找到 41 篇与 开源 相关的结果
-
东方商城系统1.8.1版本,开源商城源码 《东方商城系统》1.8.1 正式开源,一套完整可商用的数字商品自动发卡平台,开箱即可搭建卡密售卖、授权售卖、分站分销类商城网站。 一、项目是什么? 东方商城系统是数字商品自动发卡平台。 适合售卖:卡密、会员、软件授权,也可搭建多商户分站平台。 定位:开箱即用的商城网站系统。 二、界面与产品能力 前台(移动端优先,三端自适应:手机 / 平板 / PC) 首页:搜索框、轮播图、分类导航、商品列表 商品详情:规格选择、多支付渠道下单 用户中心:订单管理、余额充值、签到、推广分销、工单提交 后台(LayUI 框架,AJAX 交互,操作流畅) 控制台:销售额统计、趋势图表、支付渠道分布 商品管理:分类管理、商品维护、卡密库存、上架日志、价格波动记录 订单管理:订单列表、订单导出、评价管理 分站管理:多商户分站体系,分站支持独立域名、独立商品 支付管理:支付宝、微信、QQ 钱包、易支付等 8 种支付渠道 对接管理:对接卡速售等第三方平台,一键导入分类与商品 插件商店:云端一键安装插件,内置钩子机制扩展功能 三、开源初衷 项目最初自用,后续陆续交付给朋友与客户。 发现市面上同类发卡系统痛点明显:售价高、代码质量差、闭源难以二次开发。 因此决定开源,方便更多从业者使用,同时欢迎开发者共同参与迭代完善。 四、技术栈 后端:PHP 7.4 ~ 8.0(原生开发,无框架依赖) 数据库:MySQL 5.7+,使用 PDO 预处理防 SQL 注入 前端:后台 LayUI 2.8+;前台 Bootstrap5 + jQuery 支付:8 种支付渠道,异步回调稳定处理订单 安全能力:CSRF 防御、XSS 过滤、SQL 预处理、密码哈希保护 项目特点: 无需 Composer,上传服务器即可使用 自带安装程序,一键部署 单功能独立页面,代码结构清晰,方便二次开发 适配器模式,快速对接第三方商品系统 五、完整核心功能 ✅ 前台功能 移动端优先,手机 / 平板 / PC 三端自适应 商品浏览:分类筛选、搜索、排序 商品下单,支持多规格选择 多渠道支付:支付宝 / 微信 / QQ 钱包 / 易支付 / 余额支付 用户中心:订单查询、余额充值、签到、推广分销、工单 自助开通分站 ✅ 后台功能 数据控制台:销售额、趋势图、支付分布统计 商品管理:分类、商品、卡密库存、价格日志 订单管理:订单列表、导出、评价管理 分站管理:多商户,分站独立域名 支付接口配置,共 8 种支付渠道 第三方商品对接,一键导入商品 营销模块:签到、推广、抽奖、防红 插件商店(钩子机制) 员工账号,精细化权限分配 ✅ 扩展能力 对接卡速售等第三方平台,批量拉取商品 站点克隆:一键复制其他东方商城站点的商品与分类 适配器模式:新增第三方对接只需要编写适配器类 钩子机制:插件注册钩子,灵活扩展业务功能 六、开源协议(MIT) 你可以自由: 免费商用 修改源码 自由分发 闭源部署使用 唯一要求:保留项目原始版权声明。 七、快速部署步骤 下载源码包 上传至服务器,环境要求:PHP7.4+,MySQL5.7+ 访问地址 /install/index.php 根据安装向导完成 4 步安装 登录后台配置,开始使用 八、截图预览 (预留位置:前台首页、商品详情页、用户中心、后台控制台、商品管理页、支付配置页) 九、后续版本规划 新增更多第三方平台对接 扩充插件市场插件数量 开发小程序版本 开放 API 平台 十、关于作者 独立开发者 项目欢迎 Star、Fork、提交 PR;使用过程遇到问题可以提交反馈。 资源下载 隐藏内容,请前往内页查看详情 本资源售价9.9元,购买后即可查看下载地址。如有问题请联系站长。 -
md_blockchain {card-default label="? 项目信息"} ? 项目名称:md_blockchain ? 开发语言:Java ⭐ Star数:3379 | ? Fork数:1388 ? 开源协议:Apache-2.0 ? 项目地址:https://gitee.com/tianyalei/md_blockchain {/card-default} 项目介绍 开源java区块链平台,可做联盟链、私链使用,不适用于公链。各节点已知IP,维持长连接。共识机制采用PBFT。无虚拟货币,可用于存储各种类型的数据,无需挖矿。不仅仅可以用来做账本,还可以做各种定制化的存储需求。理念来自于腾讯的trustsql。加密、公钥私钥、网络模块、存储模块等。 项目详情 京东官方区块链项目JDChain,https://gitee.com/jdchain/jdchain 有研究微服务网关权限的,在网关zuul中对所有下游服务权限做控制,覆盖到所有接口,权限控制到角色、菜单、按钮、方法。基于zuul纯内存的方式,校验时性能无损耗。参考我另一个项目 https://gitee.com/tianyalei/zuulauth 有对多线程并行调度感兴趣的,参考另一个项目 https://gitee.com/jd-platform-opensource/asyncTool 该并发框架支持任意的多线程并行、串行、阻塞、依赖、回调,可以任意组合各线程的执行顺序,还带全链路回调。该项目在京东app后台正在试用,有海量用户、高并发等各种复杂极端场景。是作为Java程序员学习多线程的不可多得的好项目。 有对热key探测功能有需求,毫秒级探测热点数据,毫秒级推送至服务器集群内存,大幅降低热key对数据层查询压力,高性能热key探测中间件hotkey,https://gitee.com/jd-platform-opensource/hotkey。 md_blockchain Java区块链平台,基于Springboot开发的区块链平台。区块链qq交流群737858576,一起学习区块链平台开发,当然也交流Springboot、springcloud、机器学习等知识。 起因 公司要开发区块链,原本是想着使用以太坊开发个合约或者是使用个第三方平台来做,后来发现都不符合业务需求。原因很简单,以太坊、超级账本等平台都是做共享账本的,有代币和挖矿等模块。而我们需要的就是数家公司组个联盟,来共同见证、记录一些不可篡改的交互信息,如A公司给B公司发了一个xxx请求,B公司响应了什么什么。其实要的就是一个分布式数据库,而且性能要好,不能像比特币那种10分钟才生成一个区块。我们要的更多的是数据库的性能,和区块链的一些特性。 经过 项目于18年3月初开始研发,历时一月发布了第一版。主要做了存储模块、加密模块、网络通信、PBFT共识算法、公钥私钥、区块内容解析落地入库等。已经初步具备了区块链的基本特征,但在merkle tree、智能合约以及其他的一些细节上,尚不到位。 希望高手不吝赐教,集思广益,提出见解或方案,来做一个区块链平台项目,适合更多的区块链场景,而不仅仅是账本和各种忽悠人的代币。 理想中的区块链平台: title= 项目说明 主要有存储模块、网络模块、PBFT共识算法、加密模块、区块解析入库等。 该项目属于"链",非"币"。不涉及虚拟币和挖矿。 存储模块 Block内存储的是类Sql语句。联盟间预先设定好符合业务场景需要的数据库表结构,然后设定好各个节点对表的操作权限(ADD,UPDATE,DELETE),将来各个节点就可以按照自己被允许的权限,进行Sql语句的编写,并打包至Block中,再全网广播,等待全网校验签名、权限等信息的合法性。如果Block合法,则进入PBFT共识算法机制,各节点开始按照PrePrepare、Prepare、Commit等状态依次执行,直到2f+1个commit后,开始进行本地生成新区块。新区块生成后,各节点进行区块内容解析,并落地入库的操作。 场景就比较广泛了,可以设定不同的表结构,或者多个表,进而能完成各自类型信息的存储。譬如商品溯源,从生产商、运输、经销商、消费者等,每个环节都可以对某个商品进行ADD信息的操作。 存储采用的是key-value数据库rocksDB,了解比特币的知道,比特币用的是levelDB,都是类似的东西。可以通过修改yml中db.levelDB为true,db.RocksDB为false来动态切换使用哪个数据库。 结构类似于sql的语句,如ADD(增删改) tableName(表名)ID(主键) JSON(该记录的json)。这里设置了回滚的逻辑,也就是当你做了一个ADD操作时,会同时存储一条Delete语句,以用于将来可能的回滚操作。 网络模块 网络层,采用的是各节点互相长连接、断线重连,然后维持心跳包。网络框架使用的是t-io,也是oschina的知名开源项目。t-io采用了AIO的方式,在大量长连接情况下性能优异,资源占用也很少,并且具备group功能,特别适合于做多个联盟链的SaaS平台。并且包含了心跳包、断线重连、retry等优秀功能。 在项目中,每个节点即是server,又是client,作为server则被其他的N-1个节点连接,作为client则去连接其他N-1个节点的server。同一个联盟,设定一个Group,每次发消息,直接调用sendGroup方法即可。 但仍需要注意的是,由于项目采用了pbft共识算法,在达到共识的过程中,会产生N的3次方数量的网络通信,当节点数量较多,如已达到100时,每次共识将会给网络带来沉重的负担。这是算法本身的限制。 共识模块PBFT 分布式共识算法是分布式系统的核心,常见的有Paxos、pbft、bft、raft、pow等。区块链中常见的是POW、POS、DPOS、pbft等。 比特币采用了POW工作量证明,需要耗费大量的资源进行hash运算(挖矿),由矿工来完成生成Block的权利。其他多是采用选举投票的方式来决定谁来生成Block。共同的特点就是只能特定的节点来生成区块,然后广播给其他人。 区块链分如下三类: 私有链:这是指在企业内部部署的区块链应用,所有节点都是可以信任的,不存在恶意节点; 联盟链:半封闭生态的交易网络,存在不对等信任的节点,可能存在恶意节点; 公有链:开放生态的交易网络,为联盟链和私有链等提供全球交易网络。 由于私有链是封闭生态的存储系统,因此采用Paxos类共识算法(过半同意)可以达到最优的性能;联盟链有半公开半开放特性,因此拜占庭容错是适合选择之一,例如IBM超级账本项目;对于公有链来说,这种共识算法的要求已经超出了普通分布式系统构建的范畴,再加上交易的特性,因此需要引入更多的安全考虑。所以比特币的POW是个非常好的选择。 我们这里可选的是raft和pbft,分别做私链和联盟链,项目中我使用了修改过的pbft共识算法。 先来简单了解pbft: (1)从全网节点选举出一个主节点(Leader),新区块由主节点负责生成。 (2)每个节点把客户端发来的交易向全网广播,主节点将从网络收集到需放在新区块内的多个交易排序后存入列表,并将该列表向全网广播。 (3)每个节点接收到交易列表后,根据排序模拟执行这些交易。所有交易执行完后,基于交易结果计算新区块的哈希摘要,并向全网广播。 (4)如果一个节点收到的2f(f为可容忍的拜占庭节点数)个其它节点发来的摘要都和自己相等,就向全网广播一条commit消息。 (5)如果一个节点收到2f+1条(包括自己)commit消息,即可提交新区块到本地的区块链和状态数据库。 (6)客户端收到f + 1个成功(即便有f个失败、再f个恶意返回的错误信息,f + 1个正确的也是多数派)的返回,即可认为该次写入请求是成功的。 可以看到,传统的pbft是需要先选举出leader的,然后由leader来搜集交易,并打包,然后广播出去。然后各个节点开始对新Block进行校验、投票、累积commit数量,最后落地。 而我这里对pbft做了修改,这是一个联盟,各个节点是平等的,而且性能要高。所以我不想让每个节点都生成一个指令后,发给其他节点,再大家选举出一个节点来搜集网络上的指令组合再生成Block,太复杂了,而且又存在了leader节点的故障隐患。 我对pbft的修改是,不需要选择leader,任何节点都可以构建Block,然后全网广播。其他节点收到该Block请求时即进入Pre-Prepare状态,校验格式、hash、签名、和table的权限,校验通过后,进入Prepare状态,并全网广播状态。待自己累积的各节点Prepare的数量大于2f+1时,进入commit状态,并全网广播该状态。待自己累积的各节点Commit的数量大于2f+1时,认为已达成共识,将Block加入区块链中,然后执行Block中sql语句。 很明显,和有leader时相比,缺少了顺序的概念。有leader时能保证Block的顺序,当有并发生成Block的需求时,leader能按照顺序进行广播。譬如大家都已经到number=5的区块了,然后需要再生成2个,有leader时,则会按照6、7的顺序来生成。而没有leader时,则可能发生多节点同时生成6的情况。为了避免分叉,我做了一些处理,具体的可以在代码里看实现逻辑。 区块信息查询 各节点通过执行相同的sql来实现一个同步的sqlite数据库(或mysql等其他关系型数据库),将来对数据的查询都是直接查询sqlite,性能高于传统的区块链项目。 由于各个节点都能生成Block,在高并发下会出现区块不一致的情况。如果因为某些原因导致链分叉了,也提供了回滚机制,sql可以回滚。原理也很简单,你ADD一个数据时,我会在区块里同时记录两个指令,一个是ADD,一个是回滚用的DELETE。同理,UPDATE时也会保存原来的旧数据。区块里的sql落地,譬如顺序执行1-10个指令,回滚时就是从10-1执行回滚指令。 每个节点都会记录自己已经同步了的区块的值,以便随时进行sql落地入库。 对区块链信息的查询,那就简单了,直接做数据库查询即可。相比于比特币需要检索整个区块链的索引树,速度和方便性就大不同了。 简单使用说明 使用方法:先下载md_blockchain_manager项目,然后导入工程里的sql数据库文件,修改application.yml数据库配置,最后启动manager项目。 然后修改md_blockchain中application.yml里的name、appid和manager项目数据库里的某个值对应,作为一个节点。如果有多个节点,则某个节点都和数据库里对应,填写各节点的ip。managerUrl就是manager项目的url,让该项目能访问到manager项目。 在md_blockchian项目启动时,在ClientStarter类中可见,启动时会从manager项目拉取所有节点的数据,并进行连接。如果自己的ip和appId等不在manager数据库中,则无法启动。 可以通过访问localhost:8080/block?content=1来生成一个区块。正常使用时至少要启动4个节点才行,否则无法达成共识,PBFT要求2f+1个节点同意才能生成Block。为了方便测试,可以直接修改pbftSize的返回值为0,这样就能自己一个节点玩起来了。如果有多个节点,在生成Block后就会发现别的节点也会自动同步自己新生成的Block。目前代码里默认设置了一张表message,里面也只有一个字段content,相当于一个简单的区块链记事本。当有4个节点时,可以通过并发访问其中的几个来同时生成Block进行测试,看是否会分叉。还可以关停其中的一个,看其他的三个是否能达成共识(拜占庭最多容许f个节点故障,4个节点允许1个故障),恢复故障的那个,看是否能够同步其他正常节点的Block。可以进行各种测试,欢迎提bug。 可以通过localhost:8080/block/sqlite来查看sqlite里存的数据,就是根据Block里的sql语句执行后的结果。 我把项目部署到docker里了,共启动4个节点,如图: title= manager就是md_blockchain_manager项目,主要功能就是提供联盟链内各节点ip和各节点的权限信息 title= 四个节点ip都写死了,都启动后,它们会相互全部连接起来,并维持住长连接和心跳包,相互交换最新的Block信息。 title= 我调用一下block项目的生成区块接口,http://ip:port/block?content=1,可以看到各节点投票及pbft的各状态 title= 别的节点会是这样,收到block项目请求生成区块的请求、并开始校验,然后进入pbft的投票状态 title= 如果某节点断线了、或者是新加入的节点,从别的正常节点拉取新区块 title= 此外还有高并发情况下,各节点同时生成Block,系统处理共识、保证区块链不分叉的一些测试。 这个生成区块的接口是写好用来测试的,正常走的流程是调用instuction接口,先生产符合自己需求的指令,然后组合多个指令,调用BlockController里的生成区块接口。 ⬇️ 下载地址 {cloud type="default" title="网盘下载" url="https://gitee.com/tianyalei/md_blockchain/repository/archive/master.zip"} 下载后请先检查文件完整性,如有问题请在评论区反馈 -
roncoo-education {card-default label="? 项目信息"} ? 项目名称:roncoo-education ? 开发语言:Java ⭐ Star数:5599 | ? Fork数:2549 ? 开源协议:AGPL-3.0 ? 项目地址:https://gitee.com/roncoocom/roncoo-education {/card-default} 项目介绍 领课教育系统是一套基于点播、直播、考试、题库、任务等功能完善的在线教育系统,开源版是基于商业版精简实现的一个网课网校系统,致力于打造一个各行业都适用的在线培训系统、远程教学平台、学习管理系统、知识付费系统。 项目详情 项目截图 项目截图 项目截图 项目截图 项目截图 项目截图 使用须知 可以用于个人学习、毕业设计、教学案例、公益事业等。 商用限制,若要商用请咨询:18302045627(微信可加)。 禁止将本项目的相关代码和相关资料进行任何形式任何名义的出售。 项目介绍 领课教育系统(roncoo-education)是基于领课网络多年的在线教育平台开发和运营经验打造出来的产品,致力于打造一个各行业都适用的分布式在线教育系统。系统采用前后端分离模式,前台采用vue.js为核心框架,后台采用Spring Cloud为核心框架。系统目前主要功能有课程点播功能,支持多家视频云的接入,课程附件管理功能,支持多家存储云的接入,可以帮助个人或者企业快速搭建一个轻量级的在线教育平台。 目前集成AI写作能力,采用流式输出技术,实时生成课程简介、教学大纲等专业教育内容,显著提升课程内容生产效率和质量,我们会陆续添加更多AI能力,请持续关注。 项目截图 项目截图 项目截图 项目截图 项目截图 项目截图 项目截图 项目截图 项目截图 演示地址 门户系统:https://eduos.roncoos.com/ 管理系统:https://eduos.roncoos.com/admin/ 前端技术体系:Vue3 + Nuxt3 + Vite8 + Vue-Router + Element-Plus + Pinia + Axios 后端技术体系:Spring Cloud Alibaba2025 + MySQL8 + Nacos + Seata + Mybatis + Druid 源码地址 后端系统:roncoo-education(核心框架:Spring Cloud Alibaba):码云 | Github | Gitcode 门户系统:roncoo-education-web(核心框架:Nuxt3):码云 | Github | Gitcode 管理系统:roncoo-education-admin(核心框架:Vue3):码云 | Github | Gitcode 关注微信公众号可获取更多学习资料(SQL脚本、部署教程、常见问题等) 项目截图 ⬇️ 下载地址 {cloud type="default" title="网盘下载" url="https://gitee.com/roncoocom/roncoo-education/repository/archive/master.zip"} 下载后请先检查文件完整性,如有问题请在评论区反馈 -
hertzbeat {card-default label="? 项目信息"} ? 项目名称:hertzbeat ? 开发语言:Java ⭐ Star数:3366 | ? Fork数:1008 ? 开源协议:Apache-2.0 ? 项目地址:https://gitee.com/hertzbeat/hertzbeat {/card-default} 项目介绍 Apache HertzBeat™ 是 AI 驱动的下一代开源实时观测系统。指标日志统一收集,告警一站分发,智能管控分析。无需 Agent,高性能集群,提供强大的自定义监控和状态页构建能力。 项目详情 项目截图 Readme: English | 中文 | 日本語 Discord Reddit Twitter OpenSSF Best Practices codecov Docker Pulls Artifact Hub YouTube Channel Subscribers Contribute with Gitpod 官网: hertzbeat.apache.org 邮件: 发送至 dev-subscribe@hertzbeat.apache.org 订阅邮件列表 ? 介绍 Apache HertzBeat™ 是 AI 驱动的下一代开源实时观测系统。指标日志统一收集,告警一站分发,智能管控分析。无需 Agent,高性能集群,提供强大的自定义监控和状态页构建能力。 特点 集采集+分析+告警+通知为一体,HertzBeat AI 驱动下的新交互与功能,也内置 MCP Server 对外能力。 统一的指标平台,无需 Agent,兼容 Prometheus,支持应用服务,程序,数据库,缓存,操作系统,大数据,中间件,Web 服务器,云原生,网络,自定义等。 统一的日志平台,通过 OTLP 协议多日志源无缝对接上报。 统一的告警平台,内部告警与外部多种告警源集成接入,统一告警处理分析,灵活的实时与周期阈值规则,分组收敛,静默,抑制等。 统一的消息分发,告警平台处理后通过 邮件 Discord Slack Telegram 钉钉 微信 飞书 短信 Webhook Server酱 等方式分发通知。 将 Http, Jmx, Ssh, Snmp, Jdbc, Prometheus 等协议规范可配置化,只需配置模板 YML 就能自定义采集指标。您相信只需简单配置即可快速适配一款 K8s 或 Docker 等新的监控类型吗? 高性能,支持多采集器集群横向扩展,支持多隔离网络监控,云边协同。 提供强大的状态页构建能力,轻松向用户传达您产品服务的实时状态。 HertzBeat的统一平台,AI智能,强大自定义,多类型支持,高性能,易扩展,希望能帮助用户快速方便实现观测需求。? 模块 hertzBeat ⛄ 已支持 我们将监控采集类型(mysql,jvm,k8s)都定义为 yml 模板,用户可以导入这些模板来支持对应类型的监控! 欢迎大家一起贡献你使用过程中自定义的通用指标模板。 Website, Port Telnet, Http Api, Ping Connect, Jvm, SiteMap, Ssl Certificate, SpringBoot2, FTP Server, SpringBoot3, Udp Port, Dns, Pop3, Ntp, Api Code, Smtp, Nginx Mysql, PostgreSQL, MariaDB, Redis, ElasticSearch, SqlServer, Oracle, MongoDB, DM, OpenGauss, ClickHouse, IoTDB, Redis Cluster, Redis Sentinel Doris BE, Doris FE, Memcached, NebulaGraph Linux, Ubuntu, CentOS, Windows, EulerOS, Fedora CoreOS, OpenSUSE, Rocky Linux, Red Hat, FreeBSD, AlmaLinux, Debian Linux Tomcat, Nacos, Zookeeper, RabbitMQ, Flink, Kafka, ShenYu, DynamicTp, Jetty, ActiveMQ, Spring Gateway, EMQX MQTT, AirFlow, Hive, Spark, Hadoop Kubernetes, Docker CiscoSwitch, HpeSwitch, HuaweiSwitch, TpLinkSwitch, H3cSwitch 和更多自定义指标模板。 通知支持 Discord Slack Telegram 邮件 钉钉 微信 飞书 短信 Webhook Server酱。 ? 快速开始 如果您是想将 HertzBeat 部署到内网环境搭建监控系统,请参考下面的部署文档进行操作。 ? HertzBeat 安装 HertzBeat 支持通过源码安装启动,Docker 容器运行和安装包方式安装部署,CPU 架构支持 x86/arm64。方式一:Docker 方式快速安装 docker 环境仅需一条命令即可开始 docker run -d -p 1157:1157 -p 1158:1158 --name hertzbeat apache/hertzbeat 浏览器访问 http://localhost:1157 即可开始,默认账号密码 admin/hertzbeat 部署采集器集群(可选) docker run -d -e IDENTITY=custom-collector-name -e MANAGER_HOST=127.0.0.1 -e MANAGER_PORT=1158 --name hertzbeat-collector apache/hertzbeat-collector -e IDENTITY=custom-collector-name : 配置此采集器的唯一性标识符名称,多个采集器名称不能相同,建议自定义英文名称。 - `-e MODE=public` : 配置运行模式(public or private), 公共集群模式或私有云边模式。 - `-e MANAGER_HOST=127.0.0.1` : 配置连接主 HertzBeat 服务的对外 IP。 - `-e MANAGER_PORT=1158` : 配置连接主 HertzBeat 服务的对外端口,默认1158。 更多配置详细步骤参考 通过 Docker 方式安装 HertzBeat 方式二:通过安装包安装 下载您系统环境对应的安装包 hertzbeat-xx.tar.gz Download 配置 HertzBeat 的配置文件 hertzbeat/config/application.yml (可选) 部署启动 $ ./bin/startup.sh 或 bin/startup.bat 浏览器访问 http://localhost:1157 即可开始,默认账号密码 admin/hertzbeat 部署采集器集群(可选) 下载采集器安装包 hertzbeat-collector-xx.tar.gz 到规划的另一台部署主机上 Download 配置采集器的配置文件 hertzbeat-collector/config/application.yml 里面的连接主 HertzBeat 服务的对外 IP,端口,当前采集器名称(需保证唯一性)等参数 identity mode (public or private) manager-host manager-port collector: dispatch: entrance: netty: enabled: true identity: ${IDENTITY:} mode: ${MODE:public} manager-host: ${MANAGER_HOST:127.0.0.1} manager-port: ${MANAGER_PORT:1158} 启动 $ ./bin/startup.sh 或 bin/startup.bat 浏览器访问主 HertzBeat 服务 http://localhost:1157 查看概览页面即可看到注册上来的新采集器 更多配置详细步骤参考 通过安装包安装HertzBeat 方式三:本地代码启动 此为前后端分离项目,本地代码调试需要分别启动后端工程 hertzbeat-startup 和前端工程 web-app 后端:需要 maven3+, java17 和 lombok 环境,修改 YML 配置信息,添加JVM参数--add-opens=java.base/java.nio=org.apache.arrow.memory.core,ALL-UNNAMED后启动 hertzbeat-startup 服务即可。 前端:需要 nodejs npm angular-cli环境,待本地后端启动后,在 web-app 目录下启动 ng serve --open 浏览器访问 http://localhost:4200 即可开始,默认账号密码 admin/hertzbeat 详细步骤参考 参与贡献之本地代码启动 方式四:Docker-Compose 统一安装 hertzbeat+postgresql+tsdb 通过 Docker-Compose 部署脚本 一次性把 postgresql/mysql 数据库, victoria-metrics/iotdb/tdengine 时序数据库和 hertzbeat 安装部署。 详细步骤参考 通过 Docker-Compose 安装 HertzBeat 方式五:Kubernetes Helm Charts 部署 hertzbeat+collector+postgresql+tsdb 通过 Helm Chart 一次性将 HertzBeat 集群组件部署到 Kubernetes 集群中。 详细步骤参考 Artifact Hub HAVE FUN ✨ Contributors Thanks these wonderful people, welcome to join us: 贡献者指南 项目截图tomsun28? ? ? 项目截图会编程的王学长? ? ?  ⬇️ 下载地址 {cloud type="default" title="网盘下载" url="https://gitee.com/hertzbeat/hertzbeat/repository/archive/master.zip"} 下载后请先检查文件完整性,如有问题请在评论区反馈 -
