Skip to content
View X1r0z's full-sized avatar

Organizations

@X1cT34m

Block or report X1r0z

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Stars

Java Security

52 repositories

Some ReadObject Sink With JDBC

Java 240 18 Updated May 8, 2024

Java Js Engine Payloads All in one

288 24 Updated Aug 21, 2023

JDBC Connection URL Attack

Java 435 44 Updated Sep 10, 2021

纯 Java 实现的 MySQL Fake Server | 支持 GUI 版和命令行版 | 支持反序列化和文件读取的利用方式 | 支持常见的 GADGET 和自定义 GADGET 数据 | 根据目标环境自动生成匹配的 PAYLOAD | 支持 PGSQL 和 DERBY 的利用

Java 817 92 Updated Sep 18, 2023

Alibaba Java Diagnostic Tool Arthas/Alibaba Java诊断利器Arthas

Java 36,959 7,618 Updated Dec 19, 2025

java内存对象搜索辅助工具

Java 819 87 Updated Sep 23, 2022

Java RMI Vulnerability Scanner

Java 910 108 Updated Jul 3, 2024

spring boot Fat Jar 任意写文件漏洞到稳定 RCE 利用技巧

Java 750 75 Updated Apr 14, 2021

HeapDump敏感信息提取工具

Java 1,610 146 Updated Dec 15, 2025

多功能 java agent 内存马

Java 502 59 Updated Oct 8, 2023

Jar Analyzer - 一个 JAR 包 GUI 分析工具,方法调用关系搜索,方法调用链 DFS 算法分析,模拟 JVM 的污点分析验证 DFS 结果,字符串搜索,Java Web 组件入口分析,CFG 程序分析,JVM 栈帧分析,自定义表达式搜索,支持 MCP 调用,文档:https://docs.qq.com/doc/DV3pKbG9GS0pJS0tk

Java 1,839 170 Updated Nov 22, 2025

JNDIExploit or a ysoserial.

Java 1,721 189 Updated Nov 10, 2025

jolokia-exploitation-toolkit

Python 309 32 Updated Dec 19, 2024

无需文件落地Agent内存马生成器

Java 246 17 Updated May 30, 2024
Java 145 11 Updated Jan 16, 2023

a rep for documenting my study, may be from 0 to 0.1

Java 2,222 337 Updated Nov 10, 2025

A list for Spring Security

Java 125 16 Updated Jan 16, 2024

基于 jdwp-shellifier 的进阶JDWP漏洞利用脚本(动态执行Java/Js代码并获得回显)

Python 318 31 Updated Dec 22, 2024

一款支持自定义的 Java 回显载荷生成工具|A customizable Java echo payload generation tool.

Java 456 43 Updated Jan 12, 2025

一款支持自定义的 Java 内存马生成工具|A customizable Java in-memory webshell generation tool.

Java 2,125 233 Updated Aug 21, 2025

A neo4j procedure for tabby

Java 136 8 Updated May 17, 2025

A helpful Java Deserialization exploit framework.

Java 1,233 151 Updated Feb 17, 2025

A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.

Java 8,660 1,848 Updated Dec 4, 2025

哥斯拉

4,301 567 Updated Jul 17, 2024

“冰蝎”动态二进制加密网站管理客户端

6,110 978 Updated Aug 24, 2023

JMX enumeration and attacking tool.

Java 481 51 Updated Jun 26, 2025

🐛 Java ASM

Java 344 73 Updated Feb 24, 2025

heapdump敏感信息查询工具,例如查找 spring heapdump中的密码明文,AK,SK等

1,430 143 Updated May 21, 2024