Automic VaultAutomic Vault

brew

exploitdb mit Homebrew, MacPorts, Nix, pacman installieren

Prüfe Installationswege, Executables, Metadaten und Sicherheitshinweise für exploitdb in AI-Agent-Workflows.

Installation

Weitere Installationsbefehle

macOS

Homebrewverifiziert · 100%
brew install exploitdb

local Homebrew formula metadata

MacPortsverifiziert · 94%
sudo port install exploitdb

MacPorts ports tree · security/exploitdb/Portfile · Quelle: api.github.com

Linux

Nixverifiziert · 92%
nix profile install nixpkgs#exploitdb

nixpkgs package indexes · pkgs/by-name/ex/exploitdb/package.nix · Quelle: api.github.com

Arch Linux pacmanverifiziert · 92%
sudo pacman -S exploitdb

Arch Linux sync databases · exploitdb · Quelle: geo.mirror.pkgbuild.com

Überblick

Paketzusammenfassung

Database of public exploits and corresponding vulnerable software

Befehle und Aliase

  • searchsploit

Verlauf

Projektgeschichte und Nutzung

Exploit-DB is OffSec's public archive of exploit code, shellcode, papers, and proof-of-concept material for vulnerable software. It is built for penetration testers and vulnerability researchers who need searchable, actionable examples rather than advisory prose.

The Homebrew package is mostly useful because it installs the database and SearchSploit, the command-line tool for querying a local checkout. That makes Exploit-DB one of the rare security datasets that package managers ship as a practical offline research corpus.

Projektgeschichte

The archive traces back to milw0rm, a public exploit archive started by str0ke in early 2004 after another exploit source moved behind a paid model. OffSec's history page presents milw0rm as a trusted community source because submitted exploits were verified before inclusion.

In July 2009, str0ke announced that milw0rm would close, then said it would continue temporarily because of community demand. OffSec took over the database in November 2009, launched the exploit-db.com domain that month, and continued the service as Exploit-DB.

The current GitLab repository is the official source tree for Exploit-DB exploits and shellcode, with companion repositories for binary exploits and papers. Its README says the repository is updated daily with recent submissions.

Adoptionsgeschichte

Exploit-DB became a standard reference because it preserved working exploit and proof-of-concept material in a searchable form. OffSec describes it as a non-profit public-service project and a CVE-compliant archive intended for penetration testers and vulnerability researchers.

SearchSploit turned the web archive into a local Unix workflow. The official manual documents Kali Linux packaging, Git installation, and Homebrew installation, and notes that the standard Kali GNOME build includes the exploitdb package by default.

Wie es verwendet wird

SearchSploit searches a local copy of Exploit-DB by one or more terms, with options for title-only searches, exact matching, CVE lookup, JSON output, Nmap XML correlation, path lookup, and mirroring selected exploits into a working directory.

The manual emphasizes offline use: a tester can take a local checkout into segregated or air-gapped networks, update it later, and optionally add binary-exploit and papers repositories for more complete local data.

Warum Paket-Nerds sich dafür interessieren

Exploit-DB is a package-manager oddity: it is both a command-line program and a frequently updated vulnerability corpus. Installing it with Homebrew or apt gives users a filesystem tree of exploits plus a shell-oriented search interface.

For Unix users, the interesting part is not just the executable but the layout and update behavior: SearchSploit reads CSV indexes, points at exploit/shellcode/paper paths through .searchsploit_rc, and can be kept current through package updates or git.

Zeitleiste

  • 2004: str0ke starts a public exploit archive that becomes milw0rm.
  • 2009-07-08: str0ke announces the site will close.
  • 2009-11-04: OffSec is publicly reported as the group taking over the database.
  • 2009-11-16: The OffSec handover goes live.
  • 2009-11-17: exploit-db.com is set up.
  • 2010: milw0rm closes for good after no longer accepting updates.
  • 2016: SearchSploit users with older Kali packages are directed to update through the traditional package manager before using newer update behavior.

