Skip to content
View cc06's full-sized avatar

Block or report cc06

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
21 stars written in Java
Clear filter

Tools to work with android .dex and java .class files

Java 13,107 2,192 Updated Jul 21, 2024

A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.

Java 8,844 1,852 Updated Dec 4, 2025

JNDI注入测试工具(A tool which generates JNDI links can start several servers to exploit JNDI Injection vulnerability,like Jackson,Fastjson,etc)

Java 2,797 737 Updated Mar 22, 2023

jSQL Injection is a Java application for automatic SQL database injection.

Java 1,759 441 Updated Mar 27, 2026

Fastjson vulnerability quickly exploits the framework(fastjson漏洞快速利用框架)

Java 1,393 176 Updated Dec 16, 2022

A helpful Java Deserialization exploit framework.

Java 1,242 149 Updated Feb 17, 2025

A tool to dump Java serialization streams in a more human readable form.

Java 1,069 127 Updated Jun 21, 2024

用于host碰撞而生的小工具,专门检测渗透中需要绑定hosts才能访问的主机或内部系统

Java 668 66 Updated Jun 13, 2024

A powerful JNDI injection exploitation framework that supports RMI, LDAP and LDAPS protocols, including various bypass methods for high-version JDK restrictions

Java 578 39 Updated Feb 4, 2026

Sample codes written for the Hackers to Hackers Conference magazine 2017 (H2HC).

Java 521 113 Updated Mar 11, 2022

A collection of Cortana scripts that you may use with Armitage and Cobalt Strike 2.x. Cortana Scripts are not compatible with Cobalt Strike 3.x. Cobalt Strike 3.x uses a variant of Cortana called A…

Java 459 287 Updated Mar 2, 2021

fastjson remote code execute poc 直接用intellij IDEA打开即可 首先编译得到Test.class,然后运行Poc.java

Java 403 133 Updated Dec 16, 2022

Fastjson <= 1.2.47 远程命令执行漏洞利用工具及方法

Java 401 71 Updated Jan 24, 2025

😈 Jenkins RCE PoC. From unauthenticated user to remote code execution, it's a hacker's dream!

Java 298 59 Updated Jun 10, 2019

解密weblogic AES或DES加密方法

Java 232 36 Updated Dec 3, 2020

Java-Web-Security - Sichere Webanwendungen mit Java entwickeln

Java 222 62 Updated Apr 15, 2026

A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.优化了一些东西。

Java 214 32 Updated Jan 17, 2022

Mogwai Java Management Extensions (JMX) Exploitation Toolkit

Java 175 31 Updated Jul 21, 2016

Some codes for bypassing Oracle WebLogic CVE-2018-2628 patch

Java 114 48 Updated May 21, 2018

Spring messaging STOMP protocol RCE

Java 113 18 Updated Apr 12, 2018