- All languages
- Assembly
- AutoHotkey
- Batchfile
- C
- C#
- C++
- CMake
- CSS
- CodeQL
- CoffeeScript
- Dart
- Dockerfile
- EJS
- Elixir
- Go
- HTML
- Haskell
- Java
- JavaScript
- Jupyter Notebook
- Kotlin
- Less
- Lua
- Meson
- Objective-C
- PHP
- Perl
- PowerShell
- Python
- Roff
- Ruby
- Rust
- SCSS
- Shell
- Smali
- Swift
- TSQL
- TeX
- TypeScript
- Vim Script
- Visual Basic .NET
- Vue
- XSLT
- YARA
Starred repositories
JDK main-line development https://openjdk.org/projects/jdk
一个轻量级 Java 权限认证框架,让鉴权变得简单、优雅!—— 登录认证、权限认证、分布式Session会话、微服务网关鉴权、单点登录、OAuth2.0
Suite of tools for deploying and training deep learning models using the JVM. Highlights include model import for keras, tensorflow, and onnx/pytorch, a modular and tiny c++ library for running mat…
OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies.
Decompiler from Java bytecode to Java, used in IntelliJ IDEA.
FlatLaf - Swing Look and Feel (with Darcula/IntelliJ themes support)
HaE - Highlighter and Extractor, Empower ethical hacker for efficient operations.
Apache Log4j is a versatile, feature-rich, efficient logging API and backend for Java.
cSploit - The most complete and advanced IT security professional toolkit on Android.
JNDI注入测试工具(A tool which generates JNDI links can start several servers to exploit JNDI Injection vulnerability,like Jackson,Fastjson,etc)
Java安全相关的漏洞和技术demo,原生Java、Fastjson、Jackson、Hessian2、XML反序列化漏洞利用和Spring、Dubbo、Shiro、CAS、Tomcat、RMI、Nexus等框架\中间件\功能的exploits以及Java Security Manager绕过、Dubbo-Hessian2安全加固等等实践代码。
shiro反序列化漏洞综合利用,包含(回显执行命令/注入内存马)修复原版中NoCC的问题 https://github.com/j1anFen/shiro_attack
APIKit:Discovery, Scan and Audit APIs Toolkit All In One.
China's first CTFTools framework.中国国内首个CTF工具框架,旨在帮助CTFer快速攻克难关
项目是根据LandGrey/SpringBootVulExploit清单编写,目的hvv期间快速利用漏洞、降低漏洞利用门槛。
A burp extension that add some useful function to Context Menu 添加一些右键菜单让burp用起来更顺畅
TCP/UDP Non-HTTP Proxy Extension (NoPE) for Burp Suite.
Thinkphp(GUI)漏洞利用工具,支持各版本TP漏洞检测,命令执行,getshell。
BeautyEye is a Java Swing cross-platform look and feel.
PySonar2: a semantic indexer for Python with interprocedual type inference
Fastjson vulnerability quickly exploits the framework(fastjson漏洞快速利用框架)
CaA - Collector and Analyzer, Insight into information, exploring with intelligence in a thousand ways.