安卓驿站v2.90开源翻译软件 软件介绍 译站是一款简洁、干净、无广、好用的“一对多”开源翻译软件,支持文本、图片翻译。基于Jetpack Compose编写页面,多引擎同步翻译,提供横向对比选择,支持插件体系,超强可拓展性Material You Design ,适配Android 13,一键调用百度/有道/腾讯等多种翻译引擎同步翻译! 软件安卓驿站v2.90开源翻译软件 图片2 ⬇️ 下载地址 {cloud type="tianyi" title="天翼云盘" url="https://cloud.189.cn/t/qAVne2aayuYn (访问码:2ikm)"} 下载后请先检查文件完整性,如有问题请在评论区反馈 -
rt-thread {card-default label="? 项目信息" /} ? 项目名称:rt-thread ? 开发语言:C ⭐ Star数:5557 | ? Fork数:2276 ? 开源协议:Apache-2.0 ? 项目地址:https://gitee.com/rtthread/rt-thread {/card-default} 项目介绍 RT-Thread是一个来自中国的开源物联网操作系统,它提供了非常强的可伸缩能力:从一个可以运行在ARM Cortex-M0芯片上的极小内核,到中等的ARM Cortex-M3/4/7系统,甚至是多核,64位的ARM Cortex-A,MIPS32/64处理器的功能丰盛系统 项目详情 项目![rt-thread 图片1 English | 中文 | Español | Deutsch GitHubStars GiteeStars GitHub GitHub release Gitter GitHub pull-requests PRs Welcome 简介 RT-Thread诞生于2006年,是一款以开源、中立、社区化发展起来的物联网操作系统。 RT-Thread主要采用 C 语言编写,浅显易懂,且具有方便移植的特性(可快速移植到多种主流 MCU 及模组芯片上)。RT-Thread把面向对象的设计方法应用到实时系统设计中,使得代码风格优雅、架构清晰、系统模块化并且可裁剪性非常好。 RT-Thread有完整版和Nano版,对于资源受限的微控制器(MCU)系统,可通过简单易用的工具,裁剪出仅需要 3KB Flash、1.2KB RAM 内存资源的 NANO 内核版本;而相对资源丰富的物联网设备,可使用RT-Thread完整版,通过在线的软件包管理工具,配合系统配置工具实现直观快速的模块化裁剪,并且可以无缝地导入丰富的软件功能包,实现类似 Android 的图形界面及触摸滑动效果、智能语音交互效果等复杂功能。 RT-Thread架构 RT-Thread是一个集实时操作系统(RTOS)内核、中间件组件的物联网操作系统,架构如下: architecturezh 内核层:RT-Thread内核,是 RT-Thread的核心部分,包括了内核系统中对象的实现,例如多线程及其调度、信号量、邮箱、消息队列、内存管理、定时器等;libcpu/BSP(芯片移植相关文件 / 板级支持包)与硬件密切相关,由外设驱动和 CPU 移植构成。 组件与服务层:组件是基于 RT-Thread内核之上的上层软件,例如虚拟文件系统、FinSH命令行界面、网络框架、设备框架等。采用模块化设计,做到组件内部高内聚,组件之间低耦合。 RT-Thread软件包:运行于 RT-Thread物联网操作系统平台上,面向不同应用领域的通用软件组件,由描述信息、源代码或库文件组成。RT-Thread提供了开放的软件包平台,这里存放了官方提供或开发者提供的软件包,该平台为开发者提供了众多可重用软件包的选择,这也是 RT-Thread生态的重要组成部分。软件包生态对于一个操作系统的选择至关重要,因为这些软件包具有很强的可重用性,模块化程度很高,极大的方便应用开发者在最短时间内,打造出自己想要的系统。RT-Thread已经支持的软件包数量已经达到450+。 RT-Thread的特点 资源占用极低,超低功耗设计,最小内核(Nano版本)仅需1.2KB RAM,3KB Flash。 组件丰富,繁荣发展的软件包生态 。 简单易用 ,优雅的代码风格,易于阅读、掌握。 高度可伸缩,优质的可伸缩的软件架构,松耦合,模块化,易于裁剪和扩展。 强大,支持高性能应用。 跨平台、芯片支持广泛。 代码目录 RT-Thread源代码目录结构如下图所示: 名称描述bspBoard Support Package(板级支持包)基于各种开发板的移植componentsRT-Thread 的各个组件代码,例如 finsh,gui 等。documentation相关文档,如编码规范等examples相关示例代码includeRT-Thread 内核的头文件。libcpu各类芯片的移植代码。srcRT-Thread 内核的源文件。toolsRT-Thread 命令构建工具的脚本文件。目前RT-Thread已经针对将近90种开发板做好了移植,大部分 BSP 都支持 MDK﹑IAR开发环境和GCC编译器,并且已经提供了默认的 MDK 和 IAR 工程,用户可以直接基于这个工程添加自己的应用代码。 每个 BSP 的目录结构高度统一,且都提供一个 README.md 文件,包含了对这个 BSP 的基本介绍,以及相应的说明,方便用户快速上手。 Env 是RT-Thread推出的开发辅助工具,针对基于RT-Thread操作系统的项目工程,提供编译构建环境、图形化系统配置及软件包管理功能。其内置的 menuconfig 提供了简单易用的配置剪裁工具,可对内核、组件和软件包进行自由裁剪,使系统以搭积木的方式进行构建。 下载 Env 工具 Env 用户手册 资源文档 硬件支持 RT-Thread RTOS 支持许多架构,并且已经涵盖了当前应用中的主要架构。涉及的架构和芯片制造商有: ARM Cortex-M0/M0+:如芯片制造商 ST ARM Cortex-M3:如芯片制造商 ST、全志、灵动等. ARM Cortex-M4:如芯片制造商 ST、Infineon、Nuvoton、NXP、Nordic、GigaDevice、Realtek、Ambiq Micro等 ARM Cortex-M7:如芯片制造商 ST、NXP ARM Cortex-M23:如芯片制造商 GigaDevice ARM Cortex-M33:如芯片制造商 ST ARM Cortex-R4 ARM Cortex-A8/A9:如芯片制造商 NXP ARM7:如芯片制造商Samsung ARM9:如芯片制造商Allwinner、Xilinx 、GOKE ARM11:如芯片制造商Fullhan MIPS32:如芯片制造商loongson、Ingenic RISC-V RV32E/RV32I[F]/RV64[D]:如芯片制造商sifive、嘉楠Kendryte、博流、芯来Nuclei、平头哥T-Head、先楫 ARC:如芯片制造商SYNOPSYS DSP:如芯片制造商 TI C-Sky x86 支持的 IDE 和编译器 RT-Thread主要支持的IDE/编译器包括: MDK KEIL IAR Gcc RT-Thread Studio 使用基于 Python 的 scons 进行命令行生成。 RT-Thread Studio演示: studiozh 快速上手 RT-Thread BSP可以直接编译并下载到相应的开发板使用。此外,RT-Thread还提供 qemu-vexpress-a9 BSP,无需硬件平台即可使用。有关详细信息,请参阅下面的入门指南。 QEMU 入门指南(Windows) QEMU 入门指南(Ubuntu) 文档 文档中心 | 编程指南 应用 RT-Thread 实现蜂鸣器播放器教程 | 分布式温度监控系统教程 | 智能车连载教程 例程 内核示例 | 设备示例代码 | 文件系统示例代码 | 网络示例代码 | RT-Thread API参考手册 基于STM32L475 IoT Board 开发板SDK | 基于W601 IoT Board 开发板SDK RT-Thread中心提供了一系列RT-Thread相关教程及分享内容。 如:内核入门系列 | Env系列 | 网络系列 | Nano移植系列 | RT-Thread Studio系列 | 柿饼UI系列 | 答疑直播系列 | 社区作品系列 更多详情,请前往 中心 许可协议 RT-Thread 系统完全开源,遵循 Apache License 2.0 开源许可协议,可以免费在商业产品中使用,并且不需要公开私有代码,没有潜在商业风险。 /* * Copyright (c) 2006-2018, RT-Thread Development Team * * SPDX-License-Identifier: Apache-2.0 */社区支持 RT-Thread非常感谢所有社区小伙伴的支持,在使用RT-Thread的过程中若您有任何的想法,建议或疑问都可通过以下方式联系到 RT-Thread,我们也实时在这些频道更新RT-Thread的最新讯息。同时,任何疑问都可以在 论坛 中提出,社区成员将回答这些疑问。 官网 | 论坛 | 哔哩哔哩官方账号 | 微博官方账号 | 知乎官方账号 RT-Thread微信公众号: qrcode 贡献代码 如果您对RT-Thread感兴趣,并希望参与RT-Thread的开发并成为代码贡献者,请参阅代码贡献指南。 感谢以下小伙伴对本仓库的贡献! 项目![rt-thread 图片11 ⬇️ 下载地址 {cloud type="default" title="网盘下载" url="https://gitee.com/rtthread/rt-thread/repository/archive/master.zip"} 下载后请先检查文件完整性,如有问题请在评论区反馈 -
Wireshark 是什么?好用的工具软件推荐 推荐一个实用的开源工具——Wireshark。项目由Wireshark开发维护,采用未知开源协议发布。简单来说,它是一个,对于站长和开发者来说是个不错的工具。 工具功能介绍 介绍 {以下是码云平台说明,您可以替换此简介 码云是 OSCHINA 推出的基于 Git 的代码托管平台(同时支持 SVN)。专为开发者提供稳定、高效、安全的云端软件开发协作平台 无论是个人、团队、或是企业,都能够用码云实现代码托管、项目管理、协作开发。企业项目请看 https://gitee.com/enterprises} 软件架构 软件架构说明 安装教程 xxxx xxxx xxxx 使用说明 xxxx xxxx xxxx 参与贡献 Fork 本仓库 新建 Feat_xxx 分支 提交代码 新建 Pull Request 码云特技 使用 Readme\_XXX.md 来支持不同的语言,例如 Readme\_en.md, Readme\_zh.md 码云官方博客 blog.gitee.com 你可以 https://gitee.com/explore 这个地址来了解码云上的优秀开源项目 GVP 全称是码云最有价值开源项目,是码云综合评定出的优秀开源项目 码云官方提供的使用手册 https://gitee.com/help 码云封面人物是一档用来展示码云会员风采的栏目 https://gitee.com/gitee-stars/ 总的来说,Wireshark是一个功能比较实用的开源工具,适合日常工作和学习使用。如果你正在寻找一个的解决方案,不妨下载试试。使用前建议仔细阅读项目文档。 {card-default label="? 工具信息" /} ? 工具名称:Wireshark ? 开发作者:Wireshark ? 工具描述: ? 开发语言:Java ? 开源协议:未知开源协议 ⭐ Star数:0 | ? Fork数:0 ? 更新时间:2020年12月19日 {/card-default} {cloud type="default" title="网盘下载" url="https://gitee.com/Wireshark/Wireshark/repository/archive/master.zip"} {cloud type="default" title="网盘下载" url="https://gitee.com/Wireshark/Wireshark.git"} -
免费开源开源工具推荐:setool-master 下载 今天给大家分享一款实用的开源工具——setool-master。这个工具在Gitee上获得了3个Star,主要功能是SetoolMaster是一款让你入门即入狱的python3开发的进阶型社会工程学工具。包括了全球定位、Ngrok内网穿透、Seeker高精度定位、网页钓鱼、病毒攻击、恐吓勒索信、爬虫、网站克隆、物联网设备搜索等,同时拥有中文支持,内置大量钓鱼模板,设计用于组织级别红队渗透测试,用于团队组织设备型协同,经过非常多的实战演练,效果出众,远超同行产品,对于需要提高工作效率的朋友来说是个不错的选择。 工具功能介绍 SetoolMaster是一款让你入门即入狱的python3开发的进阶型社会工程学工具。包括了全球定位、Ngrok内网穿透、Seeker高精度定位、网页钓鱼、病毒攻击、恐吓勒索信、爬虫、网站克隆、物联网设备搜索等,同时拥有中文支持,内置大量钓鱼模板,设计用于组织级别红队渗透测试,用于团队组织设备型协同,经过非常多的实战演练,效果出众,远超同行产品 你看过电影里面的黑客么,手指在键盘上不停的在打字,屏幕上运行的数不清的计算机命令, 没过一会儿,便可以入侵、盗取别人的计算机密码、 没错,Setool Master就是这样一款黑客工具,设计用于红队的社会工程学攻击。比起传统 的漏洞利用,社会工程学攻击会更加的高效和安全,而且对于使用者的门槛会非常低,入门 linux的也能快速掌握。使用python3开发,有更加良好的发展属性和可读性、运行效率 非常的高,设计用于对组织级别的攻击 绝对不要使用Setool Master去攻击一个你不认识的人,或者你可能会遇到许麻烦 你不能将这些源代码用于商业用途 本开源项目内包含第三方工具,在这里说说明:ngrok,seeker-master 本开源项目允许引用,但受到Apache2开源条约限制 作者:LinWinCloud 版本维护 安卓源代码版本 持续维护 v Linux安装包版本 部分维护 v 安卓编译版本 不再维护 X linux编译版本 不再维护 X 源代码 持续维护 V 安装教程 $ git clone https://github.com/LinWin-Cloud/setool-master $ cd setool-master $ pip3 install whois $ pip3 install requests 1.源代码版本、安卓源代码版本 $ cd resources_code_vistion (这个是源代码版本) 或者 cd Android_Resources_code $ python3 setool.py 2.Linux安装包版本 $ 7z x Setool-Master.7z $ cd Setool-Master $ cd Setool-Master $ python3 install_linux.py 软件将安装在/var/Setool-Master,环境请自行配置 3.编译版本、安卓编译版本 $ cd build_vistion(这个是编译版本) 或者 cd Termax_Android_vistion (这个是安卓编译版本) $ chmod +x ./setool $ bash ./setool 使用文档 使用文档(英文版本) 使用文档(中文版本) 注意 本工具集内Web Console密码linwin用户名linwin 更新日志 v1.0.0 2022.1.5 发布Setool Linux轻量个人版本 v2.1.1 2022.3.5 发布Setool Master源代码版本 v2.1.2 2022.3.5 发布Setool Master安装包版本 v2.1.3 2022.3.15 发布Setool Master预编译版本 v2.1.4 2022.4.1 更新配置文件、告示 v2.2.1 2022.5.1 修改部分源代码 v2.3.2 2022.5.4 修改配置文件 v2.4.1 2022.5.7 修改配置文件,更新版本信息 v2.4.2 2022.5.8 修改配置文件和源代码 v2.5.1 2022.5.15 发布安卓Termux编译版本 v2.5.2 2022.5.17 更新安卓Termux编译版本 v2.5.3 2022.5.19 更新部分源代码 v2.5.4 2022.5.28 发布安卓Termux源代码版本 v2.5.5 2022.5.29 更新版本信息、更新源代码 v2.5.6 2022.5.30 修复部分代码错误、更新部分配置文件 v2.5.7 2022.5.31 更新 Setool Master编译版本 版本信息、配置文件 v2.5.8 2022.6.2 更新配置、版本信息 v2.5.9 2022.6.6 更新源代码版本代码 v2.6.0 2022.6.7 创建使用文档文档 v2.6.1 2022.6.10 更新 使用文档(英文版本) v2.6.2 2022.6.11 更新版本信息、配置信息 v2.6.2 2022.6.12 更新配置文件 v2.6.3 2022.6.13 更新 安卓源代码版本 源代码 v2.6.4 2022.6.15 更新使用文档、配置文件 v2.6.5 2022.6.16 更新配置文件 v2.6.6 2022.6.20 更新源代码 v2.6.7 2022.6.21 更新英语文档,创建中文文档 v2.6.8 2022.6.22 更新配置文件 v2.6.9 2022.6.24 更新安卓源代码,更新配置文件 v2.7.0 2022.6.26 修复源代码错误,修复帮助和配置 v2.7.1 2022.6.28 更新版本信息、更新配置文件 v2.7.2 2022.6.30 更新配置文件 v2.7.3 2022.7.3 更新配置文件,修复源码错误 v2.7.4 2022.7.5 更新项目为Setool Master LTS长期支持版本 v2.7.5 2022.7.6 更新源代码、修复IO操作漏洞 v2.7.6 2022.7.13 更新配置文件 v2.7.7 2022.7.22 更新配置文件,说明 v2.7.8 2022.7.23 更新中文帮助、更新配置文件 v2.7.9 2022.8.9 更新配置文件 v2.8.0 2022.8.31 更新配置文件、修复错误 v2.8.1 2022.9.12 修改文档 v2.8.2 2022.9.16 删除了Linux编译版本,不再维护此版本、修改了源代码、修改了说明文件 v2.8.3 2022.10.15 删除了部分无用文件、更新文档 About Setool Master is a open resources social enginnering tools for linux.android(termux). It is free.You do not pay some money for these tools. Setool Master use Python Code language.It is very easy and funny.You can use these resources code to make a new tools and so on.If you want to get Setool-Master,you can goto https://github.com/LinWin-Cloud/setool-master. https://gitee.com/LinWin-CLoud/setool-master Setool Master是一个适用于Linux、Android(termux)的开源的社会工程学 工具。它是免费的。你不需要为这些工具支付费用。Setool Master使用Python 编程语言。非常简单并且有趣,你能用这些源代码去创造一个新的工具等等。如果你 想获取SetoolMaster,你能够访问 https://github.com/LinWin-Cloud/setool-master. https://gitee.com/LinWin-CLoud/setool-master 该项目会持续维护,吸收大家的建议 项目维护真的不容易,开源项目不赚钱,本项目将保证永远也不进行商业收费 真心希望屏幕前面的你能够给开发者一些动力来维护更新这更好的项目 综合来看,setool-master在同类工具中还是有一定优势的,特别是在功能完整性和易用性方面表现不错。如果你有相关需求,可以下载试试。 {card-default label="? 工具信息" /} ? 工具名称:setool-master ? 开发作者:LinWin-Cloud ? 工具描述:SetoolMaster是一款让你入门即入狱的python3开发的进阶型社会工程学工具。包括了全球定位、Ngrok内网穿透、Seeker高精度定位、网页钓鱼、病毒攻击、恐吓勒索信、爬虫、网站克隆、物联网设备搜索等,同时拥有中文支持,内置大量钓鱼模板,设计用于组织级别红队渗透测试,用于团队组织设备型协同,经过非常多的实战演练,效果出众,远超同行产品 ? 开发语言:Python ? 开源协议:未知开源协议 ⭐ Star数:3 | ? Fork数:0 ? 更新时间:2025年06月18日 {/card-default} {cloud type="default" title="网盘下载" url="https://gitee.com/LinWin-Cloud/setool-master/repository/archive/main.zip"} {cloud type="default" title="网盘下载" url="https://gitee.com/LinWin-Cloud/setool-master.git"} -
DiscuzX 后台系统下载 - 基于PHP的开源网站系统 推荐一个实用的PHP开源项目——DiscuzX。项目由Discuzx开发维护,采用未知开源协议发布。简单来说,它是一个Discuz! X 官方免费开源版,简体中文 UTF8 编码。中国领先的社区软件服务商,2001 年至今为 300 万企业及站长赋能,拥有超过 7000 款应用,全球成熟度最高,覆盖率量大的建站系统之一。秉承“开放、连接、共赢”的精神,倡导与生态伙伴及开发者共建,健康可持续的 Discuz! 品牌合作模式。,对于需要搭建网站的朋友来说是个不错的选择。 项目功能介绍 简介 Discuz! X5 官方中文版 Git 仓库 https://gitee.com/Discuz/DiscuzX 国际版镜像仓库 https://github.com/DiscuzTeam/DiscuzX 关于 X5 从 X5.0 起 Discuz! 默认不再包含 UCenter 服务端,如需站群方式部署请自行下载 UCenter 从 X5.0 起安装程序默认内置升级程序,请先升级到 X3.5 版本 从 X5.0 起安装程序默认内置工具箱程序,请修改 install/index.php 文件名后启用 从 X5.0 起将不再兼容 PHP 7 环境,安装、升级前请自行准备 PHP 8 环境 X5 兼容 X3.5 应用的运行,但是,是否兼容 PHP 8 环境下运行请咨询应用的开发者 欢迎 D 粉们积极 PR,Discuz! 从 2001 年至今,开源产品少不了大家的支持 额外目录说明 Git 版以下目录默认为空,如需要请自行单独下载覆盖 文件名含义Git 仓库地址/vendorDiscuz! X5 Vendor 库https://gitee.com/Discuz/vendor/source/data/ipDiscuz! X5 IP 库https://gitee.com/Discuz/IP更新说明 基于 MitFrame® 内核的全新框架体系重构,既是社区又是框架,全面开拓更广泛的开放视角 从前台到后台,开放更加彻底 轻重兼顾的多功能一体化社区 全新 JSON 编辑器 版块、用户组、积分全面加强 全面拥抱 OAuth2.0 的 RESTful API 接口,开发者可随意自定义自己的接口 点击了解版本功能说明 X5 特性应用列表 插件 模板 关于商业版 X5.1 是目前 X5 系列产品的商业版本,不提供开源版,如您想了解报价请点击这里 原生多端生态、原生队列、原生 AI、原生流程、万象智能 内置多种对象存储、内置多种企业登录平台、内置 ES 全文搜索 点击了解版本功能说明 协助安装 为方便站长基于 Discuz! X 搭建网站,Discuz! 应用中心 为站长提供安装 Discuz! X 的服务,详情咨询 声明 您可以 Fork 本站代码,但未经许可 禁止 在本产品的整体或任何部分基础上以发展任何派生版本、修改版本或第三方版本用于 重新分发 Dx Git Forker 以上就是关于DiscuzX的简单介绍。这个项目的代码结构清晰,文档也比较完善,对于PHP初学者来说也是一个不错的学习资源。有兴趣的朋友可以通过下方链接下载源码体验一下。 {card-default label="? 项目信息" /} ? 项目名称:DiscuzX ? 开发作者:Discuzx ? 项目描述:Discuz! X 官方免费开源版,简体中文 UTF8 编码。中国领先的社区软件服务商,2001 年至今为 300 万企业及站长赋能,拥有超过 7000 款应用,全球成熟度最高,覆盖率量大的建站系统之一。秉承“开放、连接、共赢”的精神,倡导与生态伙伴及开发者共建,健康可持续的 Discuz! 品牌合作模式。 ? 开发语言:PHP ? 开源协议:未知开源协议 ⭐ Star数:3811 | ? Fork数:1535 ? 更新时间:2026年09月01日 {/card-default} {cloud type="default" title="网盘下载" url="https://gitee.com/Discuz/DiscuzX/repository/archive/MitFrame.zip"} {cloud type="default" title="网盘下载" url="https://gitee.com/Discuz/DiscuzX.git"} -
