Skip to content
View cwkiller's full-sized avatar
🍉
🍉
  • 漫漫安全路
  • China

Block or report cwkiller

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Stars

Java

59 repositories

《Java安全-只有Java安全才能拯救宇宙》Only Java Security Can Save The Universe.

2,871 516 Updated Aug 4, 2023

一个LDAP请求监听器,摆脱dnslog平台

Java 294 59 Updated Apr 7, 2023

自己学习java安全的一些总结,主要是安全审计相关

1,694 214 Updated Jan 5, 2022

🤗 JVM 底层原理最全知识总结

JavaScript 11,071 2,313 Updated Jan 21, 2026

payloads

Java 15 Updated Mar 17, 2021

关于学习java安全的一些知识,正在学习中ing,欢迎fork and star

Java 791 147 Updated Jul 11, 2023

拿来即用的Tomcat7/8/9/10版本Listener/Filter/Servlet内存马,支持注入CMD内存马和冰蝎内存马

Java 511 75 Updated Aug 31, 2022

解决FastJson、Jackson、Log4j2、原生JNDI注入漏洞的高版本JDKBypass利用,探测本地可用反序列化gadget达到命令执行、回显命令执行、内存马注入

Java 770 112 Updated Jan 26, 2022

ZKar is a Java serialization protocol analysis tool implement in Go.

Go 644 53 Updated Feb 15, 2025
Java 341 41 Updated Oct 11, 2025

a rep for documenting my study, may be from 0 to 0.1

Java 2,248 338 Updated Nov 10, 2025

When MVC magic turns black

Java 296 26 Updated Sep 4, 2020

构造字节在ASCII范围内的jar

Python 139 8 Updated Feb 14, 2022

JRE8u20_RCE_Gadget

Java 255 42 Updated Jul 1, 2016

Parse HPROF files from the Spring Boot Heapdump Actuator

Python 29 5 Updated Jun 11, 2024

HeapDump敏感信息提取工具

Java 1,629 149 Updated Dec 15, 2025

对原版https://github.com/feihong-cs/JNDIExploit 进行了实用化修改

Java 1,362 286 Updated Oct 16, 2022

ysoserial修改版,着重修改ysoserial.payloads.util.Gadgets.createTemplatesImpl使其可以通过引入自定义class的形式来执行命令、内存马、反序列化回显。

Java 752 121 Updated Jan 11, 2024

通过JavaAgent与Javassist技术对JVM加载的类对象进行动态插桩,可以做一些破解、加密验证的绕过等操作

Java 116 6 Updated Jun 18, 2024

shiro反序列化漏洞综合利用,包含(回显执行命令/注入内存马)修复原版中NoCC的问题 https://github.com/j1anFen/shiro_attack

Java 2,379 283 Updated Apr 10, 2024

Spring Boot web application vulnerable to Log4Shell (CVE-2021-44228).

Java 1,139 554 Updated Apr 26, 2024

Spring Cloud Netflix Hystrix Dashboard template resolution vulnerability CVE-2021-22053

Java 37 8 Updated Dec 15, 2022

Additional materials for RootedCON 2015 Apache Struts talk

Java 30 3 Updated Mar 6, 2015

注入JVM进程 动态获取目标进程连接的数据库

Java 342 39 Updated Mar 6, 2022

PaddingZip is a tool that you can craft a zip file that contains the padding characters between the file content.

Python 81 4 Updated Aug 14, 2022

springboot跨线程注入内存马

Java 123 12 Updated Apr 10, 2022

Java安全相关的漏洞和技术demo,原生Java、Fastjson、Jackson、Hessian2、XML反序列化漏洞利用和Spring、Dubbo、Shiro、CAS、Tomcat、RMI、Nexus等框架\中间件\功能的exploits以及Java Security Manager绕过、Dubbo-Hessian2安全加固等等实践代码。

Java 2,688 497 Updated Mar 14, 2024

A tool to dump Java serialization streams in a more human readable form.

Java 1,065 128 Updated Jun 21, 2024