This is your work, valued
Cyber Security
ShiroExploit-Deprecated. Shiro550/Shiro721 一键化利用工具,支持多种回显方式
★ 2kJava-Rce-Echo. Java RCE 回显测试代码
★ 1kmemShell. FilterBased/ServletBased in memory shell for Tomcat and some other middlewares
★ 390JspMaster-Deprecated. 一款基于webshell命令执行功能实现的GUI webshell管理工具,支持流量加密
★ 220Attacking_Shiro_with_CVE_2020_2555. Java
★ 50jre8u20_gadget. jre8u20 gadget
★ 34PHP-Audit-Labs. 一个关于PHP的代码审计项目
★ 8ysoserial. A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.
★ 1pinyinSegmentation. 拼音分词
★ 1TerraformGoat. TerraformGoat is HXSecurity research lab's "Vulnerable by Design" multi cloud deployment tool.
★ 639chrome-extensions-samples. Chrome Extensions Samples
★ 18kjazzer. Coverage-guided, in-process fuzzing for the JVM
★ 1.2kmomo-code-sec-inspector-java. IDEA静态代码安全审计及漏洞一键修复插件
★ 1kmalicious-pdf. 💀 Generate malicious PDF test files for testing phone-home callbacks, SSRF, XSS, NTLM credential theft, and data exfiltration in PDF viewers, converters, and web applications. Can be used with Burp Collaborator or Interact.sh
★ 4.1kcodeql. CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security
★ 9.9kkubernetes-goat. Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on playground 🚀
★ 5.7kcodeql_grehack_workshop. GreHack 2021 CodeQL for Java workshop
★ 73docker-images. Official source of container configurations, images, and examples for Oracle products and projects
★ 7ktoBeBetterJavaer. 一份通俗易懂、风趣幽默的Java学习指南,内容涵盖Java基础、Java并发编程、Java虚拟机、Java企业级开发、Java面试等核心知识点。学Java,就认准二哥的Java进阶之路😄
★ 17kjavaparser. Java 1-25 Parser and Abstract Syntax Tree for Java with advanced analysis functionalities.
★ 6.1kJDKSourceCode1.8. Jdk1.8源码解析
★ 1.5kdnsFookup. DNS rebinding toolkit
★ 255JDBC-Attack. JDBC Connection URL Attack
★ 450prototype-pollution-exploits. Prototype Pollution exploits collection
★ 40client-side-prototype-pollution. Prototype Pollution and useful Script Gadgets
★ 1.6kregexploit. Find regular expressions which are vulnerable to ReDoS (Regular Expression Denial of Service)
★ 848nuclei. Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
★ 30kFastjson. Fastjson姿势技巧集合
★ 1.9kweblogic-infodetector. woodpecker框架weblogic信息探测插件
★ 186sec-dev-in-action-src. 《白帽子安全开发实战》配套代码
★ 995Sreg. Sreg可对使用者通过输入email、phone、username的返回用户注册的所有互联网护照信息。
★ 1.2kSpringBoot-Labs. 一个涵盖六个专栏:Spring Boot 2.X、Spring Cloud、Spring Cloud Alibaba、Dubbo、分布式消息队列、分布式事务的仓库。希望胖友小手一抖,右上角来个 Star,感恩 1024
★ 20kspring-boot-upload-file-lead-to-rce-tricks. spring boot Fat Jar 任意写文件漏洞到稳定 RCE 利用技巧
★ 760SerialKiller. Look-Ahead Java Deserialization Library
★ 422AgentMemShellScanner. 清除基于java agent木马
★ 79BehinderClientSource. ❄️冰蝎客户端源码-V4.0.6🔞
★ 944log-agent. 利用agent hock指定的class,在jar运行周期内,用于跟踪被执行的方法,辅助做一些事情,比如挖洞啊
★ 123cas-sample-java-webapp. Sample Java web app protected by Java CAS client
★ 1learnjavabug. Java安全相关的漏洞和技术demo,原生Java、Fastjson、Jackson、Hessian2、XML反序列化漏洞利用和Spring、Dubbo、Shiro、CAS、Tomcat、RMI、Nexus等框架\中间件\功能的exploits以及Java Security Manager绕过、Dubbo-Hessian2安全加固等等实践代码。
★ 2.7kbylibrary. 白阁文库是白泽Sec安全团队维护的一个漏洞POC和EXP公开项目
★ 1.5kCobaltStrike4.0_related. 破解的cs4.0、cs4.0官方手册翻译和一些笔记
★ 405DongTai-agent-java. Java Agent is a Java application probe of DongTai IAST, which collects method invocation data during runtime of Java application by dynamic hooks.
