Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

订阅源联系隐私© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
area51 — The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a dashboard you control, and it gets whatever response you choose in return. | Kitploit
工具/GitHubGitHub/thoropass-public/area51
ExploitationWeb Application ExploitationAPI Security TestingInformation GatheringPenetration TestingCloud SecurityEmail Security
GitHubthoropass-public/area51

area51

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a dashboard you control, and it gets whatever response you choose in return.

查看仓库
62942天前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
内容在请求的语言中不可用。显示英文版本。
AREA 51 exploit server by Thoropass

Every callback, captured.

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a dashboard you control, and it gets whatever response you choose in return.

License Runs on Cloudflare Node MCP

Getting started · Playbooks · CLI · Architecture · Documentation

⚠️ For authorized security testing and research only. A black hole is a live, internet-reachable catch-all: everything a target sends it is stored, and it serves back whatever you configure. Only point targets you have explicit, written authorization to test at it, and treat every deployment as client-data storage. Test only what you are authorized to test.


Why it exists

Half of what you find on an engagement only proves itself when something calls home. A blind SSRF. An XXE that exfiltrates over HTTP. A stored XSS firing in an admin's browser you will never see. A password-reset flow you need to read. An OAuth redirect_uri nobody validated. Each one needs infrastructure that is reachable from the target, captures everything, and answers exactly how you want.

Public interaction services give you a hostname and a log. AREA 51 gives you the whole thing, on infrastructure you own:

  • Nothing shared. Your domains, your storage, your captures. No third party holds your clients' tokens, reset links or internal hostnames.
  • Any response you like. A 302 into a metadata endpoint, a DTD, a .js beacon, a JSON stub, a 25 MB binary. Per exact path.
  • Email is a first-class capture. Every address at the domain is live, and every message is kept verbatim, headers and attachments included.
  • Your agent can drive it. An MCP server exposes recent captures and a sandboxed slice of the endpoint table, so an AI agent can inject a callback URL and confirm the hit without you in the loop.
  • One command to stand up, one to tear down. No servers, no containers, no cron host, and no bill at pentest volumes.

Released early, on purpose. AREA 51 began as an internal tool for a small, trusted team, so it favors simplicity over hardening and scale. Expect rough edges. If you hit one, open an issue with repro steps. Contributions are welcome; see CONTRIBUTING.md.

The three pieces

AREA 51 · the dashboard

Configure endpoints, read captured requests and email, manage noise filters. Locked behind single sign-on with an emailed one-time PIN.

Black Holes · your domains

Every path serves what you defined, and every request and every address at the domain is captured. Public by necessity, because targets have to reach it.

Autopilot · the agent interface

A key-authenticated MCP + REST server. Reads the last hour of callbacks, stages its own response stubs, and cannot touch anything else.

Drive it from an agent 🆕

Cool and easy: Autopilot exposes an MCP server (with a REST mirror) so an authorized AI agent can run the loop itself mid-engagement, without you in the middle of it. It reads the last hour of callbacks, stages its own response stub under the fenced /-/* namespace, and confirms the hit. Every operator gets their own API key, and it is sandboxed: it can never read your files, or any endpoint outside /-/. → Autopilot internals

What it looks like

AREA 51 Home Endpoints
Captured requests Captured email

What you can do with it

下载工具