Skip to content
View heroanswer's full-sized avatar
🤒
Out sick
🤒
Out sick

Organizations

@okrce

Block or report heroanswer

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
32 stars written in Java
Clear filter

Alibaba Java Diagnostic Tool Arthas/Alibaba Java诊断利器Arthas

Java 36,826 7,603 Updated Oct 23, 2025

A free, secure and open source app for Android to manage your 2-step verification tokens.

Java 11,341 474 Updated Aug 3, 2025

A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.

Java 8,571 1,843 Updated Mar 31, 2024

OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies.

Java 7,280 1,380 Updated Nov 5, 2025

SpringBoot 相关漏洞学习资料,利用方法和技巧合集,黑盒安全评估 check list

Java 6,048 1,321 Updated Mar 10, 2021

Java安全相关的漏洞和技术demo,原生Java、Fastjson、Jackson、Hessian2、XML反序列化漏洞利用和Spring、Dubbo、Shiro、CAS、Tomcat、RMI、Nexus等框架\中间件\功能的exploits以及Java Security Manager绕过、Dubbo-Hessian2安全加固等等实践代码。

Java 2,677 497 Updated Mar 14, 2024

Java web common vulnerabilities and security code which is base on springboot and spring security

Java 2,606 710 Updated Dec 2, 2024

一款高性能 HTTP 代理隧道工具 | A high-performance http proxy tunneling tool

Java 2,542 236 Updated Apr 14, 2025

项目是根据LandGrey/SpringBootVulExploit清单编写,目的hvv期间快速利用漏洞、降低漏洞利用门槛。

Java 1,890 317 Updated Jan 15, 2024

WebSocket 内存马/Webshell,一种新型内存马/WebShell技术

Java 1,477 231 Updated Apr 10, 2023

Burpsuite - Route Vulnerable Scanning 递归式被动检测脆弱路径的burp插件

Java 1,295 88 Updated Jun 29, 2024

Fiora:漏洞PoC框架Nuclei的图形版。快捷搜索PoC、一键运行Nuclei。即可作为独立程序运行,也可作为burp插件使用。

Java 1,263 149 Updated Jul 2, 2025

A byte code analyzer for finding deserialization gadget chains in Java applications

Java 1,064 229 Updated Jun 15, 2021

❄️冰蝎客户端源码-V4.0.6🔞

Java 929 288 Updated Jul 8, 2025

搜集了市面上绝大部分weblogic解密方式,整理了7种解密weblogic的方法及响应工具。

Java 832 177 Updated Nov 7, 2023

冰蝎 哥斯拉 WebShell bypass

Java 746 107 Updated Mar 18, 2022

Look-Ahead Java Deserialization Library

Java 423 71 Updated Jan 7, 2020

Java反序列化漏洞利用链补全计划,仅用于个人归纳总结。

Java 422 37 Updated Dec 3, 2021

内存马Demo合集 memshell demo for java / php / python

Java 421 76 Updated May 31, 2021

帆软/致远密码解密工具

Java 360 40 Updated Jul 29, 2021

Burp插件,Malleable C2 Profiles生成器;可以通过Burp代理选中请求,生成Cobalt Strike的profile文件(CSprofile)

Java 288 35 Updated Jan 15, 2022

适用于weblogic和Tomcat的无文件的内存马(memshell)

Java 270 23 Updated Mar 4, 2022

rmi打内存马工具,适用于目标用不了ldap的情况

Java 255 25 Updated Jul 12, 2023

解密weblogic AES或DES加密方法

Java 231 36 Updated Dec 3, 2020

shiro-cve-2020-17523 漏洞的两种绕过姿势分析 以及配套的漏洞环境

Java 117 12 Updated Feb 7, 2021

fastjson漏洞POC代码

Java 105 22 Updated May 29, 2022

本项目其实就是个简单的代理服务器,把代理池集成进来来了。

Java 86 17 Updated Jun 17, 2022
Next