Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
Exploits — Exploits 作者:1N3 @CrowdShield @xer0dayz @XeroSecurity | Kitploit
工具/GitHubGitHub/1n3/exploits
漏洞利用框架漏洞分析漏洞利用Web应用程序漏洞利用CTF渗透测试
GitHub1n3/exploits

Exploits

Exploits 作者:1N3 @CrowdShield @xer0dayz @XeroSecurity

查看仓库
2081014年前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
网站

由 @xer0dayz @Sn1perSecurity 开发的漏洞利用合集 https://sn1persecurity.com

  • Vulnserver.exe GMON SEH Overflow Exploit
  • FreeFloat FTP Server HOST Buffer Overflow (ASLR Bypass)
  • CoolPlayer+ Portable 2.19.6 Stack Overflow (ASLR Bypass)
  • HTTPoxy Exploit/PoC Scanner
  • Ability FTP 2.34 Buffer Overflow Exploit
  • Aruba AP-205 Buffer Overflow Denial of Service PoC
  • Brainpan1 CTF Buffer Overflow Exploit
  • CesarFTP 0.99g Buffer Overflow Exploit
  • Apache 2.2.x Range Header Denial of Service Exploit
  • GHOST Glibc Gethostbyname Buffer Overflow Exploit
  • PHP Serialization Injection Remote Code Execution Exploit
  • CrikeyConCTF Koala Gallery Exploit
  • Webmin 1.920 Unauthenticated RCE Metasploit Exploit

漏洞赏金主页

  • https://bugcrowd.com/1N3
  • https://hackerone.com/1N3

公开漏洞利用

  • https://packetstormsecurity.com/files/author/1N3/
  • https://www.exploit-db.com/?author=7787
  • https://vulners.com/search?query=1N3

博客

  • https://sn1persecurity.com/wordpress/blog/
  • https://crowdshield.com/blog.php
  • https://treadstonesecurity.blogspot.ca

社交媒体

  • https://twitter.com/xer0dayz
  • https://twitter.com/sn1persecurity
  • https://twitter.com/crowdshield
  • https://youtube.com/crowdshield
  • https://youtube.com/sn1persecurity

网站

  • https://sn1persecurity.com
  • https://crowdshield.com

公开漏洞利用/PoC/CVE/漏洞赏金/CTF

2018年:

  • 收录于 Hackin9 杂志 - 开源黑客工具特辑 (https://hakin9.org/download/open-source-hacking-tools/) 2018年8月
  • Jetty 6.1.6 跨站脚本(XSS) (https://seclists.org/fulldisclosure/2018/Aug/15) (Full Disclosure) 2018年8月
  • 上榜 DoD Defense Travel System 名人堂 2018年6月
  • 获得 BugCrowd 2018 年 MVP 研究名单预选资格 (https://www.bugcrowd.com/bugcrowd-mvps-april-edition/) 2018年4月
  • CVE-2018-8917 Synology-SA-18:14 - DSM 6.1.5-15254 中的反射型 XSS (https://www.synology.com/en-us/security/advisory/Synology_SA_18_14) 2018年3月
  • CVE-2018-6545 Ipswitch MoveIt v8.1 存储型跨站脚本(XSS) (https://www.exploit-db.com/exploits/43947) 2018年2月
  • Illustra IP Cameras 多个跨站脚本(XSS)漏洞(600 美元赏金) 2018年2月
  • Illustra IP Cameras 目录遍历漏洞(800 美元赏金) 2018年2月
  • Illustra IP Cameras 远程命令执行漏洞(900 美元赏金) 2018年2月
  • 上榜 BugCrowd 2017 年 MVP 研究人员名单 (https://www.bugcrowd.com/today-we-recognize-our-2017-mvp-researchers/) 2018年1月

2017年:

  • 获得 Offensive Security 认证专家(OSCE)认证 2017年12月
  • WEMO HomeKit Bridge 多个跨站请求伪造(CSRF)漏洞(3,000 美元赏金) 2017年9月
  • WEMO HomeKit Bridge 存储型跨站脚本(XSS)漏洞(500 美元赏金) 2017年9月
  • WEMO HomeKit Android 应用程序存在系统性存储型 XSS 漏洞(1,500 美元赏金) 2017年9月
  • DEMO HomeKit Android 应用程序存在系统性本地文件包含漏洞(3,000 美元赏金) 2017年9月
  • 在 ToorConCTF CTF 中获得第 7 名 2017年8月
  • ModSecurity App for Splunk 存储型 XSS(Full Disclosure) 2017年8月
  • PSPDFKit/Atlassian Jira Cloud Android 应用存在目录遍历漏洞(Bug Bounty) 2017年7月
  • 获得 SecurityTube 颁发的 Android Security For Penetration Testers(ASFP)认证 2017年5月
  • 在 ISSA/OWASP Phoenix 向 90 多名与会者发表题为 "Man In The Browser Advanced Client Side Exploitation" 的演讲 (https://www.slideshare.net/1N3/man-in-the-browser-advanced-client-side-exploitation-using-beef) 2017年4月
  • PSV-2017-0227: NETGEAR Arlo 跨站跟踪漏洞 CVE 2017年2月
  • NETGEAR M4300-8X8F 交换机存在目录遍历 + 多个 CSRF + 多个存储型和反射型 XSS 漏洞(3,000+ 美元赏金) 2017年3月
  • 因 Hack The Army 漏洞赏金计划获得美国国防部 HackerOne 挑战纪念币 2017年2月
  • 上榜 BugCrowd 2016 年 MVP 名单 2017年1月