★ 696ZhouYu. (周瑜)Java - SpringBoot 持久化 WebShell(不仅仅是SpringBoot,适合任何符合JavaEE规范的服务)
★ 616freddy. Automatically identify deserialisation issues in Java and .NET applications by using active and passive scans
★ 582Goby. Attack surface mapping
★ 1.5kvulmap. Vulmap 是一款 web 漏洞扫描和验证工具, 可对 webapps 进行漏洞扫描, 并且具备漏洞验证功能
★ 3.5kbestJavaer. 现在这个 repo 它已转型为 cxuan-ai-labs:一个普通开发者在 AI 时代的个人实验室,用来记录 AI 文章、工具资源、Agent 实验、模型观察、踩坑复盘,以及一些未必成熟但真实有趣的 AI 作品。旧 Java 内容已归档保留,新主线转向 AI。
★ 6.6kMy-Presentation-Slides. Collections of Orange Tsai's public presentation slides.
★ 760javaSerializationTools. Python
★ 145vue-admin-template. a vue2.0 minimal admin template
★ 20kCVE-2021-3156. C
★ 1kvueDemo. Vue
★ 19awesome-vue. 🎉 A curated list of awesome things related to Vue.js
★ 74kActive-Directory-Exploitation-Cheat-Sheet. A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.
★ 6.7kHaE. HaE - Highlighter and Extractor, Empower ethical hacker for efficient operations. 赋能白帽,高效作战!
★ 4.4kJavaSecurity. Java web and command line applications demonstrating various security topics
★ 238redteam_vul. 红队作战中比较常遇到的一些重点系统漏洞整理。
★ 2.5kBurpSuiteHTTPSmuggler. A Burp Suite extension to help pentesters to bypass WAFs or test their effectiveness using a number of techniques
★ 745abuse-ssl-bypass-waf. Bypassing WAF by abusing SSL/TLS Ciphers
★ 321bayonet. bayonet是一款src资产管理系统,从子域名、端口服务、漏洞、爬虫等一体化的资产管理系统
★ 1.5kwafw00f. WAFW00F allows one to identify and fingerprint Web Application Firewall (WAF) products protecting a website.
★ 6.5kAs-Exploits. 中国蚁剑后渗透框架
★ 942GetIPinfo. 用于寻找多网卡主机方便内网跨网段渗透避免瞎打找不到核心网
★ 237Sublist3r. Fast subdomains enumeration tool for penetration testers
★ 11kBypassAntiVirus. 远控免杀系列文章及配套工具,汇总测试了互联网上的几十种免杀工具、113种白名单免杀方式、8种代码编译免杀、若干免杀实战技术,并对免杀效果进行了一一测试,为远控的免杀和杀软对抗免杀提供参考。
★ 5.1kJavaThings. Share Things Related to Java - Java安全漫谈笔记相关内容
★ 2kSerializationDumper. A tool to dump Java serialization streams in a more human readable form.