strix - 一款实用的开源工具 推荐一个实用的开源工具——**strix**。项目由usestrix开发维护,GitHub上获得了 **61007** 个Star。简单来说,它是一款开源人工智能渗透测试工具,用于查找和修复应用程序的漏洞。,对于站长和开发者来说是个不错的工具。 # # 工具功能介绍 ### The open-source AI pentesting tool. Autonomous AI hackers that find and fix your app’s vulnerabilities. > [!TIP] > **New!** Strix integrates seamlessly with GitHub Actions and CI/CD pipelines. Automatically scan for vulnerabilities on every pull request and block insecure code before it reaches production - [Get started with no setup required](https://app.strix.ai?utm_source=github&utm_medium=readme&utm_content=tip_ci).---## Strix OverviewStrix are autonomous AI penetration testing agents that act just like real hackers - they run your code dynamically, find vulnerabilities, and validate them through actual proofs-of-concept. Built for developers and security teams who need fast, accurate security testing without the overhead of manual pentesting or the false positives of static analysis tools.**Key Capabilities:**- **Full pentesting toolkit** - reconnaissance, exploitation, and validation out of the box - **Multi-agent orchestration** - teams of AI pentesters that collaborate and scale - **Real exploit validation** - working PoCs, not false positives like legacy vulnerability scanners - **Developer‑first CLI** - actionable findings with remediation guidance - **Auto‑fix & reporting** - generate patches and compliance-ready pentest reports# # Use Cases- **Application Security Testing** - Detect and validate critical vulnerabilities in your applications - **Rapid Penetration Testing** - Get penetration tests done in hours, not weeks, with compliance reports - **Bug Bounty Automation** - Automate bug bounty research and generate PoCs for faster reporting - **CI/CD Integration** - Run tests in CI/CD to block vulnerabilities before reaching production## ? Quick Start**Prerequisites:** - Docker (running) - An LLM API key from any [supported provider](https://docs.strix.ai/llm-providers/overview) (OpenAI, Anthro, Google, etc.)### Installation & First Scan bash # Install Strix curl -sSL https://strix.ai/install | bash # Configure your AI provider export STRIX_LLM="openrouter/z-ai/glm-5.3" export LLM_API_KEY="your-api-key" # Run your first security assessment strix --target ./app-directory > [!NOTE] > First run automatically pulls the sandbox Docker . Results are saved to `strix_runs/`---## Ways to Run Strix- **Open Source** - free, runs locally with Docker and your own LLM key. [Quick Start](https://docs.strix.ai/quickstart) - **Strix Cloud** - no setup, validated findings, one-click autofix, and PR reviews. [Run a pentest →](https://app.strix.ai?intent=pentest&utm_source=github&utm_medium=readme&utm_content=table_cloud) - **Enterprise** - SSO, compliance-ready reports, VPC or self-hosted deployment. [Try Strix Enterprise →](https://strix.ai/demo?utm_source=github&utm_medium=readme&utm_content=table_demo)---## ☁️ Strix CloudTry the Strix full-stack penetration testing platform at **[app.strix.ai](https://app.strix.ai?utm_source=github&utm_medium=readme&utm_content=cloud_heading)** - sign up for free, connect your repos and domains, and launch a pentest in minutes.- **Validated findings with PoCs** - every vulnerability includes a working proof-of-concept exploit and reproduction steps - **One-click autofix** - AI-generated security patches as ready-to-merge pull requests - **Continuous pentesting** - always-on vulnerability scanning that keeps pace with your deployments - **DevSecOps integrations** - GitHub, GitLab, Bitbucket, Slack, Jira, Linear, and CI/CD pipelines - **Continuous learning** - AI that builds on past findings, adapts to your codebase, and reduces false positives over time[**Run a pentest →**](https://app.strix.ai?intent=pentest&utm_source=github&utm_medium=readme&utm_content=cloud_cta)## ? EnterpriseGet the same Strix experience with enterprise-grade controls: SSO (SAML/OIDC), custom compliance-ready penetration testing reports (SOC 2, ISO 27001, PCI DSS), dedicated support and SLA, custom deployment options (VPC or self-hosted), BYOK model support, and tailored AI pentesting agents optimized for your environment.[**Try Strix Enterprise →**](https://strix.ai/demo?utm_source=github&utm_medium=readme&utm_content=enterprise_cta)--- ## ? Use Strix from Your Coding AgentStrix is agent-ready. Give Claude Code, Cursor, Codex, or any [SKILL.md-compatible](https://agentskills.io) agent the ability to run pentests, fix findings, and set up CI scanning: bash npx skills add usestrix/strix This installs nine skills for running pentests, fixing findings, and CI scanning, against code, web apps, APIs, and the OWASP Top 10. Agents can use the local CLI or the managed cloud with the same engine.See [`AGENTS.md`](AGENTS.md) for the quick reference, [docs.strix.ai/llms.txt](https://docs.strix.ai/llms.txt) for the CLI, and [docs.app.strix.ai](https://docs.app.strix.ai) for the API.--- ## ✨ Features ### Agentic Pentesting ToolsStrix agents come equipped with a comprehensive offensive security toolkit - the same tools used by professional penetration testers and ethical hackers:- **HTTP Interception Proxy** - Full request/response manipulation and analysis with Caido - **Browser Exploitation** - Automated browser for testing XSS, CSRF, clickjacking, and auth bypass flows - **Shell & Command Execution** - Interactive terminal for exploit development and post-exploitation - **Custom Exploit Runtime** - Python sandbox for writing and validating proof-of-concept exploits - **Reconnaissance & OSINT** - Automated attack surface mapping, subdomain enumeration, and fingerprinting - **Static & Dynamic Code Analysis** - SAST + DAST capabilities for comprehensive application security testing - **Vulnerability Knowledge Base** - Structured findings with CVSS scoring and OWASP classification### Comprehensive Vulnerability ScannerStrix identifies, validates, and exploits a wide range of security vulnerabilities across the OWASP Top 10 and beyond:- **Broken Access Control** - IDOR, privilege escalation, auth bypass - **Injection Attacks** - SQL injection, NoSQL injection, OS command injection, SSTI - **Server-Side Vulnerabilities** - SSRF, XXE, insecure deserialization, RCE - **Client-Side Attacks** - XSS (stored/reflected/DOM), prototype pollution, CSRF - **Business Logic Flaws** - Race conditions, payment manipulation, workflow bypass - **Authentication & Session** - JWT attacks, session fixation, credential stuffing vectors - **Infrastructure & Cloud** - Misconfigurations, exposed services, cloud security issues - **API Security** - Broken authentication, mass assignment, rate limiting bypass### Graph of Agents (Multi-Agent Pentesting)Advanced multi-agent orchestration for comprehensive automated penetration testing:- **Distributed Pentesting** - Specialized AI agents for recon, exploitation, and post-exploitation - **Scalable Security Testing** - Parallel execution across multiple targets for fast, comprehensive coverage - **Dynamic Coordination** - Agents share discoveries, chain vulnerabilities, and collaborate like a red team---## ?️ Local Web ViewerEvery scan writes its results to disk as it runs. Bring them up in a local dashboard with a single command: bash # Open the most recent run strix view # ...or open a specific run by name strix view my-run-name # Expose the viewer on all IPv4 interfaces at a fixed port strix view --host 0.0.0.0 --port 8080 --no-open The dashboard shows the findings, a live map of the agent team, and past runs. Nothing leaves your machine, and the UI ships prebuilt. `strix view` binds to `127.0.0.1` and prints a tokened link that grants access to the run, so share it carefully.See the [viewer documentation](https://docs.strix.ai/usage/viewer) for the options and for reaching the viewer from another machine.--- ## Usage Examples ### Basic Usage bash # Scan a local codebase strix --target ./app-directory # Security review of a GitHub repository strix --target https://github.com/org/repo # Black-box web application assessment strix --target https://your-app.com ### API Testing (OpenAPI / Swagger / Postman)Point Strix at an API contract and it tests every declared endpoint instead of having to discover them by crawling. Pair the spec with the live base URL so the agent knows where to send traffic: bash # OpenAPI / Swagger file, Postman export, or a live collection by id strix --target ./openapi.yaml --target https://api.your-app.com strix --target postman:// --target https://api.your-app.com ### Advanced Testing Scenarios bash # Grey-box authenticated testing strix --target https://your-app.com --instruction "Perform authenticated testing using credentials: user:pass" # Multi-target testing (source code + deployed app) strix -t https://github.com/org/app -t https://your-app.com # Targets from a file, one target per non-empty, non-comment line strix --target-list ./targets.txt See the [CLI reference](https://docs.strix.ai/usage/cli) for every option, including scan modes, diff scope, instruction files, and budgets. ### Headless ModeRun Strix programmatically without interactive UI using the `-n/--non-interactive` flag - perfect for servers and automated jobs. The CLI prints real-time vulnerability findings and the final report before exiting. Exits with non-zero code when vulnerabilities are found. bash strix -n --target https://your-app.com ### CI/CD (GitHub Actions)Strix can be added to your pipeline to run a security test on pull requests with a lightweight GitHub Actions workflow: yaml name: strix-penetration-teston: pull_request:jobs: security-scan: runs-on: ubuntu-latest steps: - uses: actions/checkout@v6 with: fetch-depth: 0- name: Install Strix run: curl -sSL https://strix.ai/install | bash- name: Run Strix env: STRIX_LLM: ${{ secrets.STRIX_LLM }} LLM_API_KEY: ${{ secrets.LLM_API_KEY }}run: strix -n -t ./ --scan-mode quick > [!TIP] > In CI pull request runs, Strix automatically scopes quick reviews to changed files, which is why the > checkout above fetches full history. See the > [CI/CD documentation](https://docs.strix.ai/integrations/github-actions) for the details.### Configuration bash export STRIX_LLM="openrouter/z-ai/glm-5.3" export LLM_API_KEY="your-api-key" # Optional export LLM_API_BASE="your-api-base-url" # if using a local model, e.g. Ollama, LMStudio > [!NOTE] > Strix automatically saves your configuration to `~/.strix/cli-config.json`, so you don't have to re-enter it on every run. > See the [configuration reference](https://docs.strix.ai/advanced/configuration) for every environment variable.#### Sign in with a ChatGPT subscriptionInstead of a metered API key, you can run Strix on your ChatGPT Plus/Pro subscription: bash strix auth login chatgpt # sign in with your ChatGPT account export STRIX_LLM="chatgpt/gpt-5.4" # chatgpt/ runs on the subscription strix auth status # show the active sign-in, or logout to forget it #### Use the managed platform: `strix cloud`Run scans on [app.strix.ai](https://app.strix.ai) from the terminal, without Docker or an LLM key: bash strix cloud login # browser sign-in, one credential per install strix cloud scans start --source . --yes --wait # scan local code, approving the upload strix cloud scans start --engagement-type live_test --domain-ids --wait strix cloud vulns list --severity critical Every [REST API](https://docs.app.strix.ai) operation has a matching `strix cloud ` command. Run `strix cloud` to list the resources, and add `help` to a resource to list its verbs. Output is JSON when stdout is not a terminal or when you pass `--json`. Binary downloads are the exception: redirect the raw bytes, or combine `--output FILE --json` for download metadata.See the [cloud CLI documentation](https://docs.strix.ai/cloud/cli) for scopes, workspaces, billing, and source-upload options. #### Connect your own MCP serversStrix can connect to Model Context Protocol (MCP) servers you list and expose their tools to the agent during a run. Create `~/.strix/mcp-servers.json` with a JSON list of local `stdio` servers or remote `http` servers: json [ { "name": "github", "transport": "http", "url": "https://api.githubcopilot.com/mcp/", "auth": { "kind": "bearer", "token": "your-token" }, "allowed_tools": ["list_issues"] } ] Each server's tools are namespaced by `name`, for example `github_list_issues`. See the [MCP documentation](https://docs.strix.ai/integrations/mcp) for the full schema, tool filtering, and `stdio` servers.**Recommended models for best results:**- [Z.ai GLM-5.3 on OpenRouter](https://openrouter.ai/z-ai/glm-5.3) - `openrouter/z-ai/glm-5.3` (the default k) - [OpenAI GPT-5.4](https://openai.com/api/) - `openai/gpt-5.4` - [AnthroClaude Sonnet 4.6](https://claude.com/platform/api) - `anthro/claude-sonnet-4-6` - [Google Gemini 3 Pro Preview](https://cloud.google.com/vertex-ai) - `vertex_ai/gemini-3-pro-preview` - [DeepSeek V4 Pro](https://platform.deepseek.com) - `deepseek/deepseek-v4-pro` - [Moonshot Kimi K3](https://platform.kimi.ai) - `moonshot/kimi-k3`See the [LLM Providers documentation](https://docs.strix.ai/llm-providers/overview) for all supported providers including Vertex AI, Bedrock, Azure, and local models.## Documentation Full documentation is available at **[docs.strix.ai](https://docs.strix.ai)** - including detailed guides for usage, CI/CD integrations, skills, and advanced configuration. ## Contributing We welcome contributions of code, docs, and new skills - check out our [Contributing Guide](https://docs.strix.ai/contributing) to get started or open a [pull request](https://github.com/usestrix/strix/pulls)/[issue](https://github.com/usestrix/strix/issues). ## Join Our CommunityHave questions? Found a bug? Want to contribute? **[Join our Discord!](https://discord.gg/strix-ai)** ## Support the Project**Love Strix?** Give us a ⭐ on GitHub! ## Acknowledgements Strix builds on the incredible work of open-source projects like [LiteLLM](https://github.com/BerriAI/litellm), [Caido](https://github.com/caido/caido), [Nuclei](https://github.com/projectdiscovery/nuclei), [Playwright](https://github.com/microsoft/playwright), and [Bubble Tea](https://github.com/charmbracelet/bubbletea). Huge thanks to their maintainers!> [!WARNING] > **Authorized use only.** Strix actively tests the targets you point it at, so only run it against systems you own or have **explicit, written permission** to test, and stay within the agreed scope. Unauthorized testing is illegal in most jurisdictions. > You alone are responsible for obtaining authorization and complying with the law. Strix is provided "as is" with no warranty or liability for misuse.{card-default label="? 工具信息" /} ? 项目地址:[https://github.com/usestrix/strix](https://github.com/usestrix/strix) ⭐ Star数:61007 ? 开发语言:Python ? 项目描述:开源人工智能渗透测试工具,用于查找和修复应用程序的漏洞。 {/card-default}{cloud type="default" title="网盘下载" url="https://github.com/usestrix/strix/archive/refs/heads/main.zip"} {cloud type="default" title="网盘下载" url="https://github.com/usestrix/strix"}总的来说,**strix**是一个功能比较实用的开源工具,适合日常工作和学习使用。如果你正在寻找一款相关工具,不妨下载试试。使用前建议仔细阅读项目文档。 -
