Skip to content
View changxia3's full-sized avatar

Block or report changxia3

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
42 results for source starred repositories written in Java
Clear filter

SpringBoot 相关漏洞学习资料,利用方法和技巧合集,黑盒安全评估 check list

Java 5,838 1,303 Updated Mar 10, 2021

Java安全相关的漏洞和技术demo,原生Java、Fastjson、Jackson、Hessian2、XML反序列化漏洞利用和Spring、Dubbo、Shiro、CAS、Tomcat、RMI、Nexus等框架\中间件\功能的exploits以及Java Security Manager绕过、Dubbo-Hessian2安全加固等等实践代码。

Java 2,619 496 Updated Mar 14, 2024

a rep for documenting my study, may be from 0 to 0.1

Java 1,963 302 Updated Jan 5, 2025

SEKIRO is a multi-language, distributed, network topology-independent service publishing platform. By writing handlers in their respective languages, functionalities can be published to the central…

Java 1,773 525 Updated Jan 3, 2025

一款支持自定义的 Java 内存马生成工具|A customizable Java in-memory webshell generation tool.

Java 1,769 200 Updated Jan 12, 2025

一款基于BurpSuite的被动式shiro检测插件

Java 1,699 155 Updated Dec 14, 2022

Burp Bounty (Scan Check Builder in BApp Store) is a extension of Burp Suite that allows you, in a quick and simple way, to improve the active and passive scanner by means of personalized rules thro…

Java 1,695 341 Updated Apr 26, 2024

The new bridge between Burp Suite and Frida!

Java 1,672 208 Updated Mar 28, 2024

A CAT called tabby ( Code Analysis Tool )

Java 1,324 152 Updated Jan 13, 2025

Vulnerable Android application for developers and security enthusiasts to learn about Android insecurities

Java 1,272 461 Updated Apr 17, 2024

A malicious LDAP server for JNDI injection attacks

Java 1,021 221 Updated Sep 28, 2023

Burp插件,根据自定义来达到对数据包的处理(适用于加解密、爆破等),类似mitmproxy,不同点在于经过了burp中转,在自动加解密的基础上,不影响APP、网站加解密正常逻辑等。

Java 1,009 83 Updated Jan 14, 2025

A byte code analyzer for finding deserialization gadget chains in Java applications

Java 1,009 221 Updated Jun 15, 2021

A tool to dump Java serialization streams in a more human readable form.

Java 1,005 125 Updated Jun 21, 2024

Java RCE 回显测试代码

Java 1,000 176 Updated Oct 15, 2020

分享几个直接可用的内存马,记录一下学习过程中看过的文章

Java 944 157 Updated Mar 23, 2022

Java RMI Vulnerability Scanner

Java 847 109 Updated Jul 3, 2024

一个想让你测试加密流量像测试明文一样简单高效的 Burp 插件。 A Burp plugin that makes testing encrypted traffic as simple and efficient as testing plaintext.

Java 815 59 Updated Jan 14, 2025

java内存对象搜索辅助工具

Java 794 86 Updated Sep 23, 2022

Log4j2 RCE Passive Scanner plugin for BurpSuite

Java 781 95 Updated Aug 4, 2023

Nacos JRaft Hessian 反序列化 RCE 加载字节码 注入内存马 不出网利用

Java 760 85 Updated Jul 7, 2023

spring boot Fat Jar 任意写文件漏洞到稳定 RCE 利用技巧

Java 693 70 Updated Apr 14, 2021

burp插件开发指南

Java 609 98 Updated Aug 8, 2021

JavaWeb MemoryShell Inject/Scan/Killer/Protect Research & Exploring

Java 600 94 Updated Jun 25, 2021

Probe endpoints consuming Java serialized objects to identify classes, libraries, and library versions on remote Java classpaths.

Java 592 96 Updated Mar 4, 2021

(周瑜)Java - SpringBoot 持久化 WebShell 学习demo(不仅仅是SpringBoot,适合任何符合JavaEE规范的服务)

Java 590 64 Updated Dec 29, 2021

给woodpecker框架量身定制的ysoserial

Java 545 73 Updated Oct 26, 2022

Collection of bypass gadgets to extend and wrap ysoserial payloads

Java 351 76 Updated Apr 16, 2022

基于亚马逊S3\阿里云OSS\腾讯COS通信隧道的远程管理工具

Java 320 52 Updated Oct 10, 2020
Java 304 41 Updated Aug 7, 2024
Next