Skip to content
View fengchenzxc's full-sized avatar

Block or report fengchenzxc

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
74 stars written in Java
Clear filter

A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.

Java 7,920 1,776 Updated Mar 31, 2024

OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies.

Java 6,641 1,312 Updated Jan 18, 2025

SpringBoot 相关漏洞学习资料,利用方法和技巧合集,黑盒安全评估 check list

Java 5,838 1,304 Updated Mar 10, 2021

Unofficial mirror of FernFlower Java decompiler (All pulls should be submitted upstream)

Java 3,547 663 Updated Nov 27, 2024

HaE - Highlighter and Extractor, Empower ethical hacker for efficient operations.

Java 3,306 257 Updated Jan 17, 2025

JNDI注入测试工具(A tool which generates JNDI links can start several servers to exploit JNDI Injection vulnerability,like Jackson,Fastjson,etc)

Java 2,637 725 Updated Mar 22, 2023

Java安全相关的漏洞和技术demo,原生Java、Fastjson、Jackson、Hessian2、XML反序列化漏洞利用和Spring、Dubbo、Shiro、CAS、Tomcat、RMI、Nexus等框架\中间件\功能的exploits以及Java Security Manager绕过、Dubbo-Hessian2安全加固等等实践代码。

Java 2,619 496 Updated Mar 14, 2024

一款高性能 HTTP 代理隧道工具 | A high-performance http proxy tunneling tool

Java 2,234 204 Updated Jan 10, 2025

shiro反序列化漏洞综合利用,包含(回显执行命令/注入内存马)修复原版中NoCC的问题 https://github.com/j1anFen/shiro_attack

Java 2,137 271 Updated Apr 10, 2024

MDUT - Multiple Database Utilization Tools

Java 2,046 232 Updated Sep 22, 2023

A Burp Suite extension that integrates OpenAI's GPT to perform an additional passive scan for discovering highly bespoke vulnerabilities and enables running traffic-based analysis of any type.

Java 2,026 237 Updated Jun 9, 2024

a rep for documenting my study, may be from 0 to 0.1

Java 1,963 302 Updated Jan 5, 2025

Share Things Related to Java - Java安全漫谈笔记相关内容

Java 1,801 210 Updated Aug 12, 2024

一款支持自定义的 Java 内存马生成工具|A customizable Java in-memory webshell generation tool.

Java 1,769 200 Updated Jan 12, 2025

A simple FOFA client written in JavaFX. Made by WgpSec, Maintained by f1ashine.

Java 1,627 164 Updated Jun 11, 2024

HackBar plugin for Burpsuite

Java 1,562 261 Updated Apr 15, 2021

An easy-to-learn/use static analysis framework for Java

Java 1,504 180 Updated Dec 31, 2024

OAExploit一款基于产品的一键扫描工具。

Java 1,469 196 Updated Sep 20, 2022

☕️ Java Security,安全编码和代码审计

Java 1,433 224 Updated Dec 6, 2024

WebSocket 内存马/Webshell,一种新型内存马/WebShell技术

Java 1,424 226 Updated Apr 10, 2023

HeapDump敏感信息提取工具

Java 1,381 136 Updated Dec 12, 2024

Collect JSP webshell of various implementation methods. 收集JSP Webshell的各种姿势

Java 1,367 325 Updated Jan 18, 2022

Jar Analyzer - 一个JAR包分析工具,批量分析,SCA漏洞分析,方法调用关系搜索,字符串搜索,Spring组件分析,信息泄露检查,CFG程序分析,JVM栈帧分析,进阶表达式搜索,字节码指令级的动态调试分析,反编译JAR包一键导出,一键提取序列化数据恶意代码,一键分析BCEL字节码

Java 1,305 114 Updated Jan 7, 2025

A helpful Java Deserialization exploit framework.

Java 1,195 150 Updated Jun 20, 2024

一款基于BurpSuite的被动式FastJson检测插件

Java 1,160 127 Updated Oct 1, 2022

记录一下 Java 安全学习历程,也算是半条学习路线了

Java 1,028 100 Updated Jan 8, 2025

A byte code analyzer for finding deserialization gadget chains in Java applications

Java 1,009 221 Updated Jun 15, 2021

Nacos漏洞综合利用GUI工具,集成了默认口令漏洞、SQL注入漏洞、身份认证绕过漏洞、反序列化漏洞的检测及其利用

Java 1,002 74 Updated Aug 2, 2024

分享几个直接可用的内存马,记录一下学习过程中看过的文章

Java 943 157 Updated Mar 23, 2022

🐱‍💻 ✂️ 🤬 CVE-2021-44228 - LOG4J Java exploit - WAF bypass tricks

Java 935 141 Updated Jan 15, 2022
Next