★ 1.1kMySQL_Fake_Server. MySQL Fake Server use to help MySQL Client File Reading and JDBC Client Java Deserialize
★ 1.4krhizobia_J. JAVA安全SDK及编码规范
★ 1.1kBurpShiroPassiveScan. 一款基于BurpSuite的被动式shiro检测插件
★ 1.8kApache-Solr-RCE. Apache Solr Exploits 🌟
★ 346java-memshell-scanner. 通过jsp脚本扫描java web Filter/Servlet型内存马
★ 1kKernelhub. :palm_tree:Linux、macOS、Windows Kernel privilege escalation vulnerability collection, with compilation environment, demo GIF map, vulnerability details, executable file (提权漏洞合集)
★ 3.2kSharpChromium. .NET 4.0 CLR Project to retrieve Chromium data, such as cookies, history and saved logins.
★ 761xray-crack. xray社区高级版证书生成,仅供学习研究,正常使用请支持正版。removed due to Chaitin requirements & support to version 1.4.4 & learning purpose
★ 442JavaTools. 一些Java编写的小工具。
★ 320javaagent-tomcat-memshell. 使用java agent反序列化注入内存shell
★ 69Rogue-MySql-Server. Rogue MySql Server
★ 472ysoserial.net. Deserialization payload generator for a variety of .NET formatters
★ 3.8kyaml-payload. Spring Cloud SnakeYAML 反序列化一键注入cmdshell和reGeorg
★ 136memShell. a webshell resides in the memory of java web server
★ 704icmpsh. Simple reverse ICMP shell
★ 1.6kBurpSuite-collections. 有关burpsuite的插件(非商店),文章以及使用技巧的收集(此项目不再提供burpsuite破解文件,如需要请在博客mrxn.net下载)---Collection of burpsuite plugins (non-stores), articles and tips for using Burpsuite, no crack version file
★ 3.9kJ2EEScan. J2EEScan is a plugin for Burp Suite Proxy. The goal of this plugin is to improve the test coverage during web application penetration tests on J2EE applications.
★ 679Penetration_Testing_POC. 渗透测试有关的POC、EXP、脚本、提权、小工具等---About penetration-testing python-script poc getshell csrf xss cms php-getshell domainmod-xss csrf-webshell cobub-razor cve rce sql sql-poc poc-exp bypass oa-getshell cve-cms
★ 7.4kCVE-2020-1472. PoC for Zerologon - all research credits go to Tom Tervoort of Secura
★ 1.3kattackRmi. attackRmi
★ 259FastjsonScan. 一个简单的Fastjson反序列化检测burp插件
★ 980WeblogicEnvironment. Weblogic环境搭建工具
★ 800Demo-Exploit-Jackson-RCE. Exploiting CVE-2017-7525 demo project with Angular7 frontend and Spring.
★ 18shiroPoc. Java
★ 318FastjsonPocs. 一些结合第三方组件的Fastjson POC,在1.2.48以后版本中陆续被添加至黑名单。
★ 56Empire. Empire is a PowerShell and Python post-exploitation agent.
★ 7.9kspringboot-analysis. 🍃 something about springboot
★ 348Java-Deserialization-Cheat-Sheet. The cheat sheet about Java Deserialization vulnerabilities
★ 3.2kCodeGuide. :books: 本代码库是作者小傅哥多年从事一线互联网 Java 开发的学习历程技术汇总,旨在为大家提供一个清晰详细的学习教程,侧重点更倾向编写Java核心内容。如果本仓库能为您提供帮助,请给予支持(关注、点赞、分享)!
