📦 GitHub 全球红队渗透资源中转站。
旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒
🚨 发现关键词: #SSTI #RCE
📦 项目名称: Learn-SecByte-DNS-SSTI-XXE-RCE-Web-Security-CTF-Labs
👤 项目作者: sifatnotes
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-29 05:47:03
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #SSTI #RCE
📦 项目名称: Learn-SecByte-DNS-SSTI-XXE-RCE-Web-Security-CTF-Labs
👤 项目作者: sifatnotes
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-29 05:47:03
📝 项目描述:
Hands-on cybersecurity and CTF labs covering DNS and subdomain discovery, RCE, template injection, SSTI-to-root, authentication reconnaissance, credential trails, stream investigation, XXE file leaks, XML-based attacks, and hosts-file hijacking.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #SSTI #RCE
📦 项目名称: SuperSecretTip-TryHackMe-Walkthrough
👤 项目作者: anurag-rvnkr1
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-23 07:35:28
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #SSTI #RCE
📦 项目名称: SuperSecretTip-TryHackMe-Walkthrough
👤 项目作者: anurag-rvnkr1
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-23 07:35:28
📝 项目描述:
Professional TryHackMe SuperSecretTip walkthrough covering source-code disclosure, XOR secret reconstruction, SSTI, RCE, Linux lateral movement, PATH hijacking, cron abuse, and root-context curl configuration exploitation. Flags redacted for portfolio-safe documentation.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #SSTI #RCE
📦 项目名称: calyteinfra-vuln-lab
👤 项目作者: VanishaParwal
🛠 开发语言: JavaScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-18 12:16:15
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #SSTI #RCE
📦 项目名称: calyteinfra-vuln-lab
👤 项目作者: VanishaParwal
🛠 开发语言: JavaScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-18 12:16:15
📝 项目描述:
Intentionally vulnerable Node/Express injection training lab (SQLi, NoSQLi, cmd injection, XSS, SSTI, XXE, LDAP injection, CRLF injection) with matching fixed routes. Local use only.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #SSTI #RCE
📦 项目名称: House-of-Liquor
👤 项目作者: Samriddha-Sapkota
🛠 开发语言: HTML
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-17 16:24:59
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #SSTI #RCE
📦 项目名称: House-of-Liquor
👤 项目作者: Samriddha-Sapkota
🛠 开发语言: HTML
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-17 16:24:59
📝 项目描述:
A deliberately vulnerable Flask web application built on Jinja2 to demonstrate SQL injection and Server-Side Template Injection (SSTI) via nmap, Gobuster, and tplmap to identify and exploit injection flaws.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #SSTI #RCE
📦 项目名称: vulnhub-web
👤 项目作者: oxihash
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-13 19:46:13
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #SSTI #RCE
📦 项目名称: vulnhub-web
👤 项目作者: oxihash
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-13 19:46:13
📝 项目描述:
A chained multi-service vulnerable web app: SSRF into an internal-trust bypass, leaked JWT secret, forged admin auth, and SSTI-to-RCE, fully automated end to end.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #SSTI #模板注入
📦 项目名称: sstiscan
👤 项目作者: 485961590
🛠 开发语言: Go
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-10 13:41:30
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #SSTI #模板注入
📦 项目名称: sstiscan
👤 项目作者: 485961590
🛠 开发语言: Go
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-10 13:41:30
📝 项目描述:
sstiscan 是一个基于 Go 1.24+ 的服务端模板注入(SSTI,Server-Side Template Injection)检测引擎,面向 Flask/Jinja2 目标的授权安全测试。它通过「随机基线标记 + 动态算术探针 + 过滤绕过升级 + 上下文比对 + 证据评分」判断参数是否被模板引擎求值,并输出结构化结果;标准语法被 WAF/过滤规则拦截时,自动以无害语法变体逐层重试并标注绕过路径。🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #SSTI #RCE
📦 项目名称: SSTI-Lab
👤 项目作者: ManuelKy08
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-09 07:21:23
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #SSTI #RCE
📦 项目名称: SSTI-Lab
👤 项目作者: ManuelKy08
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-09 07:21:23
📝 项目描述:
Laboratorium Server-Side Template Injection (SSTI) to RCE untuk pembelajaran - Flask/Jinja2: direct render, WAF blacklist bypass, string concat injection, blind time-based oracle. Payload terverifikasi + goal baca flag.txt. Localhost only.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #SSTI #RCE
📦 项目名称: GEARHEART-CTF
👤 项目作者: sac-exe
🛠 开发语言: CSS
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-09 05:38:44
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #SSTI #RCE
📦 项目名称: GEARHEART-CTF
👤 项目作者: sac-exe
🛠 开发语言: CSS
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-09 05:38:44
📝 项目描述:
A multi-stage web exploitation CTF challenge combining session hijacking, SSTI, RCE and RSA cryptography.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #SSTI #RCE
📦 项目名称: web8-ssti-scan
👤 项目作者: 5h4d0wn1k
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-08 07:43:08
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #SSTI #RCE
📦 项目名称: web8-ssti-scan
👤 项目作者: 5h4d0wn1k
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-08 07:43:08
📝 项目描述:
5h4d0wn1k cybersecurity tool - AUTHORIZED USE ONLY. Educational/own-lab. MIT.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #SSTI #POC
📦 项目名称: SSTI-VULNE
👤 项目作者: fadilsyhptra
🛠 开发语言: HTML
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-05 07:12:42
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #SSTI #POC
📦 项目名称: SSTI-VULNE
👤 项目作者: fadilsyhptra
🛠 开发语言: HTML
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-05 07:12:42
📝 项目描述:
无描述🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #SSTI #RCE
📦 项目名称: desync-saml-orm-ssti-chain
👤 项目作者: MalikHettige
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-05 07:44:53
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #SSTI #RCE
📦 项目名称: desync-saml-orm-ssti-chain
👤 项目作者: MalikHettige
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-05 07:44:53
📝 项目描述:
Operational research on the modern multi-stage chain🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #SSTI #RCE
📦 项目名称: SSTIMAP
👤 项目作者: ShashankD210
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-26 11:35:08
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #SSTI #RCE
📦 项目名称: SSTIMAP
👤 项目作者: ShashankD210
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-26 11:35:08
📝 项目描述:
无描述🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #SSTI #RCE
📦 项目名称: noteforge-greeting-template-rce
👤 项目作者: pentestinghere-labs
🛠 开发语言: PHP
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-26 12:18:41
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #SSTI #RCE
📦 项目名称: noteforge-greeting-template-rce
👤 项目作者: pentestinghere-labs
🛠 开发语言: PHP
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-26 12:18:41
📝 项目描述:
PentestingHere Academy lab: unsandboxed Twig SSTI to RCE🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #SSTI #RCE
📦 项目名称: burpsuite-ai-pentest-extension
👤 项目作者: kim-kimani
🛠 开发语言: Python
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-20 14:00:31
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #SSTI #RCE
📦 项目名称: burpsuite-ai-pentest-extension
👤 项目作者: kim-kimani
🛠 开发语言: Python
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-20 14:00:31
📝 项目描述:
AI-powered Burp Suite extension for automated web app penetration testing. DeepSeek-driven payload generation, vulnerability detection (SQLi, XSS, SSRF, SSTI, XXE, RCE), scope-aware traffic capture, findings database, and HTML/CSV reporting, for authorized pentesting & Application Security Works..🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #SSTI #RCE
📦 项目名称: SSTI-CHECKER
👤 项目作者: ebrahimgh21
🛠 开发语言: Python
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-16 23:28:04
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #SSTI #RCE
📦 项目名称: SSTI-CHECKER
👤 项目作者: ebrahimgh21
🛠 开发语言: Python
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-16 23:28:04
📝 项目描述:
无描述🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #SSTI #RCE
📦 项目名称: PipePwned---Writeup
👤 项目作者: baheandiego07
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 04:40:09
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #SSTI #RCE
📦 项目名称: PipePwned---Writeup
👤 项目作者: baheandiego07
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 04:40:09
📝 项目描述:
PipePwned es un laboratorio que simula un entorno CI/CD vulnerable, donde se explota una cadena de vulnerabilidades que incluyen IDOR, SSTI, fuga de información y escalada de privilegios mediante Poisoned Pipeline Execution (PPE) en un runner self-hosted de GitLab.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #SSTI #RCE
📦 项目名称: sentinelhub
👤 项目作者: JinBaiWansec
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 05:47:46
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #SSTI #RCE
📦 项目名称: sentinelhub
👤 项目作者: JinBaiWansec
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 05:47:46
📝 项目描述:
OSWE-style white-box web exploitation lab. A Flask monitoring app with chained RCE paths buried in normal business logic — practice source-code review.🔗 点击访问项目地址