Skip to content
View chi111i's full-sized avatar
  • Qufu Normal University
  • No. 57 Jingxuan West Road, Lucheng Subdistrict, Qufu City, Jining City, Shandong Province
  • 01:52 (UTC -12:00)

Highlights

  • Pro

Block or report chi111i

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Stars

JAVA

48 repositories

A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.

Java 8,654 1,848 Updated Dec 4, 2025

shiro反序列化漏洞综合利用,包含(回显执行命令/注入内存马)修复原版中NoCC的问题 https://github.com/j1anFen/shiro_attack

Java 2,356 281 Updated Apr 10, 2024

Shiro550/Shiro721 一键化利用工具,支持多种回显方式

Java 1,948 297 Updated Jun 4, 2021

a rep for documenting my study, may be from 0 to 0.1

Java 2,220 337 Updated Nov 10, 2025

项目是根据LandGrey/SpringBootVulExploit清单编写,目的hvv期间快速利用漏洞、降低漏洞利用门槛。

Java 1,894 317 Updated Jan 15, 2024

一款支持自定义的 Java 内存马生成工具|A customizable Java in-memory webshell generation tool.

Java 2,125 233 Updated Aug 21, 2025

JNDIExploit or a ysoserial.

Java 1,721 189 Updated Nov 10, 2025

HeapDump敏感信息提取工具

Java 1,609 146 Updated Dec 15, 2025

A helpful Java Deserialization exploit framework.

Java 1,233 151 Updated Feb 17, 2025

Java RCE 回显测试代码

Java 1,014 175 Updated Oct 15, 2020

记录一下 Java 安全学习历程,也算是半条学习路线了

Java 1,280 121 Updated Jun 26, 2025

Shiro RememberMe 1.2.4 反序列化漏洞图形化检测工具(Shiro-550)

Java 868 98 Updated Dec 16, 2022

Java编写,Python作为辅助依赖的漏洞验证、利用工具,添加了进程查找模块、编码模块、命令模块、常见漏洞利用GUI模块、shiro rememberMe解密模块,加快测试效率

Java 751 106 Updated Feb 25, 2024

80+ Gadgets(30 More than ysoserial). JNDI-Injection-Exploit-Plus is a tool for generating workable JNDI links and provide background services by starting RMI server,LDAP server and HTTP server.

Java 861 108 Updated Jun 24, 2024

解决FastJson、Jackson、Log4j2、原生JNDI注入漏洞的高版本JDKBypass利用,探测本地可用反序列化gadget达到命令执行、回显命令执行、内存马注入

Java 761 112 Updated Jan 26, 2022

Spring漏洞综合利用工具

Java 675 60 Updated Jul 5, 2023

shiro综合利用工具

Java 642 84 Updated Apr 15, 2023

JAVA 插件化漏洞扫描器,Gui基于javafx。POC 目前集成 Weblogic、Tomcat、Shiro、Spring等。

Java 542 68 Updated Nov 20, 2023

JNDI在java高版本的利用工具,FUZZ利用链

Java 590 69 Updated Oct 8, 2022

一款支持自定义的 Java 回显载荷生成工具|A customizable Java echo payload generation tool.

Java 456 43 Updated Jan 12, 2025

JavaWeb漏洞审计工具,构建方法调用链并模拟栈帧进行分析

Java 334 46 Updated Jun 3, 2023

复杂请求下的Shiro反序列化利用工具

Java 410 29 Updated Mar 12, 2024

Java内存马注入工具

Java 251 28 Updated Apr 8, 2023

一款针对Shiro550漏洞进行快速漏洞利用工具。 对 @SummerSec 大佬的项目https://github.com/SummerSec/ShiroAttack2 进行了一些改进。

Java 251 10 Updated May 29, 2023

CTF-Java-Gadget专注于收集CTF中Java赛题的反序列化片段

Java 273 15 Updated Dec 13, 2024

图形化Java反序列化利用工具,集成Ysoserial

Java 331 25 Updated May 8, 2024

个人学习Java安全的笔记

Java 126 12 Updated May 5, 2023

JNDI服务利用工具 RMI/LDAP,支持部分场景回显、内存shell,高版本JDK场景下利用等,fastjson rce命令执行,log4j rce命令执行 漏洞检测辅助工具

2,008 321 Updated May 21, 2024
Java 3 Updated Oct 27, 2021