Critical Severity
Published: Jun 24, 2025

[GitHub] maxx

Rce
Type
N/A
CVSS Score
4
Views
Anonymous
Author

Description

Maxx is an all-in-one network scanning tool that combines port scanning, protocol and fingerprint recognition, brute-force cracking, as well as vulnerability detection and exploitation functionalities.

<p align="center"> <img src="static/images/maxx_logo.svg" width="100px" alt="maxx"> </p>

[![Latest release](https://img.shields.io/github/v/release/dusbot/maxx)](https://github.com/dusbot/maxx/releases/latest)![GitHub Release Date](https://img.shields.io/github/release-date/dusbot/maxx)![GitHub All Releases](https://img.shields.io/github/downloads/dusbot/maxx/total)[![GitHub issues](https://img.shields.io/github/issues/dusbot/maxx)](https://github.com/dusbot/maxx/issues)

> This tool is intended for use by authorized security testers only. Unauthorized testing is prohibited and will be at your own risk.

[δΈ­ζ–‡](README_CN.md)

## MaXx

MaXx is a modular network security scanner combining:

- Port scanning with service fingerprinting (Coming soon)
- Vulnerability assessment (CVE detection) (Coming soon)
- Credential auditing (Brute-force & dictionary attacks) (Implemented in the initial release)
- Automated exploit chaining (Beta:Coming soon)

> If you like this tool, please star it~

### About Service Cracking

![](static/images/crack_services.png)

For webshell brute-force details, refer to [docs/webshell](docs/webshell.md)

### About Vulnerability Scanning

**Comming soon**

### Snapshot

![](static/images/help.png)

![](static/images/run.png)

### πŸš€ Project Roadmap

#### πŸ“… June: WebShell Detection & Brute-Force Module

- **Compact Webshell Detection**: Supports fingerprinting and brute-force attacks for common PHP/ASP/JSP one-liner webshells
- **Advanced Webshell Analysis**: Capable of identifying and testing popular frameworks (Godzilla/Ice Scorpion, Behinder/Chopper)
- **Intelligent Form Cracking**: Automated login brute-forcing with integrated CAPTCHA bypass (OCR/TensorFlow)

#### 🌞 July-August: OWASP Top 10 Scanner

- **Comprehensive Vulnerability Assessment**: Full coverage of OWASP Top 10 threats (SQLi, XSS, CSRF, etc.) with CTF/red team optimizations
- **Adaptive Payload Engine**: Context-aware attack vector generation with false-positive r

Community Rating
0

Login to rate this exploit

Quick Actions