​📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
​⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSTI #RCE

📦 项目名称: Learn-SecByte-DNS-SSTI-XXE-RCE-Web-Security-CTF-Labs
👤 项目作者: sifatnotes
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-29 05:47:03

📝 项目描述:
Hands-on cybersecurity and CTF labs covering DNS and subdomain discovery, RCE, template injection, SSTI-to-root, authentication reconnaissance, credential trails, stream investigation, XXE file leaks, XML-based attacks, and hosts-file hijacking.

🔗 点击访问项目地址 GitHub - sifatnotes/Learn-SecByte-DNS-SSTI-XXE-RCE-Web-Security-CTF-Labs: Hands-on cybersecurity and CTF labs covering DNS and…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSTI #RCE

📦 项目名称: SuperSecretTip-TryHackMe-Walkthrough
👤 项目作者: anurag-rvnkr1
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-23 07:35:28

📝 项目描述:
Professional TryHackMe SuperSecretTip walkthrough covering source-code disclosure, XOR secret reconstruction, SSTI, RCE, Linux lateral movement, PATH hijacking, cron abuse, and root-context curl configuration exploitation. Flags redacted for portfolio-safe documentation.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSTI #RCE #POC

📦 项目名称: serena-ssti-poc
👤 项目作者: amagesh1
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-18 18:48:25

📝 项目描述:
PoC for GHSA-pp25-4cg4-qcr9 — Serena Agent SSTI → RCE (serena-agent <= 1.6.1)

🔗 点击访问项目地址 GitHub - amagesh1/serena-ssti-poc: PoC for GHSA-pp25-4cg4-qcr9 — Serena Agent SSTI → RCE (serena-agent <= 1.6.1)
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSTI #RCE

📦 项目名称: calyteinfra-vuln-lab
👤 项目作者: VanishaParwal
🛠 开发语言: JavaScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-18 12:16:15

📝 项目描述:
Intentionally vulnerable Node/Express injection training lab (SQLi, NoSQLi, cmd injection, XSS, SSTI, XXE, LDAP injection, CRLF injection) with matching fixed routes. Local use only.

🔗 点击访问项目地址 GitHub - VanishaParwal/calyteinfra-vuln-lab: Intentionally vulnerable Node/Express injection training lab (SQLi, NoSQLi, cmd injection…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSTI #RCE

📦 项目名称: House-of-Liquor
👤 项目作者: Samriddha-Sapkota
🛠 开发语言: HTML
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-17 16:24:59

📝 项目描述:
A deliberately vulnerable Flask web application built on Jinja2 to demonstrate SQL injection and Server-Side Template Injection (SSTI) via nmap, Gobuster, and tplmap to identify and exploit injection flaws.

🔗 点击访问项目地址 GitHub - Samriddha-Sapkota/House-of-Liquor: A deliberately vulnerable Flask web application built on Jinja2 to demonstrate SQL…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSTI #RCE

📦 项目名称: vulnhub-web
👤 项目作者: oxihash
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-13 19:46:13

📝 项目描述:
A chained multi-service vulnerable web app: SSRF into an internal-trust bypass, leaked JWT secret, forged admin auth, and SSTI-to-RCE, fully automated end to end.

🔗 点击访问项目地址 GitHub - oxihash/vulnhub-web: A chained multi-service vulnerable web app: SSRF into an internal-trust bypass, leaked JWT secret…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSTI #模板注入

📦 项目名称: sstiscan
👤 项目作者: 485961590
🛠 开发语言: Go
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-10 13:41:30

📝 项目描述:
sstiscan 是一个基于 Go 1.24+ 的服务端模板注入(SSTI,Server-Side Template Injection)检测引擎,面向 Flask/Jinja2 目标的授权安全测试。它通过「随机基线标记 + 动态算术探针 + 过滤绕过升级 + 上下文比对 + 证据评分」判断参数是否被模板引擎求值,并输出结构化结果;标准语法被 WAF/过滤规则拦截时,自动以无害语法变体逐层重试并标注绕过路径。

🔗 点击访问项目地址 485961590/sstiscan
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSTI #RCE

📦 项目名称: SSTI-Lab
👤 项目作者: ManuelKy08
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-09 07:21:23

📝 项目描述:
Laboratorium Server-Side Template Injection (SSTI) to RCE untuk pembelajaran - Flask/Jinja2: direct render, WAF blacklist bypass, string concat injection, blind time-based oracle. Payload terverifikasi + goal baca flag.txt. Localhost only.