★ 12kxxe-lab. 一个包含php,java,python,C#等各种语言版本的XXE漏洞Demo
★ 818JNDI-Exploit-Bypass-Demo. Demo code for post <Restrictions of JNDI Manipulation RCE & Bypass>
★ 266SRC-experience. 工欲善其事,必先利其器
★ 1.6kRMIDeserialize. RMI 反序列化环境 一步步
★ 214JNDI-Injection-Exploit. JNDI注入测试工具(A tool which generates JNDI links can start several servers to exploit JNDI Injection vulnerability,like Jackson,Fastjson,etc)
★ 2.8kpwn_jenkins. Notes about attacking Jenkins servers
★ 2.1kJavaLearnVulnerability. Java漏洞学习笔记 Deserialization Vulnerability
★ 943JavaFamily. 【Java面试+Java学习指南】 一份涵盖大部分Java程序员所需要掌握的核心知识。
★ 37kBypassAV. Cobalt Strike插件,用于快速生成免杀的可执行文件
★ 906ActuatorExploitTools. 一款用于攻击spring boot actuator的集成环境,目前集成三种攻击方式,支持1.x、2.x
★ 85SerialKillerBypassGadgetCollection. Collection of bypass gadgets to extend and wrap ysoserial payloads
★ 389exphub. Exphub[漏洞利用脚本库] 包括Webloigc、Struts2、Tomcat、Nexus、Solr、Jboss、Drupal的漏洞利用脚本,最新添加CVE-2020-14882、CVE-2020-11444、CVE-2020-10204、CVE-2020-10199、CVE-2020-1938、CVE-2020-2551、CVE-2020-2555、CVE-2020-2883、CVE-2019-17558、CVE-2019-6340
★ 4.3kjdk8u_jdk. Java
★ 218BurpCrypto. BurpCrypto is a collection of burpsuite encryption plug-ins, support AES/RSA/DES/ExecJs(execute JS encryption code in burpsuite). 支持多种加密算法或直接执行JS代码的用于爆破前端加密的BurpSuite插件
★ 1.6kysoserial. forked from frohoff/ysoserial and added my own payloads.
★ 156java-object-searcher. java内存对象搜索辅助工具
★ 821behinder_source. Behinder3.0 Beta4 源码(Decompile and Fixed)
★ 207my-presentation-slide.
★ 97JSP-WebShells. Collect JSP webshell of various implementation methods. 梳理和发现的JSP Webshell各种姿势
★ 1.4kSecurity-List. If you have any good suggestions or comments during the search process, please feedback some index experience in issues. Thank you for your participation.查阅过程中,如果有什么好的意见或建议,请在Issues反馈,感谢您的参与。
★ 1.5kweblogicScanner. weblogic 漏洞扫描工具。目前包含对以下漏洞的检测能力:CVE-2014-4210、CVE-2016-0638、CVE-2016-3510、CVE-2017-3248、CVE-2017-3506、CVE-2017-10271、CVE-2018-2628、CVE-2018-2893、CVE-2018-2894、CVE-2018-3191、CVE-2018-3245、CVE-2018-3252、CVE-2019-2618、CVE-2019-2725、CVE-2019-2729、CVE-2019-2890、CVE-2020-2551、CVE-2020-14750、CVE-2020-14882、CVE-2020-14883
★ 2.1kSuperWordlist. 基于实战沉淀下的各种弱口令字典
★ 15CVE-2020-0796-RCE-POC. CVE-2020-0796 Remote Code Execution POC
★ 573SpringBootVulExploit. SpringBoot 相关漏洞学习资料,利用方法和技巧合集,黑盒安全评估 check list
★ 6.1kSB-Actuator. Spring Boot Actuator未授权访问【XXE、RCE】单/多目标检测
★ 524shelling. SHELLING - a comprehensive OS command injection payload generator
★ 442rogue-jndi. A malicious LDAP server for JNDI injection attacks
★ 1.1kfastjson-blacklist. Java
★ 844FastjsonExploit. Fastjson vulnerability quickly exploits the framework(fastjson漏洞快速利用框架)
★ 1.4kjndi_tool. JNDI服务利用工具 RMI/LDAP,支持部分场景回显、内存shell,高版本JDK场景下利用等,fastjson rce命令执行,log4j rce命令执行 漏洞检测辅助工具
★ 2kmarshalsec. Java
★ 3.7kysoserial. A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.
★ 9k