Skip to content
View b1win0y's full-sized avatar

Block or report b1win0y

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
59 stars written in Java
Clear filter

SpringBoot 相关漏洞学习资料,利用方法和技巧合集,黑盒安全评估 check list

Java 6,126 1,321 Updated Mar 10, 2021

Elder driver Xposed Framework.

Java 5,660 647 Updated Apr 12, 2022

一个漏洞 PoC 知识库。A knowledge base for vulnerability PoCs(Proof of Concept), with 1k+ vulnerabilities.

Java 4,913 1,011 Updated Mar 23, 2026

基于Spring Boot 2.x的一站式前后端分离快速开发平台XBoot 微信小程序+Uniapp 前端:Vue+iView Admin 后端:Spring Boot 2.x/Spring Security/JWT/JPA+Mybatis-Plus/Redis/Elasticsearch/Activiti 分布式限流/同步锁/验证码/SnowFlake雪花算法ID 动态权限 数据权限 工作…

Java 3,889 1,301 Updated Jun 14, 2023

红蓝对抗以及护网相关工具和资料,内存shellcode(cs+msf)和内存马查杀工具

Java 2,580 574 Updated Mar 8, 2026

shiro反序列化漏洞综合利用,包含(回显执行命令/注入内存马)修复原版中NoCC的问题 https://github.com/j1anFen/shiro_attack

Java 2,452 284 Updated Apr 12, 2026

APIKit:Discovery, Scan and Audit APIs Toolkit All In One.

Java 2,260 181 Updated Apr 2, 2024

基于JavaFx搭建的实用小工具集合,方便开发过程中的代码编写与调试,想学习javaFx的同学可以参考参考。其中包括文件复制、Cron表达式生成器、编码转换、加密解密、Time转换、路径转换、二维码生成工具、身份证生成器、正则表达式生成工具、网址缩短、转义字符、字符串转换、Mq调试工具、Http调试工具、json格式化编辑工具、图标生成工具、Redis连接工具、网页源码下载工具、切换Host…

Java 2,227 564 Updated Nov 24, 2025

MDUT - Multiple Database Utilization Tools

Java 2,209 233 Updated Sep 22, 2023

一款支持自定义的 Java 内存马生成工具|A customizable Java in-memory webshell generation tool.

Java 2,179 234 Updated Aug 21, 2025

溯光 (TrackRay) 3 beta⚡渗透测试框架(资产扫描|指纹识别|暴力破解|网页爬虫|端口扫描|漏洞扫描|代码审计|AWVS|NMAP|Metasploit|SQLMap)

Java 2,080 368 Updated Dec 16, 2023

项目是根据LandGrey/SpringBootVulExploit清单编写,目的hvv期间快速利用漏洞、降低漏洞利用门槛。

Java 1,903 314 Updated Jan 15, 2024

captcha-killer的修改版,支持关键词识别base64编码的图片,添加免费ocr库,用于验证码爆破,适配新版Burpsuite

Java 1,899 177 Updated Aug 26, 2025

高危漏洞利用工具

Java 1,834 246 Updated Feb 12, 2025

一款基于BurpSuite的被动式shiro检测插件

Java 1,798 159 Updated Dec 14, 2022

Burp extension to evade TLS fingerprinting. Bypass WAF, spoof any browser.

Java 1,790 117 Updated Apr 7, 2026

Shiro基于SpringBoot +JWT搭建简单的restful服务

Java 1,641 503 Updated Feb 11, 2026

BurpCrypto is a collection of burpsuite encryption plug-ins, support AES/RSA/DES/ExecJs(execute JS encryption code in burpsuite). 支持多种加密算法或直接执行JS代码的用于爆破前端加密的BurpSuite插件

Java 1,627 172 Updated Aug 4, 2023

Thinkphp(GUI)漏洞利用工具,支持各版本TP漏洞检测,命令执行,getshell。

Java 1,572 184 Updated Jun 1, 2022

OAExploit一款基于产品的一键扫描工具。

Java 1,483 197 Updated Sep 20, 2022

一款专注于 Java 主流 Web 中间件的内存马快速生成工具,致力于简化安全研究人员和红队成员的工作流程,提升攻防效率

Java 1,409 143 Updated Apr 9, 2026

Burp插件,根据自定义来达到对数据包的处理(适用于加解密、爆破等),类似mitmproxy,不同点在于经过了burp中转,在自动加解密的基础上,不影响APP、网站加解密正常逻辑等。

Java 1,364 97 Updated Apr 14, 2026

Nuclei plugin for BurpSuite

Java 1,330 134 Updated Oct 22, 2025

一款基于BurpSuite的被动式FastJson检测插件

Java 1,242 131 Updated Oct 1, 2022

RiskScanner 是开源的多云安全合规扫描平台,基于 Cloud Custodian 和 Nuclei 引擎,实现对主流公(私)有云资源的安全合规扫描和漏洞扫描。

Java 1,151 185 Updated Apr 14, 2023

将安卓远控Apk附加进普通的App中,运行新生成的App时,普通App正常运行,远控正常上线。Attach the Android remote control APK to a regular app. When the newly generated app is launched, the regular app operates as normal while the remote …

Java 1,018 275 Updated Sep 9, 2024

Java RCE 回显测试代码

Java 1,017 174 Updated Oct 15, 2020

❄️冰蝎客户端源码-V4.0.6🔞

Java 942 286 Updated Jul 8, 2025

Automated HTTP Request Repeating With Burp Suite

Java 893 120 Updated Dec 15, 2021

Nacos JRaft Hessian 反序列化 RCE 加载字节码 注入内存马 不出网利用

Java 849 91 Updated Jul 7, 2023
Next