🔗 点击访问项目地址 GitHub - ManuelKy08/SSTI-Lab: Laboratorium Server-Side Template Injection (SSTI) to RCE untuk pembelajaran - Flask/Jinja2: direct…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSTI #RCE

📦 项目名称: GEARHEART-CTF
👤 项目作者: sac-exe
🛠 开发语言: CSS
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-09 05:38:44

📝 项目描述:
A multi-stage web exploitation CTF challenge combining session hijacking, SSTI, RCE and RSA cryptography.

🔗 点击访问项目地址 GitHub - sac-exe/GEARHEART-CTF: A multi-stage web exploitation CTF challenge combining session hijacking, SSTI, RCE and RSA cryptography.
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSTI #RCE

📦 项目名称: web8-ssti-scan
👤 项目作者: 5h4d0wn1k
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-08 07:43:08

📝 项目描述:
5h4d0wn1k cybersecurity tool - AUTHORIZED USE ONLY. Educational/own-lab. MIT.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSTI #POC

📦 项目名称: SSTI-VULNE
👤 项目作者: fadilsyhptra
🛠 开发语言: HTML
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-05 07:12:42

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - fadilsyhptra/SSTI-VULNE
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSTI #RCE

📦 项目名称: desync-saml-orm-ssti-chain
👤 项目作者: MalikHettige
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-05 07:44:53

📝 项目描述:
Operational research on the modern multi-stage chain

🔗 点击访问项目地址 GitHub - MalikHettige/desync-saml-orm-ssti-chain: Operational research on the modern multi-stage chain
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSTI #RCE

📦 项目名称: SSTIMAP
👤 项目作者: ShashankD210
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-26 11:35:08

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - ShashankD210/SSTIMAP
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSTI #RCE

📦 项目名称: noteforge-greeting-template-rce
👤 项目作者: pentestinghere-labs
🛠 开发语言: PHP
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-26 12:18:41

📝 项目描述:
PentestingHere Academy lab: unsandboxed Twig SSTI to RCE

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSTI #RCE

📦 项目名称: SSTImap
👤 项目作者: vladko312
🛠 开发语言: Python
⭐ Star数量: 1620 | 🍴 Fork数量: 185
📅 更新时间: 2026-08-25 23:04:17

📝 项目描述:
Automatic SSTI detection tool with interactive interface

🔗 点击访问项目地址 GitHub - vladko312/SSTImap: Automatic SSTI detection tool with interactive interface
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSTI #RCE

📦 项目名称: burpsuite-ai-pentest-extension
👤 项目作者: kim-kimani
🛠 开发语言: Python
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-20 14:00:31

📝 项目描述:
AI-powered Burp Suite extension for automated web app penetration testing. DeepSeek-driven payload generation, vulnerability detection (SQLi, XSS, SSRF, SSTI, XXE, RCE), scope-aware traffic capture, findings database, and HTML/CSV reporting, for authorized pentesting & Application Security Works..

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSTI #RCE

📦 项目名称: SSTI-CHECKER
👤 项目作者: ebrahimgh21
🛠 开发语言: Python
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-16 23:28:04

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - ebrahimgh21/SSTI-CHECKER
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSTI #RCE

📦 项目名称: PipePwned---Writeup
👤 项目作者: baheandiego07
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 04:40:09

📝 项目描述:
PipePwned es un laboratorio que simula un entorno CI/CD vulnerable, donde se explota una cadena de vulnerabilidades que incluyen IDOR, SSTI, fuga de información y escalada de privilegios mediante Poisoned Pipeline Execution (PPE) en un runner self-hosted de GitLab.

🔗 点击访问项目地址 GitHub - baheandiego07/PipePwned---Writeup: PipePwned es un laboratorio que simula un entorno CI/CD vulnerable, donde se explota…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSTI #RCE

📦 项目名称: sentinelhub
👤 项目作者: JinBaiWansec
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 05:47:46

📝 项目描述:
OSWE-style white-box web exploitation lab. A Flask monitoring app with chained RCE paths buried in normal business logic — practice source-code review.

🔗 点击访问项目地址 GitHub - JinBaiWansec/sentinelhub: OSWE-style white-box web exploitation lab. A Flask monitoring app with chained RCE paths buried…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSTI #RCE

📦 项目名称: ssti-labs
👤 项目作者: Caxtiq
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 14:34:04

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - Caxtiq/ssti-labs
 
 
Back to Top