Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
Shockwave-OSS — 精选的漏洞赏金技巧、单行命令和自动化工作流合集,涵盖侦察、模糊测试和 Web 漏洞利用,并包含私有 Nuclei 模板与 HackerOne 报告要点。 | Kitploit
工具/GitHubGitHub/gal-nagli/shockwave-oss
侦察漏洞分析Web应用程序漏洞利用信息收集WAF绕过Web安全模糊测试渗透测试秘密检测子域名枚举学习与教育精选资源
753135262年前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
GitHubgal-nagli/shockwave-oss

Shockwave-OSS

精选的漏洞赏金技巧、单行命令和自动化工作流合集,涵盖侦察、模糊测试和 Web 漏洞利用,并包含私有 Nuclei 模板与 HackerOne 报告要点。

查看仓库

BountyTricks

分享 Bug Bounty 技巧和诀窍,包括但不限于自动化、单行命令和实用思路

目录

💂‍♂️ 杂项

正则表达式验证器

同形字攻击生成器

Shodan-Scripts

HTTP 头部

MIME 类型

反向代理

Writeups

HTTP 请求走私

  • Github 本地侦察 - 用法:gitsecrets “word” | gf pattern
gitsecrets(){
{ find .git/objects/pack/ -name "*.idx"|while read i;do git show-index < "$i"|awk '{print $2}';done;find .git/objects/ -type f|grep -v '/pack/'|awk -F'/' '{print $(NF-1)$NF}'; }|while read o;do git cat-file -p $o;done|grep -E "$1"
}
  • 对多个文件使用 ffuf
ffuf -u URL/FUZZ -w allipstoffuf:URL -w ~/.config/wordlists/envpath:FUZZ -maxtime 300 -t 500 -c -v

💂‍♂️ 私有 Nuclei 模板

  • SSRF nuclei 模板 - 自动提供端点以探测 SSRF 交互,该模块尝试对提供的输入发起简单交互,随后将常见的 SSRF 查询参数附加到原始请求中。

示例:

echo "https://checkout.stripe.com/api/color?image_url=" | nuclei -t ssrf.yaml 

nuclei_ssrf

实战中的技巧与诀窍

  • 通过更改协议(scheme)绕过 WAF:
http://web.com/?XSSendpoint ===> no WAF
https://web.com/?XSSendpoint ===> WAF implemented

子域名侦察

根域名

  • Google Dorks:
Root Domains - "org" subsidiaries
intext: credit company
  • Amass
1. Get company's ASN numbers - amass intel -org DoD
2. Turn ASN numbers into CIDR - whois -h whois.radb.net -- "-i origin $asn" | grep -Eo "([0-9.]+){4}/[0-9]+" | sort -u >> $recondir/cidr
3. Get TLDS from ASN - amass intel -asn $asn
4. Get TLDS from whois data - amass intel -whois -d TLD (facebook.com)
5. Get TLDS from CIDR - amass intel -cidr xxxxxx/23
  • CIDR 转主机名
prips 144.160.32.0/19 | hakrevdns  -d | httpx -title -status-code -follow-redirects

💂‍ H1 已公开报告分析

  • GraphQL API 端点上的 ReDoS - 利用正则炸弹(Regex BOMB)瘫痪服务器 CPU。
Takeaway : FUZZ with certain characters such as \u0000 to try and trigger ReGeX verbose errors
  • 工单技巧 - 能够使用 [email protected] 注册,系统通过向 [email protected] 发送邮件创建支持工单,验证邮件最终到达了他的账户。
Takeaway: If a company won't require email address verification and will automatically generate support tickets, try and sign up with [email protected]
  • 由于 authenticity_token 未被验证导致 CSRF - authenticity_token 具有固定值且未经过验证,导致易受 CSRF 攻击,进而可在 shopify 上接管组织。
Takeaway: whenever authenticity_token is presented on requests validate if the value is being processed in the back-end.
  • 通过构造的载荷实现应用级 DoS - POST 请求中的 "name" 参数在输入 (((((()0))))) 时导致崩溃。
Takeaway: try (((((()0))))) when fuzzing post requests.
  • steam id cookie 上的 IDOR - 使用带有受害者 steamid cookie 值的 POST 请求,以受害者的身份执行了操作
Takeaway: Swap identifyable cookie values between lateral accounts.
  • Bitbucket 公共仓库凭据泄露
Takeaway: Look through org's public repos for Bitbucket content
  • 通过 POST 请求的 "month" 参数实现 Java RCE - month 参数存在代码注入漏洞,可使用以下载荷:1${T(java.lang.System).getenv()}
Takeaway: When Fuzzing java application to try and insert code injection queries like ${T(java.lang.System).getenv()}
  • 添加尾随空格导致 SSO 接管 - 在组织名称后添加尾随空格,当用户尝试认证时该空格会被修剪
Takeaway: When supplying org name check what is the behaviour with adding " " (space) on it's name
  • 通过附加端口号实现主机头缓存投毒导致 DoS
Takeaway: Tampering with the host header with situations who involve caching, can append port to the host to cause DOS
  • Firebase API 链接缩短密钥在 JS 文件中泄露
Takeaway: Go through the "main.slug.js" files and look for API Keys, this one looks like the google maps one (AI....)
  • 开放的 S3 存储桶泄露所有上传的图片
Takeaway: Look for websites who has bucket like https://s3.amazonaws.com/BUCKETNAME and try to run aws s3 ls BUCKETNAME
  • 由于 6 位 OTP 没有速率限制,可重置任意密码
Takeaway: Check each step of reset password phase who might not be protected with rate limiting, this could even be a third step after clicking an email, allowing to skip phase 2.
  • 管理员密码暴露在 JavaScript 源文件中
Takeaway: on Admin / custom made login panels check the source code to determine if there are some leaks including password.
  • 通过 image 参数实现 SSRF

  • 通过 "features" GET 参数实现 SQL 注入 - 绕过 WAF

Takeaway: %27||/**/(case%20when(/*%c3*/length/*%c3*/(user)=5)then/**/(1)else(1/0)end)||%27
  • OAuth 流程中的开放重定向
Takeaway: Change the scope parameter to arbitrary file and see if the redirect_url will redirect to external domain

免责声明

这里展示的部分单行命令或数据可能来自其他仓库,并经过我的修改。我只分享我在过去一年中经常使用或遇到的内容。如果你在这里发现任何最初由你制作的内容,请告诉我,我会注明来源。

下载工具