开源安全工具 nuclei 推荐 推荐一个实用的开源工具——**nuclei**。项目由projectdiscovery开发维护,GitHub上获得了 **31053** 个Star。简单来说,它是一款Nuclei是一款快速、可定制的漏洞扫描器,由全球安全社区提供支持,构建在一个简单的基于YAML的DSL之上,使协作能够解决互联网上的流行漏洞。它可帮助您查找应用程序、API、网络、DNS和云配置中的漏洞。,对于站长和开发者来说是个不错的工具。 # # 工具功能介绍  **Nuclei is a modern, high-performance vulnerability scanner that leverages simple YAML-based templates. It empowers you to design custom vulnerability detection scenarios that mimic real-world conditions, leading to zero false positives.**- Simple YAML format for creating and customizing vulnerability templates.- Contributed by thousands of security professionals to tackle trending vulnerabilities. - Reduce false positives by simulating real-world steps to verify a vulnerability. - Ultra-fast parallel scan processing and request clustering. - Integrate into CI/CD pipelines for vulnerability detection and regression testing. - Supports multiple protocols like TCP, DNS, HTTP, SSL, WHOIS, JavaScript, Code and more. - Integrate with Jira, Splunk, GitHub, Elastic, GitLab. - [**`Get Started`**](#get-started) - [_`1. Nuclei CLI`_](#1-nuclei-cli) - [_`2. Pro and Enterprise Editions`_](#2-pro-and-enterprise-editions) - [**`Documentation`**](#documentation) - [_`Command Line Flags`_](#command-line-flags) - [_`Single target scan`_](#single-target-scan) - [_`Scanning multiple targets`_](#scanning-multiple-targets) - [_`Network scan`_](#network-scan) - [_`Scanning with your custom template`_](#scanning-with-your-custom-template) - [_`Connect Nuclei to ProjectDiscovery_`_](#connect-nuclei-to-projectdiscovery) - [**`Nuclei Templates, Community and Rewards`**](#nuclei-templates-community-and-rewards-) ? - [**`Our Mission`**](#our-mission) - [**`Contributors`**](#contributors-heart) ❤ - [**`License`**](#license) # # Get Started ### **1. Nuclei CLI**_Install Nuclei on your machine. Get started by following the installation guide [**`here`**](https://docs.projectdiscovery.io/tools/nuclei/install?utm_source=github&utm_medium=web&utm_campaign=nuclei_readme). Additionally, we provide [**`a free cloud tier`**](https://cloud.projectdiscovery.io/sign-up) that comes with generous monthly free limits:_- Store and visualize your vulnerability findings - Write and manage your Nuclei templates - Access the latest Nuclei templates - Discover and store your targets> [!Important] > |**This project is in active development**. Expect breaking changes with releases. Review the release changelog before updating.| > |:--------------------------------| > | This project is primarily built to be used as a standalone CLI tool. **Running nuclei as a service may pose security risks.** It's recommended to use with caution and additional security measures. |### **2. Pro and Enterprise Editions**_For security teams and enterprises, we provide a cloud-hosted service built on top of Nuclei OSS, fine-tuned to help you continuously run vulnerability scans at scale with your team and existing workflows:_- 50x faster scans - Large scale scanning with high accuracy - Integrations with cloud services (AWS, GCP, Azure, Cloudflare, Fastly, Terraform, Kubernetes) - Jira, Slack, Linear, APIs and Webhooks - Executive and compliance reporting - Plus: Real-time scanning, SAML SSO, SOC 2 compliant platform (with EU and US hosting options), shared team workspaces, and more - We're constantly [**`adding new features`**](https://feedback.projectdiscovery.io/changelog)! - **Ideal for:** Pentesters, security teams, and enterprises[**`Sign up to Pro`**](https://projectdiscovery.io/pricing?utm_source=github&utm_medium=web&utm_campaign=nuclei_readme) or [**`Talk to our team`**](https://projectdiscovery.io/request-demo?utm_source=github&utm_medium=web&utm_campaign=nuclei_readme) if you have a large organization and complex requirements. # # Documentation Browse the full Nuclei [**`documentation here`**](https://docs.projectdiscovery.io/tools/nuclei/running). If you’re new to Nuclei, check out our [**`foundational YouTube series`**](https://www.youtube.com/playlist?list=PLZRbR9aMzTTpItEdeNSulo8bYsvil80Rl). ### Installation`nuclei` requires **go >= 1.24.2** to install successfully. Run the following command to get the repo: sh go install -v github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest To learn more about installing nuclei, see `https://docs.projectdiscovery.io/tools/nuclei/install`. ### Command Line FlagsTo display all the flags for the tool: sh nuclei -h Expand full help flags ``` yaml Nuclei is a fast, template based vulnerability scanner focusing on extensive configurability, massive extensibility and ease of use.Usage: ./nuclei [flags]Flags: TARGET: -u, -target string[] target URLs/hosts to scan -l, -list string path to file containing a list of target URLs/hosts to scan (one per line) -targets-inline string inline multiline target list (for use in template profiles) -eh, -exclude-hosts string[] hosts to exclude to scan from the input list (ip, cidr, hostname) -resume string resume scan from and save to specified file (clustering will be disabled) -sa, -scan-all-ips scan all the IP's associated with dns record -iv, -ip-version string[] IP version to scan of hostname (4,6) - (default 4)TARGET-FORMAT: -im, -input-mode string mode of input file (list, burp, jsonl, yaml, openapi, swagger, http) (default "list") -ro, -required-only use only required fields in input format when generating requests -sfv, -skip-format-validation skip format validation (like missing vars) when parsing input file -vtt, -vars-text-templating enable text templating for vars in input file (only for yaml input mode) -vfp, -var-file-paths string[] list of yaml file contained vars to inject into yaml inputTEMPLATES: -nt, -new-templates run only new templates added in latest nuclei-templates release -ntv, -new-templates-version string[] run new templates added in specific version -as, -automatic-scan automatic web scan using wappalyzer technology detection to tags mapping -t, -templates string[] list of template or template directory to run (comma-separated, file) -turl, -template-url string[] template url or list containing template urls to run (comma-separated, file) -ai, -prompt string generate and run template using ai prompt -w, -workflows string[] list of workflow or workflow directory to run (comma-separated, file) -wurl, -workflow-url string[] workflow url or list containing workflow urls to run (comma-separated, file) -validate validate the passed templates to nuclei -nss, -no-strict-syntax disable strict syntax check on templates -td, -template-display displays the templates content -tl list all templates matching current filters -tgl list all available tags -sign signs the templates with the private key defined in NUCLEI_SIGNATURE_PRIVATE_KEY env variable -code enable loading code protocol-based templates -dut, -disable-unsigned-templates disable running unsigned templates or templates with mismatched signature -esc, -enable-self-contained enable loading self-contained templates -egm, -enable-global-matchers enable loading global matchers templates -file enable loading file templatesFILTERING: -a, -author string[] templates to run based on authors (comma-separated, file) -tags string[] templates to run based on tags (comma-separated, file) -etags, -exclude-tags string[] templates to exclude based on tags (comma-separated, file) -itags, -include-tags string[] tags to be executed even if they are excluded either by default or configuration -id, -template-id string[] templates to run based on template ids (comma-separated, file, allow-wildcard) -eid, -exclude-id string[] templates to exclude based on template ids (comma-separated, file) -it, -include-templates string[] path to template file or directory to be executed even if they are excluded either by default or configuration -et, -exclude-templates string[] path to template file or directory to exclude (comma-separated, file) -em, -exclude-matchers string[] template matchers to exclude in result -s, -severity value[] templates to run based on severity. Possible values: info, low, medium, high, critical, unknown -es, -exclude-severity value[] templates to exclude based on severity. Possible values: info, low, medium, high, critical, unknown -pt, -type value[] templates to run based on protocol type. Possible values: dns, file, http, headless, tcp, workflow, ssl, websocket, whois, code, javascript -ept, -exclude-type value[] templates to exclude based on protocol type. Possible values: dns, file, http, headless, tcp, workflow, ssl, websocket, whois, code, javascript -tc, -template-condition string[] templates to run based on expression conditionOUTPUT: -o, -output string output file to write found issues/vulnerabilities -sresp, -store-resp store all request/response passed through nuclei to output directory -srd, -store-resp-dir string store all request/response passed through nuclei to custom directory (default "output") -silent display findings only -nc, -no-color disable output content coloring (ANSI escape codes) -j, -jsonl write output in JSONL(ines) format -irr, -include-rr -omit-raw include request/response pairs in the JSON, JSONL, and Markdown outputs (for findings only) [DEPRECATED use -omit-raw] (default true) -or, -omit-raw omit request/response pairs in the JSON, JSONL, and Markdown outputs (for findings only) -ot, -omit-template omit encoded template in the JSON, JSONL output -nm, -no-meta disable printing result metadata in cli output -ts, -timestamp enables printing timestamp in cli output -rdb, -report-db string nuclei reporting database (always use this to persist report data) -ms, -matcher-status display match failure status -me, -markdown-export string directory to export results in markdown format -se, -sarif-export string file to export results in SARIF format -je, -json-export string file to export results in JSON format -jle, -jsonl-export string file to export results in JSONL(ine) format -pe, -pdf-export string file to export results in PDF format -rd, -redact string[] redact given list of keys from query parameter, request header and bodyCONFIGURATIONS: -config string path to the nuclei configuration file -tp, -profile string template profile config file to run -tpl, -profile-list list community template profiles -fr, -follow-redirects enable following redirects for http templates -fhr, -follow-host-redirects follow redirects on the same host -mr, -max-redirects int max number of redirects to follow for http templates (default 10) -dr, -disable-redirects disable redirects for http templates -rc, -report-config string nuclei reporting module configuration file -H, -header string[] custom header/cookie to include in all http request in header:value format (cli, file) -V, -var value custom vars in key=value format -r, -resolvers string file containing resolver list for nuclei -sr, -system-resolvers use system DNS resolving as error fallback -dc, -disable-clustering disable clustering of requests -passive enable passive HTTP response processing mode -fh2, -force-http2 force http2 connection on requests -ev, -env-vars enable environment variables to be used in