Skip to content
View gattacker's full-sized avatar
:shipit:
hac
:shipit:
hac

Block or report gattacker

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
18 stars written in Java
Clear filter

Java安全相关的漏洞和技术demo,原生Java、Fastjson、Jackson、Hessian2、XML反序列化漏洞利用和Spring、Dubbo、Shiro、CAS、Tomcat、RMI、Nexus等框架\中间件\功能的exploits以及Java Security Manager绕过、Dubbo-Hessian2安全加固等等实践代码。

Java 2,632 496 Updated Mar 14, 2024

Java web common vulnerabilities and security code which is base on springboot and spring security

Java 2,467 673 Updated Dec 2, 2024

Cknife

Java 2,430 879 Updated Nov 29, 2023

The SpotBugs plugin for security audits of Java web applications and Android applications. (Also work with Kotlin, Groovy and Scala projects)

Java 2,315 475 Updated Dec 16, 2024

A tool to dump Java serialization streams in a more human readable form.

Java 1,013 125 Updated Jun 21, 2024

JNDI-Exploitation-Kit(A modified version of the great JNDI-Injection-Exploit created by @welk1n. This tool can be used to start an HTTP Server, RMI Server and LDAP Server to exploit java web apps v…

Java 915 167 Updated Jan 11, 2022

This repository will serve as the "master" repo containing all trainings and tutorials done in preperation for OSWE in conjunction with the AWAE course. This repo will likely contain custom code by…

Java 876 285 Updated Jan 6, 2025

搜集了市面上绝大部分weblogic解密方式,整理了7种解密weblogic的方法及响应工具。

Java 806 177 Updated Nov 7, 2023

Java 内存马开聚会 🎉

Java 638 62 Updated Mar 9, 2025

Probe endpoints consuming Java serialized objects to identify classes, libraries, and library versions on remote Java classpaths.

Java 594 97 Updated Mar 4, 2021

Some payloads of JNDI Injection in JDK 1.8.0_191+

Java 475 82 Updated Dec 9, 2020

RMIScout uses wordlist and bruteforce strategies to enumerate Java RMI functions and exploit RMI parameter unmarshalling vulnerabilities

Java 427 60 Updated Sep 7, 2022

Material for the training "Developing Burp Suite Extensions – From Manual Testing to Security Automation"

Java 349 69 Updated Oct 14, 2020

rmi、jndi、ldap、jrmp、jmx、jms一些demo测试

Java 306 48 Updated Jun 17, 2022

Vulnerable Java based Web Application

Java 263 478 Updated Jun 20, 2024

Java web and command line applications demonstrating various security topics

Java 237 71 Updated Mar 4, 2025

Purposely vulnerable Java application to help lead secure coding workshops

Java 178 723 Updated Jun 24, 2024

Burp scanner plugin based on Vulners.com vulnerability database

Java 26 8 Updated Jul 10, 2017