Automic VaultAutomic Vault

brew

使用 Homebrew, MacPorts, Nix, pacman 安装 exploitdb

查看 exploitdb 的安装路径、可执行文件、元数据以及面向 AI 代理工作流的安全说明。

安装

其他安装命令

macOS

Homebrew已验证 · 100%
brew install exploitdb

local Homebrew formula metadata

MacPorts已验证 · 94%
sudo port install exploitdb

MacPorts ports tree · security/exploitdb/Portfile · 来源: api.github.com

Linux

Nix已验证 · 92%
nix profile install nixpkgs#exploitdb

nixpkgs package indexes · pkgs/by-name/ex/exploitdb/package.nix · 来源: api.github.com

Arch Linux pacman已验证 · 92%
sudo pacman -S exploitdb

Arch Linux sync databases · exploitdb · 来源: geo.mirror.pkgbuild.com

概览

软件包摘要

Database of public exploits and corresponding vulnerable software

命令和别名

  • searchsploit

历史

项目历史与用法

Exploit-DB is OffSec's public archive of exploit code, shellcode, papers, and proof-of-concept material for vulnerable software. It is built for penetration testers and vulnerability researchers who need searchable, actionable examples rather than advisory prose.

The Homebrew package is mostly useful because it installs the database and SearchSploit, the command-line tool for querying a local checkout. That makes Exploit-DB one of the rare security datasets that package managers ship as a practical offline research corpus.

项目历史

The archive traces back to milw0rm, a public exploit archive started by str0ke in early 2004 after another exploit source moved behind a paid model. OffSec's history page presents milw0rm as a trusted community source because submitted exploits were verified before inclusion.

In July 2009, str0ke announced that milw0rm would close, then said it would continue temporarily because of community demand. OffSec took over the database in November 2009, launched the exploit-db.com domain that month, and continued the service as Exploit-DB.

The current GitLab repository is the official source tree for Exploit-DB exploits and shellcode, with companion repositories for binary exploits and papers. Its README says the repository is updated daily with recent submissions.

采用历史

Exploit-DB became a standard reference because it preserved working exploit and proof-of-concept material in a searchable form. OffSec describes it as a non-profit public-service project and a CVE-compliant archive intended for penetration testers and vulnerability researchers.

SearchSploit turned the web archive into a local Unix workflow. The official manual documents Kali Linux packaging, Git installation, and Homebrew installation, and notes that the standard Kali GNOME build includes the exploitdb package by default.

使用方式

SearchSploit searches a local copy of Exploit-DB by one or more terms, with options for title-only searches, exact matching, CVE lookup, JSON output, Nmap XML correlation, path lookup, and mirroring selected exploits into a working directory.

The manual emphasizes offline use: a tester can take a local checkout into segregated or air-gapped networks, update it later, and optionally add binary-exploit and papers repositories for more complete local data.

为什么软件包爱好者会关心

Exploit-DB is a package-manager oddity: it is both a command-line program and a frequently updated vulnerability corpus. Installing it with Homebrew or apt gives users a filesystem tree of exploits plus a shell-oriented search interface.

For Unix users, the interesting part is not just the executable but the layout and update behavior: SearchSploit reads CSV indexes, points at exploit/shellcode/paper paths through .searchsploit_rc, and can be kept current through package updates or git.

时间线

  • 2004: str0ke starts a public exploit archive that becomes milw0rm.
  • 2009-07-08: str0ke announces the site will close.
  • 2009-11-04: OffSec is publicly reported as the group taking over the database.
  • 2009-11-16: The OffSec handover goes live.
  • 2009-11-17: exploit-db.com is set up.
  • 2010: milw0rm closes for good after no longer accepting updates.
  • 2016: SearchSploit users with older Kali packages are directed to update through the traditional package manager before using newer update behavior.

Related projects

  • SearchSploit is the bundled command-line search tool for the local Exploit-DB repository.
  • The Google Hacking Database is maintained by OffSec as an extension of Exploit-DB.
  • exploitdb-bin-sploits and exploitdb-papers are companion repositories for binary exploit files and papers.

安全态势

风险级别:red

escape, surveillance, or offensive capability signal.

风险分类器

red 风险 · 中 置信度 · escape-surveillance-offensive

原因

  • escape, surveillance, or offensive capability signal

信号

  • text:exploit

安装行为

  • formula 元数据中未记录 Homebrew post-install 钩子。
  • Homebrew bottle 元数据适用于 6 个平台目标。

建议审查

在无人值守的代理使用前,请检查该工具是否读取明文凭据、写入远程状态、发布制品或调用插件。

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
<exploitdb checkout>/.searchsploit_rc

可执行文件

已安装的可执行文件

命令类型暴露范围备注
searchsploitcli全局可执行文件

新鲜度

版本和新鲜度

这些信号区分页生成时间、软件包管理器活动和上游发布比较。只有存在证据 URL 和可比较版本时,才会提示版本落后。

页面生成时间2026-07-25
管理器版本2026-07-09
管理器更新时间2026-07-09
本地数据OK
上游not checked
检测到的最新版本未检测到

https://www.exploit-db.com/

安装元数据

软件包元数据

软件包键brew:exploitdb
版本2026-07-09
软件包管理器Homebrew
软件包管理器页面https://formulae.brew.sh/formula/exploitdb
主页https://www.exploit-db.com/
仓库https://gitlab.com/exploit-database/exploitdb
上游文档https://gitlab.com/exploit-database/exploitdb
许可证GPL-2.0-or-later
源码归档https://gitlab.com/exploit-database/exploitdb.git
最后更新2026-07-09T06:53:23Z
Pulseupdated
Bottle可用 (于 arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
Homebrew post-install未定义
服务未声明

注册表事实

源数据库详情

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Nameexploitdb
Version Scheme0
Revision0
Head VersionHEAD
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • head
  • stable

源数据库匹配

其他软件包管理器记录

匹配项来自外部软件包管理器索引,并与本地 Automic Vault 软件包链接分开显示。

Nix95%

exploitdb

nix profile install nixpkgs#exploitdb
  • normalized package name match
  • 匹配方式:Exploitdb
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/ex/exploitdb/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
pacman95%

exploitdb 20260602-1

Offensive Security’s Exploit Database Archive

https://www.exploit-db.com/

sudo pacman -S exploitdb
  • License: GPL-2.0-or-later
  • Architecture: any
  • 2 可选依赖
  • normalized package name match
  • 匹配方式:Exploitdb
Arch Linux sync databases · geo.mirror.pkgbuild.com · Arch Linux sync databases: exploitdb from https://geo.mirror.pkgbuild.com/extra/os/x86_64/extra.db.tar.gz
MacPorts95%

exploitdb

sudo port install exploitdb
  • normalized package name match
  • 匹配方式:Exploitdb
MacPorts ports tree · api.github.com · MacPorts ports tree: security/exploitdb/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1

来源线索

由仓库数据生成

此页面由 av-webscripts/generate-pkg-sqlite.py 生成的私有软件包 SQLite 工件提供。

使用的来源

  • Geiger risk classifier
  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated configuration and credential file locations
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment