Skip to content
View MUYU212's full-sized avatar
💭
战斗ing
💭
战斗ing

Block or report MUYU212

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
134 stars written in Java
Clear filter

一款专注于 Java 主流 Web 中间件的内存马快速生成工具,致力于简化安全研究人员和红队成员的工作流程,提升攻防效率

Java 1,229 135 Updated Dec 14, 2025

基于SSM的图书馆管理系统。主要功能包括:图书查询、图书管理、图书编辑、读者管理、图书的借阅与归还以及借还日志记录等。

Java 1,225 346 Updated Jul 9, 2020

xia SQL (瞎注) burp 插件 ,在每个参数后面填加一个单引号,两个单引号,一个简单的判断注入小插件。

Java 1,186 84 Updated May 18, 2023

A malicious LDAP server for JNDI injection attacks

Java 1,074 228 Updated Sep 28, 2023

将安卓远控Apk附加进普通的App中,运行新生成的App时,普通App正常运行,远控正常上线。Attach the Android remote control APK to a regular app. When the newly generated app is launched, the regular app operates as normal while the remote …

Java 1,012 272 Updated Sep 9, 2024

一个想让你测试加密流量像测试明文一样简单高效的 Burp 插件。 A Burp plugin that makes testing encrypted traffic as simple and efficient as testing plaintext.

Java 1,009 70 Updated Dec 1, 2025

通过jsp脚本扫描java web Filter/Servlet型内存马

Java 979 130 Updated Mar 9, 2023

仓库管理系统

Java 949 320 Updated Oct 6, 2025

🔨 基于SpringBoot的CMS/DMS/管理系统开发框架

Java 945 264 Updated Sep 22, 2025

Memshell-攻防内存马研究

Java 917 109 Updated Apr 13, 2025

A third-party Xposed framework implementation which supports Android 5.0~14.

Java 893 91 Updated Mar 25, 2024

80+ Gadgets(30 More than ysoserial). JNDI-Injection-Exploit-Plus is a tool for generating workable JNDI links and provide background services by starting RMI server,LDAP server and HTTP server.

Java 859 108 Updated Jun 24, 2024

An android Dex protection shell implementation

Java 839 292 Updated Dec 12, 2025

CVE-2021-44228 Log4j2 BurpSuite Scanner,Customize ceye.io api or other apis,including internal networks

Java 838 109 Updated Jun 13, 2023

搜集了市面上绝大部分weblogic解密方式,整理了7种解密weblogic的方法及响应工具。

Java 834 177 Updated Nov 7, 2023

Log4j2 RCE Passive Scanner plugin for BurpSuite

Java 825 95 Updated Aug 4, 2023

纯 Java 实现的 MySQL Fake Server | 支持 GUI 版和命令行版 | 支持反序列化和文件读取的利用方式 | 支持常见的 GADGET 和自定义 GADGET 数据 | 根据目标环境自动生成匹配的 PAYLOAD | 支持 PGSQL 和 DERBY 的利用

Java 815 92 Updated Sep 18, 2023

获取Android应用基本信息的工具集

Java 758 155 Updated Nov 8, 2024

一个半自动化springboot打点工具,内置目前springboot所有漏洞

Java 750 56 Updated Sep 30, 2025

ysoserial修改版,着重修改ysoserial.payloads.util.Gadgets.createTemplatesImpl使其可以通过引入自定义class的形式来执行命令、内存马、反序列化回显。

Java 748 120 Updated Jan 11, 2024

spring boot Fat Jar 任意写文件漏洞到稳定 RCE 利用技巧

Java 748 75 Updated Apr 14, 2021

Java RMI enumeration and attack tool.

Java 740 100 Updated Sep 28, 2017

Burp插件,快速探测可能存在SQL注入的请求并标记,提高测试效率

Java 697 38 Updated Nov 28, 2025

a webshell resides in the memory of java web server

Java 689 152 Updated Jun 26, 2018

ROM逆向工具

Java 646 235 Updated Mar 12, 2024

(周瑜)Java - SpringBoot 持久化 WebShell(不仅仅是SpringBoot,适合任何符合JavaEE规范的服务)

Java 616 64 Updated Dec 29, 2021

给woodpecker框架量身定制的ysoserial

Java 602 72 Updated Oct 26, 2022

JNDI在java高版本的利用工具,FUZZ利用链

Java 590 68 Updated Oct 8, 2022

《深入JDBC安全:特殊URL构造与不出网反序列化利用技术揭秘》对应研究总结项目 "Deep Dive into JDBC Security: Special URL Construction and Non-Networked Deserialization Exploitation Techniques Revealed" - Research Summary Project

Java 535 38 Updated Nov 14, 2025

个人博客系统(Spring+Spring MVC+MyBatis )

Java 508 156 Updated Mar 13, 2018