Skip to content
View pen4uin's full-sized avatar

Block or report pen4uin

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
39 stars written in Java
Clear filter

A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.

Java 8,859 1,854 Updated Dec 4, 2025

Quickly find differences and similarities in disassembled code

Java 3,014 225 Updated Nov 10, 2025

Java安全相关的漏洞和技术demo,原生Java、Fastjson、Jackson、Hessian2、XML反序列化漏洞利用和Spring、Dubbo、Shiro、CAS、Tomcat、RMI、Nexus等框架\中间件\功能的exploits以及Java Security Manager绕过、Dubbo-Hessian2安全加固等等实践代码。

Java 2,695 496 Updated Mar 14, 2024

a rep for documenting my study, may be from 0 to 0.1

Java 2,266 339 Updated Mar 25, 2026

一款支持自定义的 Java 内存马生成工具|A customizable Java in-memory webshell generation tool.

Java 2,188 235 Updated Aug 21, 2025

Share Things Related to Java - Java安全漫谈笔记相关内容

Java 2,007 229 Updated Apr 9, 2025

An easy-to-learn/use static analysis framework for Java

Java 1,779 196 Updated Mar 22, 2026

HeapDump敏感信息提取工具

Java 1,653 147 Updated Dec 15, 2025

A CAT called tabby ( Code Analysis Tool )

Java 1,646 181 Updated Jan 17, 2026

WebSocket 内存马/Webshell,一种新型内存马/WebShell技术

Java 1,494 230 Updated Apr 10, 2023

一款专注于 Java 主流 Web 中间件的内存马快速生成工具,致力于简化安全研究人员和红队成员的工作流程,提升攻防效率

Java 1,430 146 Updated Apr 26, 2026

A helpful Java Deserialization exploit framework.

Java 1,241 149 Updated Feb 17, 2025

A byte code analyzer for finding deserialization gadget chains in Java applications

Java 1,081 228 Updated Jun 15, 2021

A malicious LDAP server for JNDI injection attacks

Java 1,080 228 Updated Sep 28, 2023

A tool to dump Java serialization streams in a more human readable form.

Java 1,069 127 Updated Jun 21, 2024

java内存对象搜索辅助工具

Java 823 87 Updated Sep 23, 2022

关于学习java安全的一些知识,正在学习中ing,欢迎fork and star

Java 792 147 Updated Jul 11, 2023

给woodpecker框架量身定制的ysoserial

Java 617 72 Updated Oct 26, 2022

《深入JDBC安全:特殊URL构造与不出网反序列化利用技术揭秘》对应研究总结项目 "Deep Dive into JDBC Security: Special URL Construction and Non-Networked Deserialization Exploitation Techniques Revealed" - Research Summary Project

Java 577 44 Updated Feb 7, 2026

一款支持自定义的 Java 回显载荷生成工具|A customizable Java echo payload generation tool.

Java 463 43 Updated Jan 12, 2025

Java web路由内存分析工具

Java 439 26 Updated May 22, 2025

Dump classes from running JVM process.

Java 432 88 Updated Aug 30, 2022

Look-Ahead Java Deserialization Library

Java 424 70 Updated Jan 7, 2020

Collection of bypass gadgets to extend and wrap ysoserial payloads

Java 387 78 Updated Apr 16, 2022

Apache Dubbo (CVE-2023-23638)漏洞利用的工程化实践

Java 231 29 Updated Aug 8, 2023
Java 208 28 Updated Oct 27, 2025

Spring Actuator端点的BurpSuite被动扫描插件。

Java 202 19 Updated Nov 2, 2022

Java表达式语句生成器

Java 194 13 Updated Oct 9, 2023
Next