Skip to content
View rabbitsafe's full-sized avatar

Block or report rabbitsafe

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
29 results for source starred repositories written in Java
Clear filter

Dex to Java decompiler

Java 46,028 5,320 Updated Nov 5, 2025

SpringBoot 相关漏洞学习资料,利用方法和技巧合集,黑盒安全评估 check list

Java 6,048 1,321 Updated Mar 10, 2021

HaE - Highlighter and Extractor, Empower ethical hacker for efficient operations.

Java 3,855 278 Updated Oct 30, 2025

JNDI注入测试工具(A tool which generates JNDI links can start several servers to exploit JNDI Injection vulnerability,like Jackson,Fastjson,etc)

Java 2,760 737 Updated Mar 22, 2023

Java安全相关的漏洞和技术demo,原生Java、Fastjson、Jackson、Hessian2、XML反序列化漏洞利用和Spring、Dubbo、Shiro、CAS、Tomcat、RMI、Nexus等框架\中间件\功能的exploits以及Java Security Manager绕过、Dubbo-Hessian2安全加固等等实践代码。

Java 2,677 497 Updated Mar 14, 2024

Java web common vulnerabilities and security code which is base on springboot and spring security

Java 2,606 710 Updated Dec 2, 2024

APIKit:Discovery, Scan and Audit APIs Toolkit All In One.

Java 2,197 177 Updated Apr 2, 2024

domain_hunter的高级版本,SRC挖洞、HW打点之必备!自动化资产收集;快速Title获取;外部工具联动;等等

Java 2,104 209 Updated Nov 5, 2025

Shiro550/Shiro721 一键化利用工具,支持多种回显方式

Java 1,944 297 Updated Jun 4, 2021

A burp extension that add some useful function to Context Menu 添加一些右键菜单让burp用起来更顺畅

Java 1,852 209 Updated Nov 3, 2025

高危漏洞利用工具

Java 1,806 244 Updated Feb 12, 2025

一款基于BurpSuite的被动式shiro检测插件

Java 1,778 163 Updated Dec 14, 2022

A simple FOFA client written in JavaFX. Made by WgpSec, Maintained by f1ashine.

Java 1,736 165 Updated Jun 11, 2024

Burp被动扫描流量转发插件

Java 1,451 172 Updated Jun 17, 2024

Fiora:漏洞PoC框架Nuclei的图形版。快捷搜索PoC、一键运行Nuclei。即可作为独立程序运行,也可作为burp插件使用。

Java 1,263 149 Updated Jul 2, 2025

一款基于BurpSuite的被动式FastJson检测插件

Java 1,225 133 Updated Oct 1, 2022

Spring Boot web application vulnerable to Log4Shell (CVE-2021-44228).

Java 1,130 550 Updated Apr 26, 2024

Alibaba-Nacos-Unauthorized/ApacheDruid-RCE_CVE-2021-25646/MS-Exchange-SSRF-CVE-2021-26885/Oracle-WebLogic-CVE-2021-2109_RCE/RG-CNVD-2021-14536/RJ-SSL-VPN-UltraVires/Redis-Unauthorized-RCE/TDOA-V11.…

Java 1,080 316 Updated May 11, 2023

🐱‍💻 ✂️ 🤬 CVE-2021-44228 - LOG4J Java exploit - WAF bypass tricks

Java 956 138 Updated Jan 15, 2022

CVE-2021-44228 Log4j2 BurpSuite Scanner,Customize ceye.io api or other apis,including internal networks

Java 838 109 Updated Jun 13, 2023

spring boot Fat Jar 任意写文件漏洞到稳定 RCE 利用技巧

Java 747 75 Updated Apr 14, 2021

越权检测工具

Java 744 159 Updated Jun 17, 2022

Burpsuite-Plugins-Usage

Java 518 129 Updated Apr 7, 2020

Some payloads of JNDI Injection in JDK 1.8.0_191+

Java 482 82 Updated Dec 9, 2020

Fastjson <= 1.2.47 远程命令执行漏洞利用工具及方法

Java 400 74 Updated Jan 24, 2025
Java 318 51 Updated Jun 4, 2021

解密weblogic AES或DES加密方法

Java 231 36 Updated Dec 3, 2020

woodpecker框架weblogic信息探测插件

Java 184 25 Updated Mar 23, 2022

woodpecker-framework框架http发包库,专门为漏洞检测与利用场景设计。

Java 69 10 Updated Nov 5, 2025