Skip to content
View cwkiller's full-sized avatar
🍉
🍉

Block or report cwkiller

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Stars

Java

52 repositories

《Java安全-只有Java安全才能拯救宇宙》Only Java Security Can Save The Universe.

2,637 484 Updated Aug 4, 2023

一个LDAP请求监听器,摆脱dnslog平台

Java 285 60 Updated Apr 7, 2023

自己学习java安全的一些总结,主要是安全审计相关

1,592 209 Updated Jan 5, 2022

🤗 JVM 底层原理最全知识总结

Java 10,558 2,280 Updated Sep 17, 2024

payloads

Java 15 Updated Mar 17, 2021

关于学习java安全的一些知识,正在学习中ing,欢迎fork and star

Java 763 147 Updated Jul 11, 2023

拿来即用的Tomcat7/8/9/10版本Listener/Filter/Servlet内存马,支持注入CMD内存马和冰蝎内存马

Java 488 77 Updated Aug 31, 2022

解决FastJson、Jackson、Log4j2、原生JNDI注入漏洞的高版本JDKBypass利用,探测本地可用反序列化gadget达到命令执行、回显命令执行、内存马注入

Java 687 113 Updated Jan 26, 2022

ZKar is a Java serialization protocol analysis tool implement in Go.

Go 603 52 Updated Aug 5, 2024
Java 303 41 Updated Aug 7, 2024

a rep for documenting my study, may be from 0 to 0.1

Java 1,948 296 Updated Dec 16, 2024

When MVC magic turns black

Java 289 28 Updated Sep 4, 2020

构造字节在ASCII范围内的jar

Python 70 4 Updated Feb 14, 2022

JRE8u20_RCE_Gadget

Java 252 42 Updated Jul 1, 2016

Parse HPROF files from the Spring Boot Heapdump Actuator

Python 26 5 Updated Jun 11, 2024

HeapDump敏感信息提取工具

Java 1,364 133 Updated Dec 12, 2024

对原版https://github.com/feihong-cs/JNDIExploit 进行了实用化修改

Java 1,387 290 Updated Oct 16, 2022

ysoserial修改版,着重修改ysoserial.payloads.util.Gadgets.createTemplatesImpl使其可以通过引入自定义class的形式来执行命令、内存马、反序列化回显。

Java 647 105 Updated Jan 11, 2024

通过JavaAgent与Javassist技术对JVM加载的类对象进行动态插桩,可以做一些破解、加密验证的绕过等操作

Java 96 6 Updated Jun 18, 2024

shiro反序列化漏洞综合利用,包含(回显执行命令/注入内存马)修复原版中NoCC的问题 https://github.com/j1anFen/shiro_attack

Java 2,121 271 Updated Apr 10, 2024

Spring Boot web application vulnerable to Log4Shell (CVE-2021-44228).

Java 1,110 536 Updated Apr 26, 2024

Spring Cloud Netflix Hystrix Dashboard template resolution vulnerability CVE-2021-22053

Java 37 8 Updated Dec 15, 2022

Additional materials for RootedCON 2015 Apache Struts talk

Java 29 3 Updated Mar 6, 2015

注入JVM进程 动态获取目标进程连接的数据库

Java 310 37 Updated Mar 6, 2022

PaddingZip is a tool that you can craft a zip file that contains the padding characters between the file content.

Python 62 3 Updated Aug 14, 2022

springboot跨线程注入内存马

Java 115 10 Updated Apr 10, 2022

Java安全相关的漏洞和技术demo,原生Java、Fastjson、Jackson、Hessian2、XML反序列化漏洞利用和Spring、Dubbo、Shiro、CAS、Tomcat、RMI、Nexus等框架\中间件\功能的exploits以及Java Security Manager绕过、Dubbo-Hessian2安全加固等等实践代码。

Java 2,612 496 Updated Mar 14, 2024
Java 3,421 684 Updated Dec 11, 2022

A tool to dump Java serialization streams in a more human readable form.

Java 998 125 Updated Jun 21, 2024