2016年:

  • 在 BugCrowd 的 Operation Code CTF 中获得第 3 名 2016年9月
  • 在 @DEFCON CMD+CTRL CTF 中获得第 1 名 2016年8月
  • HTTPoxy 漏洞利用扫描器 Exploit/PoC 2016年7月
  • CVE-2016-1034 Zabbix SQL 注入 0day (www.cvedetails.com/cve/CVE-2016-10134/) 2016年7月
  • CVE-2016-4401 Aruba ClearPass 未授权数据库凭据泄露(1,500 美元赏金) (https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2016-010.txt) 2016年6月
  • 在 BugCrowd Operation Code CTF 中并列第 2 名 2016年6月
  • 进入 BugCrowd 前 10 名研究人员名单 2016年6月
  • 在 CactusCon 2016 RootTheBox CTF 中获得第 2 名 2016年5月
  • 在 BugCrowd 全球排行榜漏洞赏金中排名第 19 位 2016年5月
  • Charts 4 PHP 1.2.3 跨站脚本(Full Disclosure) (https://packetstormsecurity.com/files/135666/Charts-4-PHP-1.2.3-Cross-Site-Scripting.html) 2016年2月
  • Open Web Analytics 1.5.7 跨站脚本(Full Disclosure) (https://packetstormsecurity.com/files/135948/Open-Web-Analytics-1.5.7-Cross-Site-Scripting.html) 2016年2月
  • WordPress All In One SEO Pack 2.2.2 跨站脚本(Full Disclosure) 2016年2月
  • PSV-2016-0127: NETGEAR R7800 路由器目录遍历 0day (https://kb.netgear.com/000053136/Security-Advisory-for-Arbitrary-File-Read-on-Some-Routers-and-Gateways-PSV-2016-0127) 2016年1月
  • PSV-2016-0124: NETGEAR R7800 路由器明文提交密码 0day (https://kb.netgear.com/000055105/Security-Advisory-for-Security-Misconfiguration-on-Some-Routers-and-Extenders-PSV-2016-0124) 2016年1月
  • PSV-2016-0116: NETGEAR R7800 路由器拒绝服务(DoS)0day 2016年1月
  • PSV-2016-0136: NETGEAR R7800 路由器不受限制的任意文件上传 0day (https://kb.netgear.com/000049063/Security-Advisory-for-Security-Misconfiguration-Vulnerability-on-R7800-Routers-PSV-2017-0136) 2016年1月
  • PSV-2016-0114: NETGEAR R7800 路由器目录遍历 0day (https://kb.netgear.com/000053135/Security-Advisory-for-Arbitrary-File-Read-on-Some-Routers-and-Gateways-PSV-2016-0114) 2016年1月

2015年:

  • 进入 BugCrowd 前 10 名研究人员名单 2015年11月
  • Wordpress XMLRPC System Multicall 暴力破解漏洞利用(0day) Exploit/PoC 2015年10月
  • Aruba AP-205 远程命令注入漏洞(750 美元赏金) (https://www.youtube.com/watch?v=TZqDkN1NQf4) 2015年10月
  • Apache Range Header 拒绝服务漏洞利用(CVE-2011-3192) Exploit/PoC 2015年8月
  • 入选 AT&T 漏洞赏金名人堂 Bug Bounty (https://bugbounty.att.com/hof.php) 2015年8月
  • 赢得 InfoSec Institute Practical Web CTF #2 挑战赛 (https://resources.infosecinstitute.com/ctf-2-practical-web-hacking-winners/#gref) 2015年8月
  • HP Photosmart 7520 打印机存储型跨站脚本(0day) Exploit/CVE 2015年7月
  • Supermicro IPMI/BMC 明文密码扫描器 Exploit/PoC 2015年3月
  • WebFOCUS 533 Server XSS 与目录遍历漏洞(0day) Exploit/CVE 2015年2月
  • Imgur 服务端请求伪造(SSRF)(1,600 美元赏金) (https://hackerone.com/reports/91816) 2015年1月
  • CVE-2015-0235 GHOST glibc gethostbyname 缓冲区溢出漏洞利用 (https://www.exploit-db.com/exploits/35951) 2015年1月
  • Hak5 Wifi PinnappleV 远程代码执行漏洞利用 Exploit/CVE 2015年1月
  • Hak5 Wifi PinnappleV SSLSplit 跨站脚本漏洞利用 Exploit/CVE 2015年1月

2014年:

  • Lyris ListManagerWeb 8.95a 跨站脚本(Full Disclosure) (https://packetstormsecurity.com/files/127672/Lyris-ListManagerWeb-8.95a-Cross-Site-Scripting.html) 2014年7月
  • MyConnection Server (MCS) 9.7i 跨站脚本(Full Disclosure) (https://0day.today/exploit/description/22526) 2014年7月
  • AlogoSec FireFlow 6.3 跨站脚本(Full Disclosure) (https://packetstormsecurity.com/files/127001/AlogoSec-FireFlow-6.3-Cross-Site-Scripting.html) 2014年7月
  • 获得 Offensive Security 认证专业人员(OSCP)认证 2014年2月
下载工具
  • PSV-2016-0113: NETGEAR R7800 路由器拒绝服务(DoS)0day 2016年1月
  • PSV-2016-0131: NETGEAR R7800 路由器服务端请求伪造 0day (https://kb.netgear.com/000053137/Security-Advisory-for-Security-Misconfiguration-on-Some-Routers-and-Gateways-PSV-2016-0131) 2016年1月