mr-xn/penetration_testing_poc

渗透测试有关的POC、EXP、脚本、提权、小工具等---About penetration-testing python-script poc getshell csrf xss cms php-getshell domainmod-xss csrf-webshell cobub-razor cve rce...

View on GitHub ↗Jump to charts ↓

Summary Information

Updated 39 minutes ago
Added to GitGenius on September 8th, 2026
Created on July 24th, 2019
Open Issues & Pull Requests: 0 (+0)
GitHub issues: Enabled
Number of forks: 2,039
Total Stargazers: 7,487 (+0)
Total Subscribers: 247 (+0)

Repository Insights (GitGenius)

Median issue/PR response: 0.0 hours
Mean response time: 26.3 days
90th percentile: 52.5 days
Tracked items: 2

Most active contributors

Sign in to see contributor activity.

Related repositories by overlapping contributors

Charts & Analytics

Fetching additional details & charts...

Issue Activity (beta)

Open issues: 0
New in 7 days: 0
Closed in 7 days: 0
Avg open age: N/A days
Stale 30+ days: 0
Stale 90+ days: 0

Recent activity

Opened in 7 days: 0
Closed in 7 days: 0
Comments in 7 days: 0
Events in 7 days: 0

Top labels

No label distribution available yet.

Most active issues this week

No issue events were indexed in the last 7 days.

Detailed Description

Penetration_Testing_POC is a collection repository that aggregates proof-of-concept exploits, scripts, and tools for penetration testing activities.

The repository serves as a centralized reference for security researchers and penetration testers by gathering POCs, exploitation scripts, privilege escalation techniques, and related tools in one place. It organizes content across multiple categories including IoT devices, mobile phones, web applications, privilege escalation utilities, and PC-based exploits. The approach is fundamentally a curated index rather than a framework or tool that performs operations itself; users search through the collection to find relevant exploits and techniques applicable to their testing scenarios.

This repository is most useful for penetration testers who need quick access to known exploits and POCs across a broad range of vulnerability types and target systems. It suits practitioners working with web applications, OA systems, CMS platforms, and IoT devices who want a single reference point rather than hunting across multiple sources. The collection covers specific vulnerability classes including SQL injection, cross-site scripting, cross-site request forgery, remote code execution, and authentication bypass techniques. The README explicitly warns that all tools should be verified for backdoors or malicious behavior and recommends running them only in isolated virtual environments, reflecting the inherent risks of using third-party exploit code from public sources.

The project maintains an active collection model where content is regularly added and supplemented by contributors. The repository structure is organized by target category and vulnerability type, making it navigable through search functionality. Development activity shows ongoing curation and expansion of the POC collection across multiple exploit categories and target platforms.