template -cc, -client-cert string client certificate file (PEM-encoded) used for authenticating against scanned hosts -ck, -client-key string client key file (PEM-encoded) used for authenticating against scanned hosts -ca, -client-ca string client certificate authority file (PEM-encoded) used for authenticating against scanned hosts -sml, -show-match-line show match lines for file templates, works with extractors only -ztls use ztls library with autofallback to standard one for tls13 [Deprecated] autofallback to ztls is enabled by default -sni string tls sni hostname to use (default: input domain name) -dka, -dialer-keep-alive value keep-alive duration for network requests. -lfa, -allow-local-file-access allows file (payload) access anywhere on the system -lna, -restrict-local-network-access blocks connections to the local / private network -i, -interface string network interface to use for network scan -at, -attack-type string type of payload combinations to perform (batteringram,pitchfork,clusterbomb) -sip, -source-ip string source ip address to use for network scan -rsr, -response-size-read int max response size to read in bytes -rss, -response-size-save int max response size to read in bytes (default 1048576) -reset reset removes all nuclei configuration and data files (including nuclei-templates) -tlsi, -tls-impersonate enable experimental client hello (ja3) tls randomization -hae, -http-api-endpoint string experimental http api endpointINTERACTSH: -iserver, -interactsh-server string interactsh server url for self-hosted instance (default: oast.pro,oast.live,oast.site,oast.online,oast.fun,oast.me) -itoken, -interactsh-token string authentication token for self-hosted interactsh server -interactions-cache-size int number of requests to keep in the interactions cache (default 5000) -interactions-eviction int number of seconds to wait before evicting requests from cache (default 60) -interactions-poll-duration int number of seconds to wait before each interaction poll request (default 5) -interactions-cooldown-period int extra time for interaction polling before exiting (default 5) -ni, -no-interactsh disable interactsh server for OAST testing, exclude OAST based templatesFUZZING: -ft, -fuzzing-type string overrides fuzzing type set in template (replace, prefix, postfix, infix) -fm, -fuzzing-mode string overrides fuzzing mode set in template (multiple, single) -fuzz enable loading fuzzing templates (Deprecated: use -dast instead) -dast enable / run dast (fuzz) nuclei templates -dts, -dast-server enable dast server mode (live fuzzing) -dtr, -dast...{card-default label="? 工具信息" /} ? 项目地址:[https://github.com/projectdiscovery/nuclei](https://github.com/projectdiscovery/nuclei) ⭐ Star数:31053 ? 开发语言:Go ? 项目描述:Nuclei是一款快速、可定制的漏洞扫描器,由全球安全社区提供支持,构建在一个简单的基于YAML的DSL之上,使协作能够解决互联网上的流行漏洞。它可帮助您查找应用程序、API、网络、DNS和云配置中的漏洞。 {/card-default}{cloud type="default" title="网盘下载" url="https://github.com/projectdiscovery/nuclei/archive/refs/heads/dev.zip"} {cloud type="default" title="网盘下载" url="https://github.com/projectdiscovery/nuclei"}总的来说,**nuclei**是一个功能比较实用的开源工具,适合日常工作和学习使用。如果你正在寻找一款相关工具,不妨下载试试。使用前建议仔细阅读项目文档。 -
DiscuzQ 开源项目下载 - 基于PHP的开源网站系统 DiscuzQ 今天给大家分享一款基于PHP开发的开源项目——DiscuzQ。这个项目在Gitee上获得了431个Star,240次Fork,说明还是有不少开发者在使用和关注的。项目主要特点是【React版 后台】Discuz! Q是一套跨端全域的社区工具,是平行于Discuz! X系列的另一条产品线,Discuz! Q的目标是帮助流量大V、网红、知识付费、,适合需要快速搭建网站的开发者和站长使用。 项目功能介绍 关于 Discuz! Q Discuz Q 社区 安装方法 服务器环境需求为: PHP 7.2.5+ 和 MySQL 5.7+。 第一步:下载 Discuz! Q 首先注册腾讯云帐号 并 实名认证, 然后在 API密钥管理 处新建一个密钥 Discuz!Q 源码归类 【后台管理下载】https://gitee.com/Discuz/Discuz-Q 【PC端+H5+小程序 前端下载】https://gitee.com/Discuz/discuz-fe 感谢 背景故事 Discuz! Q项目由于是从 0 到 1,介于我们的目标,如果从第一行代码开始编写,是极为庞大的工程。想想Discuz!X,代码量依赖 10 多年的时间的积累,才完善出各种工具类、自己的框架及插件机制等。 在此背景下,我们必须借助开源的力量,才得以快速构建出Discuz! Q。以下是整个Discuz! Q中所用到的技术栈,在此特别感谢他们: Discuz! Q 是更轻的,更易变现的,更移动端的,更开放的和更易于二次开发的社区产品。 Discuz! Q 是一套跨端全域的社区工具,内置六大能力:用户能力、内容能力、支付能力、运营能力、通知能力、连接能力;可以设置公开、付费模式,发布包括图文、短、附件、话题、评论等内容形式;并支持知识变现,可以内容 以上就是关于DiscuzQ的简单介绍。这个项目的代码结构清晰,文档也比较完善,对于PHP初学者来说也是一个不错的学习资源。有兴趣的朋友可以通过下方链接下载源码体验一下。 {card-default label="? 项目信息" /} ? 项目名称:DiscuzQ ? 开发作者:Discuzx ? 项目描述:【React版 后台】Discuz! Q是一套跨端全域的社区工具,是平行于Discuz! X系列的另一条产品线,Discuz! Q的目标是帮助流量大V、网红、知识付费、 ? 开发语言:PHP ? 开源协议:未知开源协议 ⭐ Star数:431 | ? Fork数:240 ? 更新时间:2026年07月23日 {/card-default} {cloud type="default" title="网盘下载" url="https://gitee.com/Discuz/Discuz-Q/repository/archive/master.zip"} {cloud type="default" title="网盘下载" url="https://gitee.com/Discuz/Discuz-Q.git"} -
分享一个不错的建站源码:WeiPHP2 完整源码 WeiPHP2 推荐一个实用的PHP开源项目——WeiPHP2。项目由ThinkPHP开发维护,采用未知开源协议发布。简单来说,它是一个WeiPHP2.0版本全新发布,新增多款插件 助你轻松快捷搭建,对于需要搭建网站的朋友来说是个不错的选择。 项目功能介绍 WeiPHP2 以上就是关于WeiPHP2的简单介绍。这个项目的代码结构清晰,文档也比较完善,对于PHP初学者来说也是一个不错的学习资源。有兴趣的朋友可以通过下方链接下载源码体验一下。 {card-default label="? 项目信息" /} ? 项目名称:WeiPHP2 ? 开发作者:ThinkPHP ? 项目描述:WeiPHP2.0版本全新发布,新增多款插件 助你轻松快捷搭建 ? 开发语言:PHP ? 开源协议:未知开源协议 ⭐ Star数:9 | ? Fork数:4 ? 更新时间:2020年12月21日 {/card-default} {cloud type="default" title="网盘下载" url="https://gitee.com/ThinkPHP/WeiPHP2/repository/archive/master.zip"} {cloud type="default" title="网盘下载" url="https://gitee.com/ThinkPHP/WeiPHP2.git"} -
2026年值得收藏的开源项目:NIUSHOP开源商城 V5 DEV全开源 源码分享 今天给大家分享一款基于PHP开发的开源项目——**NIUSHOP开源商城 V5 DEV全开源**。这个项目在Gitee上获得了2553个Star,669次Fork,说明还是有不少开发者在使用和关注的。项目主要特点是Niushop开源商城,本源码是稳定版源码,免费商用。,适合需要快速搭建网站的开发者和站长使用。 # # 项目功能介绍  ### Niushop开源商城开发版 - 前后端全部100%开源 # ## 马上加入Niushop开发者,共同构建新零售电商应用开发生态!!! **开源啦** !!!**商城后端开源** !!!**前端Uniapp代码开源** !!!**100%开源** !!! **无任何加密** !!! **简单而又暴力** !!!技术亮点 - 标准API接口,前后端分离,二次开发更方便 - 内置消息队列,全面支持redis缓存机制,支持大数据、高并发、大流量 - 钩子 + 插件,组件化开发,可复用,开发便捷 - 结构化的商城模板设计,制作加入NiuShop商城开发者生态您将可以获得 1. 加入官方每周一场的商城开发互动直播 2. 学习商城架构,表设计,插件设计,模块化开发思路 3. 官方提供免费而有价值的专业二次开发教程 4. 商城二开项目的接单 5. 开发者开发插件,商城模板,与官方共同销售分成... # ## 产品介绍 **快速搭建专属店铺,迅速展开线上业务** 默默耕耘,是为了在明天硕果累累;沉淀积累,是为了在未来厚积薄发!!自Niushop单商户于2016年上线以来,历时几年时间的迭代更新,应广大用户的要求,Niushop单商户V5时代终于来啦~ V5是一个全新的开始,升级重构多门店、收银一体化、软硬件物联、商品线上线下营销完全打通;前后端代码重组优化80%以上; 更加强大的DIY自定义装修;完全内置消息队列、Redis缓存服务,是大型商城运营的首选,抓紧下载体验起来吧~# ## 操作指南 :fa-th-list: [ | [服务市场]() | [系统功能]() | [系统演示](https://uniapp.v5.niuteam.cn/) | [使用手册](https://www.kancloud.cn/niucloud/niushop_b2c_v5/3037616) | [二开手册](https://www.kancloud.cn/niucloud/niushop_b2c_v4_develop/1839354) | [论坛地址](https://www.niushop.com/web/community/index.html) | [留言评论](https://www.niushop.com/web/community/index.html)# ## 演示站后台[ 查看 ] https://uniapp.v5.niuteam.cn/shop 账号:test 密码:niushoptest ### 演示 ### 推荐阿里云服务器配置  # ## 环境要求 Nignx/Apache PHP 7.4 MySQL 5.6~8.0 Redis 支持# ## Niushop官方群 [ ThinkPhp6 + LayUi + ElementUi,学习维护成本低 2. 前端由UNI-APP框架编写,支持多端,易于维护 3. 钩子 + 插件,组件化开发,可复用,开发便捷 4. 标准API接口,前后端分离,二次开发更方便 5. 内置消息队列,全面支持redis缓存机制,支持大数据、高并发、大流量 6. 代码全部开源,方便企业扩展自身业务需求# ## 亮点 1.框架采用全新thinkphp6+事件开发设计+layui+uniapp进行设计,代码完全重构,支持百万级! 2.前端以layui + uniapp模块化开发; 3.数据导出采用phpExcel,使数据更加直观,更方便于管理统计; 4.插件钩子机制,功能模块独立,更有助于二次开发; 5.后台采用ECharts,直观体现关系数据可视化的图,支持图与图之间的混搭。实现完善的数据统计和分析; 6.Easy 7.内置强大灵活的权限管理体系,有利于专人专项运营; 8.内置组合数据统计,系统配置,管理碎片化数据统计; 9.客户端完善的交互效果和动画,提升用户端视觉体验; 10.可以完美对接公众号和小程序,并且数据同步,实现真正意义上的一端开发,多端使用; 11.内置客服系统,可以对接企微客服、腾讯客服、小程序客服以及Niushop客服,客服在线实时聊天; 12.高频数据redis缓存,数据库读写分离,很大程度减轻服务器压力,提升访问速度; 13.后台设置菜单中可以一键数据备份和恢复,完全傻瓜式操作就可以轻松升级备份; 14.在线一键升级,轻松跨越到最新版本; 15.标准Api接口、前后端分离,二次开发更方便快捷; 16.支持数据库结构、数据、模板在线缓存清除,提升用户体验; 17.可视化DIY店铺装修,方便、快捷、直观,可以随心所欲装扮自己的店铺; 18.无缝事件机制行为扩展更方便,方便二次开发; 19.支持队列降低流量高峰,解除代码耦合性,高可用性; 20.在线一键安装部署,自动检测系统环境一键安装,省时省力快捷部署;# ## 前端部分界面展示 # ## 后端部分界面展示 # ### 好啦!话不多说,相信你早已跃跃欲试了,那就行动起来通过下方链接赶紧下载体验吧! git clone https://gitee.com/niushop-team/niushop_b2c_v5.git # ## 开源版使用须知 1.允许用于个人学习、毕业设计、教学案例、公益事业、商业使用; 2.如果商用必须保留版权信息,请自觉遵守; 3.禁止将本开源的代码和资源进行任何形式任何名义的出售,否则产生的一切任何后果责任由侵权者自负; 4.本版本源码全部开源;包括前端,后端,无任何加密; 5.商用请仔细审查代码和漏洞,不得用于任一国家许可范围之外的商业应用,产生的一切任何后果责任自负; 6.马上加入NiuShop开发者,构建新零售电商应用开发生态; 7.一切事物有个人喜好的标准,本开源代码意在分享,不喜勿喷。 # ## 合作伙伴 .png") # ## 版权信息 版权所有Copyright © 2015-2024 NiuShop开源商城 版权所有 All rights reserved。 牛之云科技有限公司 提供技术支持 以上就是关于**NIUSHOP开源商城 V5 DEV全开源**的简单介绍。这个项目的代码结构清晰,文档也比较完善,对于PHP初学者来说也是一个不错的学习资源。有兴趣的朋友可以通过下方链接下载源码体验一下。 {card-default label="? 项目信息" /} ? 项目名称:NIUSHOP开源商城 V5 DEV全开源 ? 开发作者:niushop](https://qm.# ## V5商城特色 强大的营销功能模块,丰富的行业模板和装修组件,快速搭建最适合自己的电商平台,轻松获客、裂变。开启电商运营之路。 1. -
精选开源工具:thc-hydra 推荐 推荐一个实用的开源工具——**thc-hydra**。项目由vanhauser-thc开发维护,GitHub上获得了 **12244** 个Star。简单来说,它是一款九头蛇,对于站长和开发者来说是个不错的工具。 # # 工具功能介绍 H Y D R A(c) 2001-2023 by van Hauser / THC https://github.com/vanhauser-thc/thc-hydra Many modules were written by David (dot) Maciejak @ gmail (dot) com BFG code by Jan Dlabal Licensed under AGPLv3 (see LICENSE file)Please do not use in military or secret service organizations, or for illegal purposes. (This is the wish of the author and non-binding. Many people working in these organizations do not care for laws and ethics anyway. You are not one of the "good" ones if you ignore this.)NOTE: No, this is not meant to be a markdown doc! old school!Hydra in the most current GitHub state can be directly downloaded via Docker:docker pull vanhauser/hydra INTRODUCTION ------------ Number one of the biggest security holes are passwords, as every password security study shows. This tool is a proof-of-concept code to give researchers and security consultants the possibility of showing how easy it would be to gain unauthorized access from a remote to a system.THIS TOOL IS FOR LEGAL PURPOSES ONLY!There are already several login hacker tools available; however, none of them support more than one protocol to attack or support parallelized connects.It was tested to compile cleanly on Linux, Windows/Cygwin, Solaris, FreeBSD/OpenBSD, QNX (Blackberry 10), and MacOS.Currently, this tool supports the following protocols: Asterisk, AFP, Cisco AAA, Cisco auth, Cisco enable, CVS, Firebird, FTP, HTTP-FORM-GET, HTTP-FORM-POST, HTTP-GET, HTTP-HEAD, HTTP-POST, HTTP-PROXY, HTTPS-FORM-GET, HTTPS-FORM-POST, HTTPS-GET, HTTPS-HEAD, HTTPS-POST, HTTP-Proxy, ICQ, IMAP, IRC, LDAP, MEMCACHED, MONGODB, MS-SQL, MYSQL, NCP, NNTP, Oracle Listener, Oracle SID, Oracle, PC-Anywhere, PCNFS, POP3, POSTGRES, Radmin, RDP, Rexec, Rlogin, Rsh, RTSP, SAP/R3, SIP, SMB, SMTP, SMTP Enum, SNMP v1+v2+v3, SOCKS5, SSH (v1 and v2), SSHKEY, Subversion, Teamspeak (TS2), Telnet, VMware-Auth, VNC and XMPP.However, the module engine for new services is very easy, so it won't take a long time until even more services are supported. Your help in writing, enhancing, or fixing modules is highly appreciated!! :-)WHERE TO GET ------------ You can always find the newest release/production version of Hydra at its project page at https://github.com/vanhauser-thc/thc-hydra/releases If you are interested in the current development state, the public development repository is on GitHub: svn co https://github.com/vanhauser-thc/thc-hydra or git clone https://github.com/vanhauser-thc/thc-hydra Use the development version at your own risk. It contains new features and new bugs. Things might not work!Alternatively (and easier), you can pull it as a Docker container:docker pull vanhauser/hydra HOW TO COMPILE -------------- To configure, compile, and install Hydra, just type:./configure make make install If you want the SSH module, you have to set up libssh (not libssh2!) on your system, get it from https://www.libssh.org, for ssh v1 support you also need to add the "-DWITH_SSH1=On" option in the cmake command line. IMPORTANT: If you compile on macOS, you must do this - do not install libssh via Homebrew.If you use Ubuntu/Debian, this will install the supplementary libraries needed for a few optional modules (note that some might not be available on your distribution):apt-get install libssl-dev libssh-dev libidn11-dev libpcre3-dev \ libgtk-3-dev libmysqlclient-dev libpq-dev libsvn-dev \ firebird-dev libmemcached-dev libgpg-error-dev \ libgcrypt11-dev libgcrypt20-dev freetds-dev This enables all optional modules and features except for Oracle, SAP R/3, NCP, and the Apple filing protocol - which you will need to download and install from the vendor's websites.For all other Linux derivatives and BSD-based systems, use the system software installer and look for similarly named libraries, like in the command above. In all other cases, you have to download all source libraries and compile them manually.SUPPORTED PLATFORMS ------------------- - All UNIX platforms (Linux, *BSD, Solaris, etc.) - MacOS (basically a BSD clone) - Windows with Cygwin (both IPv4 and IPv6) - Mobile systems based on Linux, MacOS, or QNX (e.g. Android, iPhone, Blackberry 10, Zaurus, iPaq)HOW TO USE ---------- If you just enter `hydra`, you will see a short summary of the important options available. Type `./hydra -h` to see all available command line options.Note that NO login/password file is included. Generate them yourself. A default password list is, however, present; use "dpl4hydra.sh" to generate a list.For Linux users, a GTK GUI is available; try `./xhydra`For the command line usage, the syntax is as follows: For attacking one target or a network, you can use the new "://" style: hydra [some command line options] PROTOCOL://TARGET:PORT/MODULE-OPTIONS The old mode can be used for these, too, and additionally, if you want to specify your targets from a text file; you *must* use this one:hydra [some command line options] [-s PORT] TARGET PROTOCOL [MODULE-OPTIONS] Via the command line options, you specify which logins to try, which passwords, if SSL should be used, how many parallel tasks should be used for attacking, etc.PROTOCOL is the protocol you want to use for attacking, e.g., ftp, SMTP, http-get or many others are available TARGET is the target you want to attack MODULE-OPTIONS are optional values that are special per PROTOCOL moduleFIRST - select your target You have three options on how to specify the target you want to attack: 1. A single target on the command line: just put the IP or DNS address in 2. A network range on the command line: CIDR specification like "192.168.0.0/24" 3. A list of hosts in a text file: one line per entry (see below)SECOND - select your protocol Try to avoid telnet, as it is unreliable for detecting a correct or false login attempt. Use a port scanner to see which protocols are enabled on the target.THIRD - check if the module has optional parameters hydra -U PROTOCOL e.g. hydra -U smtpFOURTH - the destination port This is optional; if no port is supplied, the default common port for the PROTOCOL is used. If you specify SSL to use ("-S" option), the SSL common port is used by default.If you use "://" notation, you must use "[" "]" brackets if you want to supply IPv6 addresses or CIDR ("192.168.0.0/24") notations to attack: hydra [some command line options] ftp://[192.168.0.0/24]/ hydra [some command line options] -6 smtps://[2001:db8::1]/NTLMNote that everything Hydra does is IPv4 only! If you want to attack IPv6 addresses, you must add the "-6" command line option. All attacks are then IPv6 only!If you want to supply your targets via a text file, you can not use the :// notation, but use the old style and just supply the protocol (and module options): hydra [some command line options] -M targets.txt ftp You can also supply the port for each target entry by adding ":" after a target entry in the file, e.g.:foo.bar.com target.com:21 unusual.port.com:2121 default.used.here.com 127.0.0.1 127.0.0.1:2121 Note that if you want to attach IPv6 targets, you must supply the -6 option and *must* put IPv6 addresses in brackets in the file(!) like this:foo.bar.com target.com:21 [fe80::1%eth0] [2001::1] [2002::2]:8080 [2a01:24a:133:0:00:123:ff:1a] LOGINS AND PASSWORDS -------------------- You have many options on how to attack with logins and passwords With -l for login and -p for password, you tell Hydra that this is the only login and/or password to try. With -L for logins and -P for passwords, you supply text files with entries. e.g.:hydra -l admin -p password ftp://localhost/ hydra -L default_logins.txt -p test ftp://localhost/ hydra -l admin -P common_passwords.txt ftp://localhost/ hydra -L logins.txt -P passwords.txt ftp://localhost/ Additionally, you can try passwords based on the login via the "-e" option. The "-e" option has three parameters:s - try the login as password n - try an empty password r - reverse the login and try it as a password If you want to, e.g., try "try login as password and "empty password", you specify "-e sn" on the command line.But there are two more modes for trying passwords than -p/-P: You can use a text file where a login and password pair is separated by a colon, e.g.:admin:password test:test foo:bar This is a common default account style listing that is also generated by the dpl4hydra.sh default account file generator supplied with Hydra. You use such a text file with the -C option - note that in this mode you can not use -l/-L/-p/-P options (-e nsr however you can). Example:hydra -C default_accounts.txt ftp://localhost/ And finally, there is a brute-force mode with the -x option (which you can not use with -p/-P/-C):-x minimum_length:maximum_length:charset The charset definition is `a` for lowercase letters, `A` for uppercase letters, `1` for numbers and for anything else, what you supply is their real representation. Examples:-x 1:3:a generate passwords from length 1 to 3 with all lowercase letters -x 2:5:/ generate passwords from length 2 to 5 containing only slashes -x 5:8:A1 generate passwords from length 5 to 8 with uppercase and numbers -x '3:3:aA1&~#\\ "\'$%*?./§,;:!`' -v generates length 3 passwords with all 95 characters, and verbose. Example: hydra -l ftp -x 3:3:a ftp://localhost/ SPECIAL OPTIONS FOR MODULES --------------------------- Via the third command line parameter (TARGET SERVICE OPTIONAL) or the -m command line option, you can pass one option to a module. Many modules use this; a few require it!To see the special option of a module, type:hydra -U e.g../hydra -U http-post-formThe special options can be passed via the -m parameter, as 3rd command line option or in the service://target/option format.Examples (they are all equal):./hydra -l test -p test -m PLAIN 127.0.0.1 imap ./hydra -l test -p test 127.0.0.1 imap PLAIN ./hydra -l test -p test imap://127.0.0.1/PLAIN RESTORING AN ABORTED/CRASHED SESSION ------------------------------------ When Hydra is aborted with Control-C, killed, or crashes, it leaves a "hydra.restore" file behind, which contains all necessary information to restore the session. This session file is written every 5 minutes. NOTE: the hydra.restore file can NOT be copied to a different platform (e.g. from little endian to big endian, or from Solaris to AIX)HOW TO SCAN/CRACK OVER A PROXY ------------------------------ The environment variable HYDRA_PROXY_HTTP defines the web proxy (this works just for the HTTP services!). The following syntax is valid:HYDRA_PROXY_HTTP="http://123.45.67.89:8080/" HYDRA_PROXY_HTTP="http://login:password@123.45.67.89:8080/" HYDRA_PROXY_HTTP="proxylist.txt" The last example is a text file containing up to 64 proxies (in the same format definition as the other examples).For all other services, use the HYDRA_PROXY variable to scan/crack. It uses the same syntax. eg:HYDRA_PROXY=[connect|socks4|socks5]://[login:password@]proxy_addr:proxy_port for example: HYDRA_PROXY=connect://proxy.anonymizer.com:8000 HYDRA_PROXY=socks4://auth:pw@127.0.0.1:1080 HYDRA_PROXY=socksproxylist.txt ADDITIONAL HINTS ---------------- * Sort your password files by likelihood and use the -u option to find passwords much faster! * uniq your dictionary files! This can save you a lot of time :-) cat words.txt | sort | uniq > dictionary.txt * If you know that the target is using a password policy (allowing users only to choose a password with a minimum length of 6, containing at least one letter and one number, etc. use the tool pw-inspector, which comes along with the hydra package, to reduce the password list: cat dictionary.txt | pw-inspector -m 6 -c 2 -n > passlist.txtRESULTS OUTPUT --------------The results are output to stdio along with the other information. Via the -o command line option, the results can also be written to a file. Using -b, the format of the output can be specified. Currently, these are supported:* `text` - plain text format * `jsonv1` - JSON data using version 1.x of the schema (defined below). * `json` - JSON data using the latest version of the schema; currently, there is only version 1.If using JSON output, the results file may not be valid JSON if there are serious errors in booting Hydra.JSON Schema ----------- Here is an example of the JSON output. Notes on some of the fields:* `errormessages` - an array of zero or more strings that are normally printed to stderr at the end of Hydra's run. The text is very free-form. * `success` - indication if Hydra ran correctly without error (**NOT** if passwords were detected). This parameter is either the JSON value `true` or `false` depending on completion. * `quantityfound` - How many username+password combinations were discovered. * `jsonoutputversion` - Version of the schema, 1.00, 1.01, 1.11, 2.00, 2.03, etc. Hydra will make the second tuple of the version to always be two digits to make it easier for downstream processors (as opposed to v1.1 vs v1.10). The minor-level versions are additive, so 1.02 will contain more fields than version 1.00 and will be backward compatible. Version 2.x will break something from the version 1.x output.Version 1.00 example:{ "errormessages": [ "[ERROR] Error Message of Something", "[ERROR] Another Message", "These are very free form" ], "generator": { "built": "2021-03-01 14:44:22", "commandline": "hydra -b jsonv1 -o results.json ... ...", "jsonoutputversion": "1.00", "server": "127.0.0.1", "service": "http-post-form", "software": "Hydra", "version": "v8.5" }, "quantityfound": 2, "results": [ { "host": "127.0.0.1", "login": "bill@example.com", "password": "bill", "port": 9999, "service": "http-post-form" }, { "host": "127.0.0.1", "login": "joe@example.com", "password": "joe", "port": 9999, "service": "http-post-form" } ], "success": false } SPEED ----- Through the parallelizing feature, this password cracker tool can be very fast; however, it depends on the protocol. The fastest are generally POP3 and FTP. Experiment with the task option (-t) to speed things up! The higher - the faster ;-) (but too high - and it disables the service)STATISTICS ---------- Run against a SuSE Linux 7.2 on localhost with a "-C FILE" containing 295 entries (294 tries invalid logins, 1 valid). Every test was run three times (only for "1 task" just once), and the average was noted down.P A R A L L E L T A S K S SERVICE 1 4 8 16 32 50 64 100 128 ------- -------------------------------------------------------------------- telnet 23:20 5:58 2:58 1:34 1:05 0:33 0:45* 0:25* 0:55* ftp 45:54 11:51 5:54 3:06 1:25 0:58 0:46 0:29 0:32 pop3 92:10 27:16 13:56 6:42 2:55 1:57 1:24 1:14 0:50 imap 31:05 7:41 3:51 1:58 1:01 0:39 0:32 0:25 0:21 (*) Note: telnet timings can be VERY different for 64 to 128 tasks! e.g. with 128 tasks, running four times, resulted in timings between 28 and 97 seconds! The reason for this is unknown...guesses per task (rounded up):295 74 38 19 10 6 5 3 3guesses possible per connect ...{card-default label="? 工具信息" /} ? 项目地址:[https://github.com/vanhauser-thc/thc-hydra](https://github.com/vanhauser-thc/thc-hydra) ⭐ Star数:12244 ? 开发语言:C ? 项目描述:九头蛇 {/card-default}{cloud type="default" title="网盘下载" url="https://github.com/vanhauser-thc/thc-hydra/archive/refs/heads/master.zip"} {cloud type="default" title="网盘下载" url="https://github.com/vanhauser-thc/thc-hydra"}总的来说,**thc-hydra**是一个功能比较实用的开源工具,适合日常工作和学习使用。如果你正在寻找一款相关工具,不妨下载试试。使用前建议仔细阅读项目文档。 -
phpcms 开源项目下载 - 基于PHP的开源网站系统 最近在Gitee上发现了一个不错的PHP项目phpcms,Star数达到662,看来挺受欢迎的。这个项目的主要功能是PHPCMS V9内容管理系统,下面给大家详细介绍一下它的功能和使用方法。 项目功能介绍 该仓库是在phpcms v9.6.3的镜像基础上进行维护的。 由于各种原因phpcms官方不再维护,而大量的phpcms用户面临着各种bug风险。 现在我们建立此仓库提供bug修复、新模块、新插件,继续让phpcms在网站开发建设的路上发光发热,紧跟时代步伐。 综合来看,phpcms在同类项目中还是有一定优势的,特别是在功能完整性和易用性方面表现不错。如果你有相关需求,可以下载试试。使用过程中如果遇到问题,也可以去项目主页提交Issue反馈。 {card-default label="? 项目信息" /} ? 项目名称:phpcms ? 开发作者:phpcms ? 项目描述:PHPCMS V9内容管理系统 ? 开发语言:PHP ? 开源协议:未知开源协议 ⭐ Star数:662 | ? Fork数:37 ? 更新时间:2026年06月23日 {/card-default} {cloud type="default" title="网盘下载" url="https://gitee.com/phpcms/phpcms/repository/archive/master.zip"} {cloud type="default" title="网盘下载" url="https://gitee.com/phpcms/phpcms.git"} -
免费开源绿色软件推荐:fuzzdb-collect 下载 推荐一个实用的开源工具——fuzzdb-collect。项目由euphratica开发维护,采用未知开源协议发布。简单来说,它是一个网络上安全资源的搜集,对于站长和开发者来说是个不错的工具。 工具功能介绍 项目简介 Scanners Box是一个集合github平台上的安全行业从业者自研开源扫描器的仓库,包括子域名枚举、数据库漏洞扫描、弱口令或信息泄漏扫描、端口扫描、指纹识别以及其他大型扫描器或模块化扫描器,同时该仓库只收录各位网友自己编写的一般性开源扫描器,类似awvs、nmap、w3af等知名扫描工具不收录。 恶意软件 https://github.com/deadPix3l/CryptSky/ (勒索软件) DDOS防护 https://github.com/ywjt/Dshield waf开源及规则 https://github.com/SpiderLabs/ModSecurity https://github.com/xsec-lab/x-waf https://github.com/loveshell/ngx_lua_waf https://github.com/SpiderLabs/owasp-modsecurity-crs/tree/master/base_rules 入门指南 https://wizardforcel.gitbooks.io/web-hacking-101/content/ Web Hacking 101 中文版 https://wizardforcel.gitbooks.io/asani/content/ 浅入浅出Android安全 中文版 https://wizardforcel.gitbooks.io/lpad/content/ Android 渗透测试学习手册 中文版 https://wizardforcel.gitbooks.io/kali-linux-web-pentest-cookbook/content/ Kali Linux Web渗透测试秘籍 中文版 https://github.com/hardenedlinux/linux-exploit-development-tutorial Linux exploit 开发入门 https://www.gitbook.com/book/t0data/burpsuite/details burpsuite实战指南 http://www.kanxue.com/?article-read-1108.htm=&winzoom=1 渗透测试Node.js应用 https://github.com/qazbnm456/awesome-web-security Web安全资料和资源列表 https://sec-wiki.com/ sec-wiki安全维基百科 fuzz工具收集 https://github.com/ivanfratric/winafl https://github.com/attekett/NodeFuzz https://github.com/google/oss-fuzz http://blog.topsec.com.cn/ad_lab/alphafuzzer/ http://llvm.org/docs/LibFuzzer.html 子域名枚举扫描器或爆破工具 https://github.com/n4xh4ck5/N4xD0rk (利用搜索引擎来搜集子域名,可以使用西班牙语搜集) https://github.com/jonluca/Anubis https://github.com/lijiejie/subDomainsBrute (lijiejie开发的一款使用广泛的子域名爆破枚举工具) https://github.com/ring04h/wydomain (猪猪侠开发的一款域名收集全面、精准的子域名枚举工具) https://github.com/le4f/dnsmaper (子域名枚举爆破工具以及地图位置标记) https://github.com/0xbug/orangescan (提供web界面的在线子域名信息收集工具) https://github.com/TheRook/subbrute (高效精准的子域名爆破工具,同时也是扫描器中最常用的子域名API库) https://github.com/We5ter/GSDF (基于谷歌SSL透明证书的子域名查询脚本) https://github.com/mandatoryprogrammer/cloudflare_enum (使用CloudFlare进行子域名枚举的脚本) https://github.com/guelfoweb/knock (Knock子域名获取,可用于查找子域名接管漏洞) https://github.com/exp-db/PythonPool/tree/master/Tools/DomainSeeker (多方式收集目标子域名信息) https://github.com/code-scan/BroDomain (兄弟域名查询) https://github.com/chuhades/dnsbrute (高效的子域名爆破工具) https://github.com/yanxiu0614/subdomain3 (一款高效的子域名爆破工具) https://github.com/michenriksen/aquatone (子域名枚举、探测工具。可用于子域名接管漏洞探测) https://github.com/evilsocket/dnssearch (一款子域名爆破工具) https://github.com/reconned/domained (可用于子域名收集的一款工具) https://github.com/bit4woo/Teemo (域名收集及枚举工具) https://github.com/laramies/theHarvester ( https://github.com/swisskyrepo/Subdomino (子域名枚举,端口扫描,服务存活确认) https://github.com/nmalcolm/Inventus (通过爬虫实现的子域名收集工具) https://github.com/aboul3la/Sublist3r (快速子域枚举工具) 数据库类漏洞扫描器或爆破工具 https://github.com/0xbug/SQLiScanner (一款基于SQLMAP和Charles的被动SQL注入漏洞扫描工具) https://github.com/sqlmapproject/sqlmap (注入工具之王sqlmap) https://github.com/stamparm/DSSS (99行代码实现的sql注入漏洞扫描器) https://github.com/LoRexxar/Feigong (针对各种情况自由变化的MySQL注入脚本) https://github.com/youngyangyang04/NoSQLAttack (一款针对mongoDB的攻击工具) https://github.com/Neohapsis/bbqsql (SQL盲注利用框架) https://github.com/NetSPI/PowerUpSQL (攻击SQLSERVER的Powershell脚本框架) https://github.com/WhitewidowScanner/whitewidow (一款数据库扫描器) https://github.com/stampery/mongoaudit (MongoDB审计及渗透工具) https://github.com/torque59/Nosql-Exploitation-Framework (NoSQL扫描/爆破工具) https://github.com/missDronio/blindy (MySQL盲注爆破工具) https://github.com/fengxuangit/Fox-scan (基于SQLMAP的主动和被动资源发现的漏洞扫描工具) https://github.com/NetSPI/PowerUpSQL (用于SQL Server审计的powershell脚本) https://github.com/JohnTroony/Blisqy (用于- http header中的时间盲注爆破工具,仅针对MySQL/MariaDB) https://github.com/ron190/jsql-injection (Java 编写的SQL注入工具) https://github.com/Hadesy2k/sqliv (基于搜索引擎的批量SQL注入漏洞扫描器) https://github.com/UltimateHackers/sqlmate (在sqlmap基础上增加了目录扫描、hash爆破等功能) 弱口令/弱用户名扫描器或爆破工具 https://github.com/lijiejie/htpwdScan (一个简单的- http暴力破解、撞库攻击脚本) https://github.com/ysrc/F-Scrack (对各类服务进行弱口令检测的脚本) https://github.com/Mebus/cupp (根据用户习惯生成弱口令探测字典脚本) https://github.com/netxfly/crack_ssh (Go写的协程版的ssh edis\mongodb弱口令破解工具) https://github.com/LandGrey/pydictor (暴力破解字典建立工具) https://github.com/shengqi158/weak_password_detect (多线程探测弱口令) https://github.com/UltimateHackers/Blazy (支持测试 CSRF, Clickjacking, Cloudflare and WAF的弱口令探测器) 物联网设备识别工具或扫描器 https://github.com/reverse-shell/routersploit (路由器漏洞利用框架) https://github.com/jh00nbr/Routerhunter-2.0 (路由器漏洞扫描利用) https://github.com/RUB-NDS/PRET (打印机攻击框架) https://github.com/rapid7/IoTSeeker (物联网设备默认密码扫描检测工具) https://github.com/shodan-labs/iotdb (使用nmap扫描IoT设备) https://github.com/googleinurl/RouterHunterBR (路由器设备漏洞扫描利用) https://github.com/scu-igroup/telnet-scanner (Telnet服务密码撞库) 反射型或DOM-Based XSS扫描器 https://github.com/shawarkhanethicalhacker/BruteXSS (一款XSS扫描器,可暴力注入参数) https://github.com/1N3/XSSTracer (小型XSS扫描器,也可检测CRLF、XSS、点击劫持的) https://github.com/0x584A/fuzzXssPHP (PHP版本的反射型xss扫描) https://github.com/chuhades/xss_scan (批量扫描XSS的python脚本) https://github.com/BlackHole1/autoFindXssAndCsrf (自动化检测页面是否存在XSS和CSRF漏洞的浏览器插件) https://github.com/shogunlab/shuriken (使用命令行进行XSS批量检测) https://github.com/UltimateHackers/XSStrike (可识别并绕过WAF的XSS扫描工具) https://github.com/stamparm/DSXS (支持GET、POST方式的高效XSS扫描器) 企业资产管理或信息泄露搜集工具 https://github.com/ysrc/xunfeng (网络资产识别引擎,漏洞检测引擎) https://github.com/laramies/theHarvester (企业被搜索引擎收录敏感资产信息监控脚本:员工 https://github.com/x0day/Multisearch-v2 (Bing、google、360、zoomeye等搜索引擎聚合搜索,可用于发现企业被搜索引擎收录的敏感资产信息) https://github.com/Ekultek/Zeus-Scanner (集成化的综合搜索引擎,能够抓取被搜索引擎隐藏的url,并交由sqlmap、nmap扫描) https://github.com/0xbug/Biu-framework (企业内网基础服务安全扫描框架) https://github.com/metac0rtex/GitHarvester (github Repo信息搜集工具) https://github.com/shengqi158/svnhack (.svn文件夹泄漏利用工具) https://github.com/repoog/GitPrey (GitHub敏感信息扫描工具) https://github.com/0xbug/Hawkeye (企业资产、敏感信息GitHub泄露监控系统) https://github.com/lianfeng30/githubscan (根据企业关键词进行项目检索以及相应敏感文件和文件内容扫描的工具) https://github.com/UnkL4b/GitMiner (github敏感信息搜索工具) https://github.com/lijiejie/GitHack (.git文件夹泄漏利用工具) https://github.com/dxa4481/truffleHog (GitHub敏感信息扫描工具,包括检测commit等) https://github.com/sowish/LNScan (详细的内部网络信息扫描器) https://github.com/SkyLined/LocalNetworkScanner (javascript实现的本地网络扫描器) https://github.com/x0day/Multisearch-v2 (搜索引擎聚合搜索,可用于发现企业被搜索引擎收录的敏感资产信息) webshell检测或病毒分析工具 https://github.com/ym2011/ScanBackdoor (一款简洁的Webshell扫描工具) https://github.com/yassineaddi/BackdoorMan (可对指定目录进行php webshell检测) https://github.com/he1m4n6a/findWebshell (一款简单的webshell检测工具) https://github.com/Tencent/HaboMalHunter (哈勃分析系统,linux系统病毒分析及安全检测) https://github.com/PlagueScanner/PlagueScanner (使用python实现的集成ClamAV、ESET、Bitdefender的反病毒引擎) https://github.com/nbs-system/php-malware-finder (一款高效率PHP-webshell扫描工具) https://github.com/emposha/PHP-Shell-Detector/ (测试效率高达99%的webshell检测工具) https://github.com/erevus-cn/scan_webshell (一款简洁的Webshell扫描工具) https://github.com/emposha/Shell-Detector (Webshell扫描工具,支持php/perl/asp/aspx webshell扫描) https://github.com/m4rco-/dorothy2 (一款木马、僵尸网络分析框架) 内网渗透或扫描工具 https://github.com/0xwindows/VulScritp (企业内网渗透脚本,包括banner扫描、端口扫描;phpmyadmin、jenkins等通用漏洞利用等) https://github.com/lcatro/network_backdoor_scanner (基于网络流量的内网探测框架) https://github.com/fdiskyou/hunter (调用 Windows API 枚举用户登录信息) https://github.com/BlackHole1/WebRtcXSS (自动化利用XSS入侵内网) https://github.com/0xwindows/VulScritp (企业内网渗透脚本,包括banner扫描、端口扫描;各种通用漏洞利用等) https://github.com/fdiskyou/hunter (调用 Windows API 枚举用户登录信息) https://github.com/AlessandroZ/LaZagne (本机密码查看提取工具) https://github.com/huntergregal/mimipenguin (linux密码抓取神器) 中间件扫描器或识别工具 https://nmap.org/download.html (Nmap端口扫描器之王,- https://svn.nmap.org/) https://github.com/ring04h/wyportmap (目标端口扫描+系统服务指纹识别) https://github.com/ring04h/weakfilescan (动态多线程敏感信息泄露检测工具) https://github.com/EnableSecurity/wafw00f (WAF产品指纹识别) https://github.com/rbsec/sslscan (ssl类型识别) https://github.com/urbanadventurer/whatweb (web指纹识别) https://github.com/tanjiti/FingerPrint (web应用指纹识别) https://github.com/nanshihui/Scan-T (网络爬虫式指纹识别) https://github.com/OffensivePython/Nscan (a fast Network scanner inspired by Masscan and Zmap) https://github.com/ywolf/F-NAScan (网络资产信息扫描, ICMP存活探测,端口扫描,端口指纹服务识别) https://github.com/ywolf/F-MiddlewareScan (中间件扫描) https://github.com/maurosoria/dirsearch (Web path scanner) https://github.com/x0day/bannerscan (C段Banner与路径扫描) https://github.com/RASSec/RASscan (端口服务扫描) https://github.com/3xp10it/bypass_waf (waf自动暴破) https://github.com/3xp10it/xcdn (尝试找出cdn背后的真实ip) https://github.com/Xyntax/BingC (基于Bing搜索引擎的C段/旁站查询,多线程,支持API) https://github.com/Xyntax/DirBrute (多线程WEB目录爆破工具) https://github.com/zer0h/- httpscan (一个爬虫式的网段Web主机发现小工具) https://github.com/lietdai/doom (thorn上实现的分布式任务分发的ip端口漏洞扫描器) https://github.com/chichou/grab.js (类似 zgrab 的快速 TCP 指纹抓取解析工具,支持更多协议) https://github.com/Nitr4x/whichCDN (CDN识别、检测) https://github.com/secfree/bcrpscan (基于爬虫的web路径扫描器) https://github.com/ring04h/wyportmap (目标端口扫描+系统服务指纹识别) https://github.com/rbsec/sslscan (SSL类型识别) https://github.com/urbanadventurer/whatweb (Web指纹识别) https://github.com/tanjiti/FingerPrint (Web应用指纹识别) https://github.com/OffensivePython/Nscan (基于Masscan和Zmap的网络扫描器) https://github.com/maurosoria/dirsearch (web路径收集与扫描) https://github.com/3xp10it/xcdn (尝试找出cdn背后的真实ip) https://github.com/lietdai/doom (Thorn上实现的分布式任务分发的ip端口漏洞扫描器) https://github.com/mozilla/ssh_scan (服务器ssh配置信息扫描) https://github.com/18F/domain-scan (针对域名及其子域名的资产数据检测/扫描,包括- http/- https检测等) https://github.com/ggusoft/inforfinder (域名资产收集及指纹识别工具) https://github.com/boy-hack/gwhatweb (CMS识别 python gevent实现) https://github.com/Mosuan/FileScan (敏感文件扫描 / 二次判断降低误报率 / 扫描内容规则化 / 多目录扫描) https://github.com/Xyntax/FileSensor (基于爬虫的动态敏感文件探测工具) https://github.com/deibit/cansina (web路径扫描工具) https://github.com/0xbug/Howl (网络设备 web 服务指纹扫描与检索) https://github.com/mozilla/cipherscan (目标主机服务ssl类型识别) https://github.com/xmendez/wfuzz (Web应用fuzz工具、框架,同时可用于web路径/服务扫描) https://github.com/UltimateHackers/Breacher (多线程的后台路径扫描器,也可用于发现Execution After Redirect漏洞) https://github.com/ztgrace/changeme (弱口令扫描器,不仅支持普通登录页,也支持ssh、mongodb等组件) https://github.com/medbenali/CyberScan (渗透测试辅助工具,支持分析数据包、解码、端口扫描、IP地址分析等) https://github.com/m0nad/HellRaiser (基于nmap的扫描器,与cve漏洞关联) https://github.com/scipag/vulscan (基于nmap的高级漏洞扫描器,命令行环境使用) https://github.com/jekyc/wig (web应用信息搜集工具) https://github.com/eldraco/domain_analyzer (围绕web服务的域名进行信息收集和"域传送"等漏洞扫描,也支持针对背后的服务器端口扫描等) https://github.com/cloudtracer/paskto (基于Nikto扫描规则的被动式路径扫描以及信息爬虫) https://github.com/zerokeeper/WebEye (快速识别WEB服务器类型、CMS类型、WAF类型、WHOIS信息、以及语言框架) https://github.com/m3liot/shcheck (用于检查web服务的- http header的安全性) https://github.com/aipengjie/sensitivefilescan (一款高效快捷的敏感文件扫描工具) https://github.com/fnk0c/cangibrina (通过字典穷举、google、robots.txt等途径的跨平台后台管理路径扫描器) https://github.com/n4xh4ck5/CMSsc4n (CMS指纹识别) 专用(即特定性针对某些组件)扫描器 https://github.com/brianwrf/hackUtils (java反序列化利用工具集) https://github.com/frohoff/ysoserial ( java反序列化利用工具) https://github.com/blackye/Jenkins (Jenkins漏洞探测、用户抓取爆破) https://github.com/code-scan/dzscan (discuz漏洞扫描) https://github.com/chuhades/CMS-Exploit-Framework (CMS攻击框架) https://github.com/lijiejie/IIS_shortname_Scanner (IIS短文件名漏洞扫描) https://github.com/riusksk/FlashScanner (flashxss扫描) https://github.com/coffeehb/SSTIF (服务器端模板注入漏洞的半自动化工具) https://github.com/epinna/tplmap (服务器端模板注入漏洞检测与利用工具) https://github.com/cr0hn/dockerscan (docker扫描工具) https://github.com/GoSecure/break-fast-serial (借助DNS解析来检测Java反序列化漏洞工具) https://github.com/dirtycow/dirtycow.github.io (脏牛提权漏洞exp) https://github.com/code-scan/dzscan (首款集成化的Discuz扫描工具) https://github.com/chuhades/CMS-Exploit-Framework (一款简洁优雅的CMS扫描利用框架) https://github.com/lijiejie/IIS_shortname_Scanner (IIS短文件名暴力枚举漏洞利用工具) https://github.com/coffeehb/SSTIF (一个Fuzzing服务器端模板注入漏洞的半自动化工具) https://github.com/cr0hn/dockerscan (Docker扫描工具) https://github.com/m4ll0k/WPSeku (一款精简的wordpress扫描工具) https://github.com/rastating/wordpress-exploit-framework (集成化wordpress漏洞利用框架) https://github.com/ilmila/J2EEScan (用于扫描J2EE应用的一款burpsuite插件) https://github.com/riusksk/StrutScan (一款基于perl的strut2的历史漏洞扫描器) https://github.com/D35m0nd142/LFISuite (本地文件包含漏洞利用及扫描工具,支持反弹shell) https://github.com/0x4D31/salt-scanner (基于Salt Open以及Vulners Linux Audit API的linux漏洞扫描器,支持与JIRA、slack平台结合使用) https://github.com/tijme/angularjs-csti-scanner (自动化探测客户端AngularJS模板注入漏洞工具) https://github.com/irsdl/IIS-ShortName-Scanner (Java编写的IIS短文件名暴力枚举漏洞利用工具) https://github.com/swisskyrepo/Wordpresscan (基于WPScan以及WPSeku的优化版wordpress扫描器) https://github.com/CHYbeta/cmsPoc (CMS渗透测试框架) https://github.com/rudSarkar/crlf-injector (CRLF注入漏洞批量扫描) https://github.com/3gstudent/Smbtouch-Scanner (自动化扫描内网中存在的由shadow brokers泄露的ETERNAL系列漏洞) https://github.com/utiso/dorkbot (通过定制化的谷歌搜索引擎进行漏洞页面搜寻及扫描) https://github.com/OsandaMalith/LFiFreak (本地文件包含漏洞利用及扫描工具,支持反弹shell) https://github.com/mak-/parameth (用于枚举脚本的GET/POST未知参数字段) https://github.com/Lucifer1993/struts-scan (struts2漏洞全版本检测和利用工具) https://github.com/hahwul/a2sv (SSL漏洞扫描,例如心脏滴血漏洞等) https://github.com/NullArray/DorkNet (基于搜索引擎的漏洞网页搜寻) https://github.com/NickstaDB/BaRMIe (用于攻击爆破Java Remote Method Invocation服务的工具) https://github.com/RetireJS/grunt-retire (扫描js扩展库的常见漏洞) https://github.com/kotobukki/BDA (针对hadoop/spark等大数据平台的的漏洞探测工具) https://github.com/jagracey/Regex-DoS (RegEx 拒绝服务扫描器) https://github.com/milesrichardson/docker-onion-nmap (使用nmap扫描Tor网络上隐藏的"onion"服务) https://github.com/Moham3dRiahi/XAttacker (Web CMS Exploit 工具,包含针对主流 CMS 的 66 个不同的 Exploits) https://github.com/lijiejie/BBScan (一个迷你的信息泄漏批量扫描脚本) 无线网络(审计)扫描器 https://github.com/savio-code/fern-wifi-cracker/ (无线安全审计工具) https://github.com/m4n3dw0lf/PytheM (Python网络/渗透测试工具) https://github.com/P0cL4bs/WiFi-Pumpkin (无线安全渗透测试套件) https://github.com/MisterBianco/BoopSuite (无线网络审计工具,支持2-5GHZ频段) https://github.com/DanMcInerney/LANs.py (ARP欺骗,无线网络劫持) https://github.com/besimaltnok/PiFinger (检查wifi是否是"大菠萝"所开放的热点,并给予网络评分) https://github.com/derv82/wifite2 (自动化无线网络攻击工具wifite的重构版本) 局域网络(本地网络)扫描器 https://github.com/sowish/LNScan (基于BBScan via.lijiejie的本地网络扫描) https://github.com/niloofarkheirkhah/nili (网络扫描,中间人攻击,协议检测与逆向) https://github.com/SkyLined/LocalNetworkScanner (基于javascript的本地网络扫描) 代码审计工具或扫描器 https://github.com/wufeifei/cobra (白盒代码安全审计系统) https://github.com/OneSourceCat/phpvulhunter (静态php代码审计) https://github.com/Qihoo360/phptrace (跟踪、分析PHP运行情况的工具) https://github.com/ajinabraham/NodeJsScan (NodeJS应用代码审计) https://github.com/shengqi158/pyvulhunter (Python应用审计) https://github.com/presidentbeef/brakeman ( Ruby on ... 综合来看,fuzzdb-collect在同类工具中还是有一定优势的,特别是在功能完整性和易用性方面表现不错。如果你有相关需求,可以下载试试。 {card-default label="? 工具信息" /} ? 工具名称:fuzzdb-collect ? 开发作者:euphratica ? 工具描述:网络上安全资源的搜集 ? 开发语言:Python ? 开源协议:未知开源协议 ⭐ Star数:2 | ? Fork数:1 ? 更新时间:2026年08月06日 {/card-default} {cloud type="default" title="网盘下载" url="https://gitee.com/euphratica/fuzzdb-collect/repository/archive/master.zip"} {cloud type="default" title="网盘下载" url="https://gitee.com/euphratica/fuzzdb-collect.git"} -
