本软件首先集成危害性较大前台rce(无需登录,或者登录绕过执行rce)。反序列化(利用链简单)。上传getshell。sql注入等高危漏洞直接就可以拿权限出数据。其次对一些构造复杂exp漏洞进行检测。傻瓜式导入url即可实现批量测试,能一键getshell检测绝不sql注入或者不是只检测。其中thinkphp 集成所有rce Exp Struts2漏洞集成了shack2 和k8 漏洞利用工具所有Exp并对他们的exp进行优化和修复此工具的所集成漏洞全部是基于平时实战中所得到的经验从而写入到工具里。例如:通达oA一键getshell实战测试 struts2一键getshell 等等
仓库
superalsrk 的仓库
source code reading
Obsidian Notebook: AI Infra
Must-read papers on recommendation systems (RecSys)
Claude Code's Source Code & Breakdown from a leaked map file in their NPM registry
some archetypes for springboot
Docker hosts and containers monitoring with Prometheus, Grafana, cAdvisor, NodeExporter and AlertManager
Free HTML email templates for Mailchimp and other emails services
Hexo tag for embeded pdf
JuiceFS is a distributed POSIX file system built on top of Redis and S3.
Enhanced koa2 boilerplate in ES7 with Babel http://koa2-boilerplate.tarax.cn/
Manus code from container
Persian version of Ruby Ghost theme
Pytorch 中文文档
SpringBoot practice
Stackbox's Blog using hexo
Distributed transactional key-value database, originally created to complement TiDB
translate a webpage