Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

피드문의개인정보© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
area51 — The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a dashboard you control, and it gets whatever response you choose in return. | Kitploit
도구/GitHubGitHub/thoropass-public/area51
ExploitationWeb Application ExploitationAPI Security TestingInformation GatheringPenetration TestingCloud SecurityEmail Security
GitHubthoropass-public/area51

area51

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a dashboard you control, and it gets whatever response you choose in return.

저장소 보기
62942일 전아직 검토되지 않음

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
요청한 언어로 콘텐츠를 사용할 수 없습니다. 영어 버전을 표시합니다.
AREA 51 exploit server by Thoropass

Every callback, captured.

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a dashboard you control, and it gets whatever response you choose in return.

License Runs on Cloudflare Node MCP

Getting started · Playbooks · CLI · Architecture · Documentation

⚠️ For authorized security testing and research only. A black hole is a live, internet-reachable catch-all: everything a target sends it is stored, and it serves back whatever you configure. Only point targets you have explicit, written authorization to test at it, and treat every deployment as client-data storage. Test only what you are authorized to test.


Why it exists

Half of what you find on an engagement only proves itself when something calls home. A blind SSRF. An XXE that exfiltrates over HTTP. A stored XSS firing in an admin's browser you will never see. A password-reset flow you need to read. An OAuth redirect_uri nobody validated. Each one needs infrastructure that is reachable from the target, captures everything, and answers exactly how you want.

Public interaction services give you a hostname and a log. AREA 51 gives you the whole thing, on infrastructure you own:

  • Nothing shared. Your domains, your storage, your captures. No third party holds your clients' tokens, reset links or internal hostnames.
  • Any response you like. A 302 into a metadata endpoint, a DTD, a .js beacon, a JSON stub, a 25 MB binary. Per exact path.
  • Email is a first-class capture. Every address at the domain is live, and every message is kept verbatim, headers and attachments included.
  • Your agent can drive it. An MCP server exposes recent captures and a sandboxed slice of the endpoint table, so an AI agent can inject a callback URL and confirm the hit without you in the loop.
  • One command to stand up, one to tear down. No servers, no containers, no cron host, and no bill at pentest volumes.

Released early, on purpose. AREA 51 began as an internal tool for a small, trusted team, so it favors simplicity over hardening and scale. Expect rough edges. If you hit one, open an issue with repro steps. Contributions are welcome; see CONTRIBUTING.md.

The three pieces

AREA 51 · the dashboard

Configure endpoints, read captured requests and email, manage noise filters. Locked behind single sign-on with an emailed one-time PIN.

Black Holes · your domains

Every path serves what you defined, and every request and every address at the domain is captured. Public by necessity, because targets have to reach it.

Autopilot · the agent interface

A key-authenticated MCP + REST server. Reads the last hour of callbacks, stages its own response stubs, and cannot touch anything else.

Drive it from an agent 🆕

Cool and easy: Autopilot exposes an MCP server (with a REST mirror) so an authorized AI agent can run the loop itself mid-engagement, without you in the middle of it. It reads the last hour of callbacks, stages its own response stub under the fenced /-/* namespace, and confirms the hit. Every operator gets their own API key, and it is sandboxed: it can never read your files, or any endpoint outside /-/. → Autopilot internals

What it looks like

AREA 51 Home Endpoints
Captured requests Captured email

What you can do with it

도구 다운로드