Skip to content
View charonlight's full-sized avatar

Block or report charonlight

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
44 stars written in Java
Clear filter

A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.

Java 8,001 1,781 Updated Mar 31, 2024

Java web common vulnerabilities and security code which is base on springboot and spring security

Java 2,467 672 Updated Dec 2, 2024

一款高性能 HTTP 代理隧道工具 | A high-performance http proxy tunneling tool

Java 2,270 209 Updated Feb 20, 2025

a rep for documenting my study, may be from 0 to 0.1

Java 1,993 306 Updated Jan 5, 2025

一款支持自定义的 Java 内存马生成工具|A customizable Java in-memory webshell generation tool.

Java 1,806 207 Updated Jan 12, 2025

A burp extension that add some useful function to Context Menu 添加一些右键菜单让burp用起来更顺畅

Java 1,685 201 Updated Feb 24, 2025

A simple FOFA client written in JavaFX. Made by WgpSec, Maintained by f1ashine.

Java 1,651 164 Updated Jun 11, 2024

Fastjson vulnerability quickly exploits the framework(fastjson漏洞快速利用框架)

Java 1,302 175 Updated Dec 16, 2022

记录一下 Java 安全学习历程,也算是半条学习路线了

Java 1,060 101 Updated Mar 3, 2025

Nacos漏洞综合利用GUI工具,集成了默认口令漏洞、SQL注入漏洞、身份认证绕过漏洞、反序列化漏洞的检测及其利用

Java 1,033 74 Updated Aug 2, 2024

分享几个直接可用的内存马,记录一下学习过程中看过的文章

Java 947 154 Updated Mar 23, 2022

一个简单的Fastjson反序列化检测burp插件

Java 890 73 Updated Jun 18, 2021

对权限绕过自动化bypass的burpsuite插件

Java 872 48 Updated Jun 21, 2024

通过jsp脚本扫描java web Filter/Servlet型内存马

Java 864 126 Updated Mar 9, 2023

Nacos JRaft Hessian 反序列化 RCE 加载字节码 注入内存马 不出网利用

Java 765 85 Updated Jul 7, 2023

80+ Gadgets(30 More than ysoserial). JNDI-Injection-Exploit-Plus is a tool for generating workable JNDI links and provide background services by starting RMI server,LDAP server and HTTP server.

Java 765 100 Updated Jun 24, 2024

图形化漏洞利用Demo-JavaFX版

Java 701 142 Updated Aug 31, 2021

Spring漏洞综合利用工具

Java 645 60 Updated Jul 5, 2023

一款强大的 burp 安全测试插件,集成多种安全测试功能,支持自动化扫描和手动测试。

Java 547 36 Updated Dec 18, 2024

通过 JAVA AGENT 查杀内存马,提供简易方便的 GUI 界面,一键反编译目标环境内存马进行分析,支持远程查杀和本地查杀(注意:仅供本地复现分析学习,请勿用于正式和生产环境)

Java 476 87 Updated Dec 4, 2024

Jar Obfuscator - 一个 JAR/CLASS 字节码混淆工具,支持包名/类名/方法名/字段名/参数名引用分析和重命名混淆方式,支持字符串加密/整型异或混淆/垃圾代码花指令混淆/等方式,支持方法和字段的隐藏,支持 NATIVE 层的 JVMTI 代码加密,配置简单,文档教程齐全,容易上手

Java 353 35 Updated Aug 7, 2024

Functional enhancement based on nuclei

Java 320 30 Updated Nov 30, 2024

用java实现构造openwire协议,利用activeMQ < 5.18.3 RCE 回显利用 内存马注入

Java 263 17 Updated Nov 20, 2023

不那么一样的 Java Agent 内存马

Java 262 36 Updated Nov 27, 2023

一款用于辅助渗透测试工程师日常渗透测试的Burp被动漏扫插件

Java 239 19 Updated Nov 25, 2022

javafx练习,JS接口提取,漏洞检测

Java 223 14 Updated Jan 24, 2024

Java Source Code Obfuscator(java源代码混淆器)

Java 216 39 Updated Apr 23, 2024

一个 CLASS 文件混淆工具,支持方法名/字段名/参数名引用分析和重命名混淆方式,支持字符串提取/AES加密运行时解密/整型异或混淆/垃圾代码花指令混淆/等方式,支持方法和字段的隐藏,支持INVOKE指令改反射调用,配置简单,容易上手

Java 204 18 Updated Feb 28, 2025
Next