Related projects

  • SearchSploit is the bundled command-line search tool for the local Exploit-DB repository.
  • The Google Hacking Database is maintained by OffSec as an extension of Exploit-DB.
  • exploitdb-bin-sploits and exploitdb-papers are companion repositories for binary exploit files and papers.

Sicherheitslage

Risikostufe: red

escape, surveillance, or offensive capability signal.

Risikoklassifikator

red Risiko · mittel Konfidenz · escape-surveillance-offensive

Warum

  • escape, surveillance, or offensive capability signal

Signale

  • text:exploit

Installationsverhalten

  • In den Formelmetadaten ist kein Homebrew-Post-install-Hook erfasst.
  • Homebrew-Bottle-Metadaten sind für 6 Plattformziele verfügbar.

Empfohlene Prüfung

Prüfe vor unbeaufsichtigter Agent-Nutzung, ob das Tool Klartext-Credentials liest, Remote-Zustand schreibt, Artefakte veröffentlicht oder Plugins ausführt.

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
<exploitdb checkout>/.searchsploit_rc

Executables

Installierte Executables

BefehlArtSichtbarkeitHinweis
searchsploitcliglobales Executable

Aktualität

Version und Aktualität

Diese Signale trennen das Alter der Seitengenerierung, Aktivität des Paketmanagers und Upstream-Release-Vergleich. Versionsrückstand wird nur gemeldet, wenn eine Evidenz-URL und vergleichbare Versionen vorhanden sind.

Seite generiert2026-07-25
Manager-Version2026-07-09
Manager aktualisiert2026-07-09
lokale DatenOK
Upstreamnot checked
neueste erkannte Versionnicht erkannt

https://www.exploit-db.com/

Installationsmetadaten

Paketmetadaten

Paketschlüsselbrew:exploitdb
Version2026-07-09
PaketmanagerHomebrew
Paketmanager-Seitehttps://formulae.brew.sh/formula/exploitdb
Homepagehttps://www.exploit-db.com/
Repositoryhttps://gitlab.com/exploit-database/exploitdb
Upstream-Dokumentationhttps://gitlab.com/exploit-database/exploitdb
LizenzGPL-2.0-or-later
Quellarchivhttps://gitlab.com/exploit-database/exploitdb.git
Zuletzt aktualisiert2026-07-09T06:53:23Z
Pulseupdated
Bottleverfügbar (auf arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
Homebrew post-installnicht definiert
Dienstkeiner deklariert

Registry-Fakten

Details aus der Quelldatenbank

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Nameexploitdb
Version Scheme0
Revision0
Head VersionHEAD
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • head
  • stable

Source-Datenbank-Treffer

Andere Paketmanager-Einträge

Treffer stammen aus externen Paketmanager-Indizes und bleiben von lokalen Automic-Vault-Paketlinks getrennt.

Nix95%

exploitdb

nix profile install nixpkgs#exploitdb
  • normalized package name match
  • Abgeglichen nach: Exploitdb
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/ex/exploitdb/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
pacman95%

exploitdb 20260602-1

Offensive Security’s Exploit Database Archive

https://www.exploit-db.com/

sudo pacman -S exploitdb
  • License: GPL-2.0-or-later
  • Architecture: any
  • 2 optionale Abhängigkeiten
  • normalized package name match
  • Abgeglichen nach: Exploitdb
Arch Linux sync databases · geo.mirror.pkgbuild.com · Arch Linux sync databases: exploitdb from https://geo.mirror.pkgbuild.com/extra/os/x86_64/extra.db.tar.gz
MacPorts95%

exploitdb

sudo port install exploitdb
  • normalized package name match
  • Abgeglichen nach: Exploitdb
MacPorts ports tree · api.github.com · MacPorts ports tree: security/exploitdb/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1

Quellspur

Aus Repository-Daten generiert

Diese Seite wird von av-web aus dem privaten Paket-SQLite-Artefakt bereitgestellt, das scripts/generate-pkg-sqlite.py erstellt.

Verwendete Quellen

  • Geiger risk classifier
  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated configuration and credential file locations
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment