  • Web Shell Executions - Deploys scripts on compromised servers to create permanent HTTP interfaces for remote command execution.
  • Deployment Frameworks - Provides a framework for uploading and establishing persistent web-based backdoors on remote compromised systems.
  • Remote Command Execution - Triggers unauthorized arbitrary command execution on target systems by leveraging deserialization or plugin flaws.
  • Deserialization Exploits - Implements attacks that execute arbitrary commands via serialized object reconstruction in server environments.
  • Exploit Payload Deployments - Ships mechanisms for transferring and executing offensive exploit payloads on remote target systems.
  • Network Vulnerability Scanning - Uses server-side request forgery to identify open ports and services on a local network.
  • Penetration Testing Frameworks - Provides an automated framework for discovering and exploiting security weaknesses in enterprise software.
  • Proof of Concept Execution - Runs curated proof-of-concept scripts to verify and exploit security flaws across various software environments.
  • Web Shells - Uploads and executes a script on a remote server to establish persistent access and command control.
  • Vulnerability Detection - Checks target servers for known remote command execution vulnerabilities using proof-of-concept scripts.
  • Command Injection Exploiters - Automates the exploitation of command injection vulnerabilities to execute arbitrary commands on target servers.
  • Vulnerability Exploits - Executes proof-of-concept exploits to confirm the presence of security flaws in server environments like JBoss.
  • Port Scanners - Identifies open network ports and services by leveraging server-side request forgery.
  • Access Control Bypasses - Implements mechanisms to modify credentials or exploit privilege escalation to gain unauthorized entry.
  • Automated Vulnerability Detection - Scans target URLs to automatically identify security weaknesses and known vulnerabilities in web services.
  • Path Traversal Exploits - Provides capabilities to read sensitive system files by escaping directory constraints via path manipulation.
  • Remote Code Execution Testing - Analyzes target software to detect vulnerabilities that allow an attacker to execute arbitrary remote code.
  • SSRF-Based Reconnaissance - Includes specialized utilities to scan internal network ports and services using server-side request forgery.
  • Network Reconnaissance Tools - Scans internal networks to identify active services and potential entry points using SSRF.
  • Directory Traversal Exploits - Accesses sensitive files from target servers by exploiting path traversal and unauthorized reading flaws.
  • Arbitrary File Uploads - Provides capabilities to upload unauthorized files to remote servers to achieve remote code execution.
  • Security References - Repository of exploit proof-of-concepts.
  • Vulnerability Exploitation - Centralized repository for various application server exploits.

Star 历史

zhzyker/exphub 的 Star 历史图表zhzyker/exphub 的 Star 历史图表

AI 搜索

探索更多 awesome 仓库

用简单的语言描述您的需求 —— AI 将根据相关性为您从数千个精选开源项目中进行排序。

Start searching with AI

Exphub 的开源替代方案

相似的开源项目,按与 Exphub 的功能重合度排序。
  • jaykali/maskphishjaykali 的头像

    jaykali/maskphish

    3,020在 GitHub 上查看↗

    Maskphish is a comprehensive security toolkit that integrates capabilities for digital forensics, network vulnerability scanning, open-source intelligence, penetration testing, and social engineering. It functions as a multi-purpose framework for automating reconnaissance and executing security audits across diverse network environments. The project features a specialized phishing and social engineering toolkit used for cloning websites, masking URLs, and deploying deceptive pages to capture user credentials. It also includes a remote access Trojan builder for generating platform-specific exe

    Shellhackhackinghacking-tool
    在 GitHub 上查看↗3,020
  • k8gege/k8toolsk8gege 的头像

    k8gege/K8tools

    6,167在 GitHub 上查看↗

    K8tools is a multi-stage attack framework that combines memory-only payload execution, credential testing, port forwarding, privilege escalation, and physical USB-based keystroke injection for comprehensive system compromise. At its core, the Ladon PowerShell module loads a multi-function scanner directly into memory, enabling command execution without writing files to disk, while supporting memory-only payload delivery that downloads and runs obfuscated shellcode or PowerShell commands to evade antivirus detection. The framework distinguishes itself through its breadth of integrated capabili

    PowerShell0daybrute-forcebypass
    在 GitHub 上查看↗6,167
  • projectdiscovery/naabuprojectdiscovery 的头像

    projectdiscovery/naabu

    5,766在 GitHub 上查看↗

    Naabu is a port scanner library and tool that probes hosts for open ports using SYN, CONNECT, and UDP methods to identify active services. It functions as a Go library for embedding port scanning into programs, and as a standalone tool that accepts targets as hostnames, IP addresses, CIDR ranges, or ASN numbers. The tool discovers live hosts before scanning, filters ports by range or top lists, and can integrate with Nmap for service version detection. The project distinguishes itself through its SYN-based port probing approach that sends TCP SYN packets and analyzes responses without complet

    Gocdn-exclusionhacktoberfestnmap
    在 GitHub 上查看↗5,766
  • andresriancho/w3afandresriancho 的头像

    andresriancho/w3af

    4,850在 GitHub 上查看↗

    w3af is a web penetration testing suite and security audit framework designed to identify and exploit vulnerabilities in web applications. It functions as a vulnerability scanner that crawls targets to find injection points and a fuzzer used to discover hidden endpoints and test input validation. The project distinguishes itself by providing an intercepting HTTP proxy for capturing and modifying traffic, combined with a knowledge-base driven exploitation system. It enables the execution of security exploits to gain remote shell access and supports post-exploitation activities, such as routing

    Pythonappseccross-site-scriptingscanner
    在 GitHub 上查看↗4,850
查看 Exphub 的所有 30 个替代方案→

常见问题解答

zhzyker/exphub 是做什么的?

Exphub 是一个 CVE 利用脚本库和企业软件漏洞套件,旨在验证和利用 WebLogic、Struts2、Tomcat 和 JBoss 等服务器环境中的已知安全漏洞。它作为一个远程代码执行工具包和 Web Shell 部署框架,用于触发未经授权的命令执行并在远程系统上建立持久访问。

zhzyker/exphub 的主要功能有哪些?

zhzyker/exphub 的主要功能包括:Remote Code Execution Tools, Vulnerability Proofs of Concept, Port Scanning, Port Scanning Tools, Proof Of Concept Exploits, Software Vulnerability Exploits, Vulnerability Exploitation Frameworks, Web Application Exploits。

zhzyker/exphub 有哪些开源替代品?

zhzyker/exphub 的开源替代品包括: jaykali/maskphish — Maskphish is a comprehensive security toolkit that integrates capabilities for digital forensics, network… k8gege/k8tools — K8tools is a multi-stage attack framework that combines memory-only payload execution, credential testing, port… projectdiscovery/naabu — Naabu is a port scanner library and tool that probes hosts for open ports using SYN, CONNECT, and UDP methods to… andresriancho/w3af — w3af is a web penetration testing suite and security audit framework designed to identify and exploit vulnerabilities… hackerschoice/thc-tips-tricks-hacks-cheat-sheet — This project is a comprehensive command-line reference and toolkit designed for Linux system administration and… google/tsunami-security-scanner — Tsunami Security Scanner is a network vulnerability scanner and security auditor designed to identify high-severity…