Skip to content
View NAXG's full-sized avatar

Block or report NAXG

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
34 stars written in Java
Clear filter

A standalone Java Decompiler GUI

Java 15,058 2,478 Updated Jul 8, 2024

SpringBoot 相关漏洞学习资料,利用方法和技巧合集,黑盒安全评估 check list

Java 6,128 1,320 Updated Mar 10, 2021

MDUT - Multiple Database Utilization Tools

Java 2,209 234 Updated Sep 22, 2023

一款支持自定义的 Java 内存马生成工具|A customizable Java in-memory webshell generation tool.

Java 2,179 234 Updated Aug 21, 2025

domain_hunter的高级版本,SRC挖洞、HW打点之必备!自动化资产收集;快速Title获取;外部工具联动;等等

Java 2,121 209 Updated Apr 9, 2026

Burp suite 分块传输辅助插件

Java 2,032 297 Updated Feb 23, 2022

A burp extension that add some useful function to Context Menu 添加一些右键菜单让burp用起来更顺畅

Java 1,915 209 Updated Apr 3, 2026

JNDIExploit or a ysoserial.

Java 1,748 190 Updated Mar 30, 2026

TCP/UDP Non-HTTP Proxy Extension (NoPE) for Burp Suite.

Java 1,653 241 Updated May 25, 2024

BurpCrypto is a collection of burpsuite encryption plug-ins, support AES/RSA/DES/ExecJs(execute JS encryption code in burpsuite). 支持多种加密算法或直接执行JS代码的用于爆破前端加密的BurpSuite插件

Java 1,627 172 Updated Aug 4, 2023

CaA - Collector and Analyzer, Insight into information, exploring with intelligence in a thousand ways.

Java 1,452 83 Updated Mar 19, 2026

Fastjson vulnerability quickly exploits the framework(fastjson漏洞快速利用框架)

Java 1,394 176 Updated Dec 16, 2022

攻防演练过程中,我们通常会用浏览器访问一些资产,但很多未授权/敏感信息/越权隐匿在已访问接口过html、JS文件等,该插件能让我们发现未授权/敏感信息/越权/登陆接口等。

Java 1,384 75 Updated Oct 3, 2024

Burp插件,根据自定义来达到对数据包的处理(适用于加解密、爆破等),类似mitmproxy,不同点在于经过了burp中转,在自动加解密的基础上,不影响APP、网站加解密正常逻辑等。

Java 1,362 97 Updated Mar 20, 2026

一款基于BurpSuite的被动式FastJson检测插件

Java 1,242 131 Updated Oct 1, 2022

对Auth/Waf 自动化bypass的burpsuite插件

Java 1,126 56 Updated Feb 28, 2026

一个用于前端加密Fuzz的Burp Suite插件

Java 1,066 124 Updated Mar 6, 2020

Java RCE 回显测试代码

Java 1,017 174 Updated Oct 15, 2020

通过jsp脚本扫描java web Filter/Servlet型内存马

Java 993 130 Updated Mar 9, 2023

Nacos JRaft Hessian 反序列化 RCE 加载字节码 注入内存马 不出网利用

Java 848 91 Updated Jul 7, 2023

Log4j2 RCE Passive Scanner plugin for BurpSuite

Java 832 96 Updated Aug 4, 2023

冰蝎 哥斯拉 WebShell bypass

Java 764 107 Updated Jan 15, 2026

用于host碰撞而生的小工具,专门检测渗透中需要绑定hosts才能访问的主机或内部系统

Java 667 66 Updated Jun 13, 2024

(周瑜)Java - SpringBoot 持久化 WebShell(不仅仅是SpringBoot,适合任何符合JavaEE规范的服务)

Java 615 64 Updated Dec 29, 2021

多功能 java agent 内存马

Java 520 63 Updated Oct 8, 2023

Burp插件,自动化挖掘SSRF,Redirect,Sqli漏洞,自定义匹配参数

Java 467 13 Updated Sep 10, 2023

AntSword Shell 脚本分享/示例

Java 401 77 Updated May 23, 2021

A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.

Java 357 54 Updated Sep 20, 2022
Java 319 51 Updated Jun 4, 2021

改造BeichenDream/InjectJDBC加入shiro获取key和修改key功能

Java 280 35 Updated Nov 28, 2023
Next