2026年值得收藏的开源项目:NIUSHOP 开源商城 V6 开源版 源码分享 今天给大家分享一款基于PHP开发的开源项目——NIUSHOP 开源商城 V6 开源版。这个项目在Gitee上获得了14676个Star,1348次Fork,说明还是有不少开发者在使用和关注的。项目主要特点是NIUSHOP开源商城 V6,优秀的架构设计!代码干净,高质量,为开发者而生!前后端API接口分离!前端采用最流行技术Vite+TypeScript+Vue3+ElementPlus,国内首例使用TP8 、PHP8、MYSQL8最新技术。 内置代码生成器,插件生成器,一键云编译、一键云部署、一键小程序发布。是一款快速搭建开发企业级应用的软件系统。100%开源无加密!,适合需要快速搭建网站的开发者和站长使用。 项目功能介绍 输入图片说明 niucloud-admin是什么? niucloud-admin是一款快速开发通用管理后台框架,前端采用最新的技术栈Vite+TypeScript+Vue3+ElementPlus最流行技术架构,后台结合PHP8、Java SDK、Python等主流后端语言搭建,内置集成用户权限、代码生成器、表单设计、云存储、短信发送、素材中心、 niucloud-admin采用的技术亮点 后台php采用thinkphp8+php8+mysql,支持composer快速安装扩展,支持redis缓存以及消息队列,支持多语言设计开发,同时开发采用严格的restful的api设计开发。 后台前后端分离采用element-plus、vue3.0、typescript、vite、pina等前端技术,同时使用i18n支持国际化多语言开发。 - 操作指南 [ | 服务市场 | 使用手册 | 二开手册 | API接口手册 | 论坛地址 演示地址 管理后台演示网址:[ 查看 ] http://v6.site.niucloud.com 账号:admin 密码:123456 H5前端演示网址:[ 查看 ] https://v6.site.niucloud.com/wap/ 账号:admin 密码:123456 开源使用须知 1.允许用于个人学习、毕业设计、教学案例、公益事业、商业使用; 2.本框架应用源代码所有权和著作权归niucloud官方所有,基于niucloud-admin框架开发的应用,所有权和著作权归应用开发商所有。但必须明确声明是基于niucloud-admin框架开发,请自觉遵守,否则产生的一切任何后果责任由侵权者自负; 3.禁止修改框架代码并再次发布框架衍生版等与niucloud-admin框架产生恶意竞争或对抗的行为; 4.本框架源码全部开源;包括前端,后端,无任何加密; 5.商用请仔细审查代码和漏洞,不得用于任一国家许可范围之外的商业应用,产生的一切任何后果责任自负; 6.一切事物有个人喜好的标准,本开源代码意在分享,不喜勿喷。 版权信息 版权所有Copyright © 2015-2030 niucloud-admin 版权所有 All rights reserved。 杭州数字云动科技有限公司 杭州牛之云科技有限公司 提供技术支持 以上就是关于NIUSHOP 开源商城 V6 开源版的简单介绍。这个项目的代码结构清晰,文档也比较完善,对于PHP初学者来说也是一个不错的学习资源。有兴趣的朋友可以通过下方链接下载源码体验一下。 {card-default label="? 项目信息" /} ? 项目名称:NIUSHOP 开源商城 V6 开源版 ? 开发作者:niushop ? 项目描述:NIUSHOP开源商城 V6,优秀的架构设计!代码干净,高质量,为开发者而生!前后端API接口分离!前端采用最流行技术Vite+TypeScript+Vue3+ElementPlus,国内首例使用TP8 、PHP8、MYSQL8最新技术。 内置代码生成器,插件生成器,一键云编译、一键云部署、一键小程序发布。是一款快速搭建开发企业级应用的软件系统。100%开源无加密! ? 开发语言:PHP ? 开源协议:未知开源协议 ⭐ Star数:14676 | ? Fork数:1348 ? 更新时间:2026年09月06日 {/card-default} {cloud type="default" title="网盘下载" url="https://gitee.com/niushop-team/niushop/repository/archive/master.zip"} {cloud type="default" title="网盘下载" url="https://gitee.com/niushop-team/niushop.git"} -
分享一个不错的开源工具:osv-scanner 推荐一个实用的开源工具——**osv-scanner**。项目由google开发维护,GitHub上获得了 **10990** 个Star。简单来说,它是一款用Go编写的漏洞扫描程序,使用https://osv.dev提供的数据,对于站长和开发者来说是个不错的工具。 # # 工具功能介绍 ---Use OSV-Scanner to find existing vulnerabilities affecting your project's dependencies. OSV-Scanner provides an officially supported frontend to the [OSV database](https://osv.dev/) and CLI interface to [OSV-Scalibr](https://github.com/google/osv-scalibr) that connects a project’s list of dependencies with the vulnerabilities that affect them.OSV-Scanner supports a wide range of project types, package managers and features, including but not limited to:- **Languages:** C/C++, Dart, Elixir, Go, Java, Javascript, PHP, Python, R, Ruby, Rust. - **Package Managers:** npm, pip, yarn, maven, go modules, cargo, gem, composer, nuget and others. - **Operating Systems:** Detects vulnerabilities in OS packages on Linux systems. - **Containers:** Scans container s for vulnerabilities in their base s and included packages. - **Guided Remediation:** Provides recommendations for package version upgrades based on criteria such as dependency depth, minimum severity, fix strategy, and return on investment.OSV-Scanner uses the extensible [OSV-Scalibr](https://github.com/google/osv-scalibr) library under the hood to provide this functionality. If a language or package manager is not supported currently, please file a [feature request.](https://github.com/google/osv-scanner/issues)The underlying database, [OSV.dev](https://osv.dev/) has several benefits in comparison with closed source advisory databases and scanners:- Covering most open source language and OS ecosystems (including [Git](https://osv.dev/list?q=&ecosystem=GIT)), it’s comprehensive. - Each advisory comes from an open and authoritative source (e.g. [GitHub Security Advisories](https://github.com/github/advisory-database), [RustSec Advisory Database](https://github.com/rustsec/advisory-db), [Ubuntu security notices](https://github.com/canonical/ubuntu-security-notices/tree/main/osv)) - Anyone can suggest improvements to advisories, resulting in a very high quality database. - The OSV format unambiguously stores information about affected versions in a machine-readable format that precisely maps onto a developer’s list of packagesThe above all results in accurate and actionable vulnerability notifications, which reduces the time needed to resolve them. Check out [OSV.dev](https://osv.dev/) for more details!## Basic installationTo install OSV-Scanner, please refer to the [installation section](https://google.github.io/osv-scanner/installation) of our documentation. OSV-Scanner releases can be found on the [releases page](https://github.com/google/osv-scanner/releases) of the GitHub repository. The recommended method is to download a prebuilt binary for your platform. Alternatively, you can use `go install github.com/google/osv-scanner/v2/cmd/osv-scanner@latest` to build it from source. ## Key FeaturesFor more information, please read our [detailed documentation](https://google.github.io/osv-scanner) to learn how to use OSV-Scanner. For detailed information about each feature, click their titles in this README.Please note: These are the instructions for the latest OSV-Scanner V2 beta. If you are using V1, checkout the V1 [README](https://github.com/google/osv-scanner-v1) and [documentation](https://google.github.io/osv-scanner-v1/) instead. ### [Scanning a source directory](https://google.github.io/osv-scanner/usage) bash $ osv-scanner scan source -r /path/to/your/dir This command will recursively scan the specified directory for any supported package files, such as `package.json`, `go.mod`, `pom.xml`, etc. and output any discovered vulnerabilities.OSV-Scanner has the option of using call analysis to determine if a vulnerable function is actually being used in the project, resulting in fewer false positives, and actionable alerts.OSV-Scanner can also detect vendored C/C++ code for vulnerability scanning. See [here](https://google.github.io/osv-scanner/usage/#cc-scanning) for details. #### Supported LockfilesOSV-Scanner supports 11+ language ecosystems and 19+ lockfile types. To check if your ecosystem is covered, please check out our [detailed documentation](https://google.github.io/osv-scanner/supported-languages-and-lockfiles/#supported-lockfiles). ### [Container Scanning](https://google.github.io/osv-scanner/usage/scan-)OSV-Scanner also supports comprehensive, layer-aware scanning for container s to detect vulnerabilities in the following operating system packages and language-specific dependencies.| Distro Support | Language Artifacts Support | | -------------- | -------------------------- | | Alpine OS | Go | | Debian | Java | | Ubuntu | Node | | | Python |See the [full documentation](https://google.github.io/osv-scanner/supported-languages-and-lockfiles/#supported-artifacts) for details on support.**Usage**: bash $ osv-scanner scan my--name:tag  ### [License Scanning](https://google.github.io/osv-scanner/usage/license-scanning/)Check your dependencies' licenses using deps.dev data. For a summary: bash osv-scanner --licenses path/to/repository To check against an allowed license list (SPDX format): bash osv-scanner --licenses="MIT,Apache-2.0" path/to/directory ### [Offline Scanning](https://google.github.io/osv-scanner/usage/offline-mode/)Scan your project against a local OSV database. No network connection is required after the initial database download. The database can also be manually downloaded. bash osv-scanner --offline --download-offline-databases ./path/to/your/dir ### [Guided Remediation](https://google.github.io/osv-scanner/experimental/guided-remediation/) (Experimental)> [!WARNING] > Guided remediation (the `fix` command) can be risky when run on untrusted projects. It may trigger the package manager to execute scripts or follow external registries specified in the project. Please ensure you trust the source code and artifacts before proceeding.OSV-Scanner provides guided remediation, a feature that suggests package version upgrades based on criteria such as dependency depth, minimum severity, fix strategy, and return on investment. We currently support remediating vulnerabilities in the following files:| Ecosystem | File Format (Type) | Supported Remediation Strategies | | :-------- | :----------------------------- | :--------------------------------------------------------------------------------------------------------------------- | | npm | `package-lock.json` (lockfile) | [`in-place`](https://google.github.io/osv-scanner/experimental/guided-remediation/#in-place-lockfile-changes) | | npm | `package.json` (manifest) | [`relock`](https://google.github.io/osv-scanner/experimental/guided-remediation/#relock-and-relax-direct-dependencies) | | Maven | `pom.xml` (manifest) | [`override`](https://google.github.io/osv-scanner/experimental/guided-remediation/#override-dependency-versions) |This is available as a headless CLI command, as well as an interactive mode.#### Example (for npm) bash $ osv-scanner fix \ --max-depth=3 \ --min-severity=5 \ --ignore-dev \ --strategy=in-place \ -L path/to/package-lock.json #### Interactive mode (for npm) bash $ osv-scanner fix \ -M path/to/package.json \ -L path/to/package-lock.json ## Data Sources and PrivacyOSV-Scanner communicates with the following external services during operation: ### [OSV.dev API](https://osv.dev/)The primary data source for vulnerability information. OSV-Scanner queries this API to check packages for known vulnerabilities and to identify vendored C/C++ dependencies. Data sent includes package names, versions, ecosystems, and file hashes. Use [`--offline` mode](https://google.github.io/osv-scanner/usage/offline-mode/) to disable network requests and scan against a local database instead. ### [deps.dev API](https://docs.deps.dev/api/)Used for supplementary package information:- **Dependency resolution**: Resolves dependency graphs for vulnerability scanning and remediation - **Container scanning**: Queries container metadata for vulnerability detection - **License scanning** (`--licenses` flag): Retrieves license information for packages - **Package deprecation**: Checks if packages are deprecatedData sent includes package names, versions, and ecosystems. No source code is transmitted.### Package RegistriesWhen using native registry for dependency resolution (instead of deps.dev), OSV-Scanner may query:| Registry | URL | Used For | | ------------- | ------------------------------ | ------------------------------------ | | Maven Central | `repo.maven.apache.org/maven2` | Maven package metadata and POM files | | npm Registry | `registry.npmjs.org` | npm package metadata | | PyPI | `pypi.org` | Python package metadata |## Contribute ### Report ProblemsIf you have what looks like a bug, please use the [GitHub issue tracking system](https://github.com/google/osv-scanner/issues). Before you file an issue, please search existing issues to see if your issue is already covered. ### Contributing code to `osv-scanner`See [CONTRIBUTING.md](CONTRIBUTING.md) for documentation on how to contribute code. ## Star History {card-default label="? 工具信息" /} ? 项目地址:[https://github.com/google/osv-scanner](https://github.com/google/osv-scanner) ⭐ Star数:10990 ? 开发语言:Go ? 项目描述:用Go编写的漏洞扫描程序,使用https://osv.dev提供的数据 {/card-default}{cloud type="default" title="网盘下载" url="https://github.com/google/osv-scanner/archive/refs/heads/main.zip"} {cloud type="default" title="网盘下载" url="https://github.com/google/osv-scanner"}总的来说,**osv-scanner**是一个功能比较实用的开源工具,适合日常工作和学习使用。如果你正在寻找一款相关工具,不妨下载试试。使用前建议仔细阅读项目文档。