Web Security @Nu1LCTF
JNDIMap. A powerful JNDI injection exploitation framework that supports RMI, LDAP and LDAPS protocols, including various bypass methods for high-version JDK restrictions
595Godzilla-Suo5MemShell. 使用 Godzilla 一键注入 Suo5 内存马
440ActiveMQ-RCE. ActiveMQ RCE (CVE-2023-46604) 漏洞利用工具
254frp. 基于原版 frp 二开, 添加了一些小功能
107EBurstGo. 利用 Exchange 服务器 Web 接口爆破邮箱账户 | Brute force email accounts using Exchange server web endpoints
94pivot-rs. A lightweight port-forwarding and socks proxy tool written in Rust 🦀
56cpploader. c++ shellcode loader
40hacking-espresso. Hacking GraalVM Espresso - Abusing Continuation API to Make ROP-like Attack
36dubbo-rce. PoC of Apache Dubbo CVE-2023-23638
34jetty-fuzz. Java
32hessian-overlong-encoding. Hessian UTF-8 Overlong Encoding
21ClassNameObfuscator. 基于多种策略, 对已有 JAR 包中的全限定类名进行变换, 无限生成高度相似的虚假类名
20presentations. My presentation slides
18go-ntlmssp. NTLM/Negotiate authentication over HTTP that supports Pass The Hash Mode (PtH)
17spring-amqp-deserialization. PoC of Spring AMQP Deserialization Vulnerability (CVE-2023-34050)
13memshell-killer. A command-line tool for Java Web memory shell incident response
9dork. dork everything
5nacos-hessian-rce. PoC of Nacos JRaft Hessian RCE
4oss-security-bot. oss-security mailing list Webhook Bot, using LLM for summarization, written in Rust 🦀
3X1r0z. Profile
2memshell-killer-web. TypeScript
2webscan. Find the same IP site
1dotfiles. Vim Script
1MirrorScan. bugscan scanner
1