Skip to content
View echohun's full-sized avatar

Block or report echohun

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
30 stars written in Java
Clear filter

APM, (Application Performance Management) tool for large-scale distributed systems.

Java 13,821 3,759 Updated Apr 30, 2026

A scalable web crawler framework for Java.

Java 11,686 4,140 Updated Dec 20, 2025

SpringBoot 相关漏洞学习资料,利用方法和技巧合集,黑盒安全评估 check list

Java 6,132 1,319 Updated Mar 10, 2021

一个漏洞 PoC 知识库。A knowledge base for vulnerability PoCs(Proof of Concept), with 1k+ vulnerabilities.

Java 4,944 1,017 Updated Apr 23, 2026

JNDI注入测试工具(A tool which generates JNDI links can start several servers to exploit JNDI Injection vulnerability,like Jackson,Fastjson,etc)

Java 2,798 738 Updated Mar 22, 2023

Java安全相关的漏洞和技术demo,原生Java、Fastjson、Jackson、Hessian2、XML反序列化漏洞利用和Spring、Dubbo、Shiro、CAS、Tomcat、RMI、Nexus等框架\中间件\功能的exploits以及Java Security Manager绕过、Dubbo-Hessian2安全加固等等实践代码。

Java 2,697 496 Updated Mar 14, 2024

红蓝对抗以及护网相关工具和资料,内存shellcode(cs+msf)和内存马查杀工具

Java 2,584 575 Updated Mar 8, 2026

domain_hunter的高级版本,SRC挖洞、HW打点之必备!自动化资产收集;快速Title获取;外部工具联动;等等

Java 2,123 209 Updated Apr 10, 2026

一款基于BurpSuite的被动式shiro检测插件

Java 1,799 159 Updated Dec 14, 2022

Thinkphp(GUI)漏洞利用工具,支持各版本TP漏洞检测,命令执行,getshell。

Java 1,574 185 Updated Jun 1, 2022

OAExploit一款基于产品的一键扫描工具。

Java 1,484 197 Updated Sep 20, 2022

Collect JSP webshell of various implementation methods. 梳理和发现的JSP Webshell各种姿势

Java 1,405 329 Updated Jan 18, 2022

Fastjson vulnerability quickly exploits the framework(fastjson漏洞快速利用框架)

Java 1,394 176 Updated Dec 16, 2022

Alibaba-Nacos-Unauthorized/ApacheDruid-RCE_CVE-2021-25646/MS-Exchange-SSRF-CVE-2021-26885/Oracle-WebLogic-CVE-2021-2109_RCE/RG-CNVD-2021-14536/RJ-SSL-VPN-UltraVires/Redis-Unauthorized-RCE/TDOA-V11.…

Java 1,078 315 Updated May 11, 2023

将安卓远控Apk附加进普通的App中,运行新生成的App时,普通App正常运行,远控正常上线。Attach the Android remote control APK to a regular app. When the newly generated app is launched, the regular app operates as normal while the remote …

Java 1,017 275 Updated Sep 9, 2024

分享几个直接可用的内存马,记录一下学习过程中看过的文章

Java 982 156 Updated Mar 23, 2022

一个简单的Fastjson反序列化检测burp插件

Java 973 75 Updated Jun 18, 2021

建议使用新版:https://github.com/jar-analyzer/jar-analyzer

Java 897 105 Updated Nov 30, 2023

Shiro RememberMe 1.2.4 反序列化漏洞图形化检测工具(Shiro-550)

Java 884 99 Updated Dec 16, 2022

CVE-2021-44228 Log4j2 BurpSuite Scanner,Customize ceye.io api or other apis,including internal networks

Java 841 107 Updated Jun 13, 2023

纯 Java 实现的 MySQL Fake Server | 支持 GUI 版和命令行版 | 支持反序列化和文件读取的利用方式 | 支持常见的 GADGET 和自定义 GADGET 数据 | 根据目标环境自动生成匹配的 PAYLOAD | 支持 PGSQL 和 DERBY 的利用

Java 827 96 Updated Sep 18, 2023

关于学习java安全的一些知识,正在学习中ing,欢迎fork and star

Java 792 147 Updated Jul 11, 2023

ysoserial修改版,着重修改ysoserial.payloads.util.Gadgets.createTemplatesImpl使其可以通过引入自定义class的形式来执行命令、内存马、反序列化回显。

Java 766 120 Updated Jan 11, 2024

Spring漏洞综合利用工具

Java 674 59 Updated Jul 5, 2023

云安全利用工具-云平台AK/SK-WEB利用工具,添加AK/SK自动检测资源,无需手动执行,支持云服务器、存储桶、数据库操作

Java 588 65 Updated Dec 19, 2024

FilterBased/ServletBased in memory shell for Tomcat and some other middlewares

Java 384 65 Updated Nov 6, 2020

一个LDAP请求监听器,摆脱dnslog平台

Java 291 58 Updated Apr 7, 2023

Fofa采集工具

Java 112 11 Updated Feb 10, 2022