- All languages
- ASP
- ActionScript
- Arduino
- Assembly
- AutoIt
- Batchfile
- BlitzBasic
- Boo
- C
- C#
- C++
- CSS
- CodeQL
- Dart
- Dockerfile
- Go
- HCL
- HTML
- Haskell
- Java
- JavaScript
- Jupyter Notebook
- Kotlin
- Less
- Lua
- Makefile
- Mask
- Objective-C
- PHP
- Pascal
- Perl
- PowerShell
- Python
- Rich Text Format
- Ruby
- Rust
- Scala
- Shell
- Smali
- Smarty
- Standard ML
- Swift
- TeX
- TypeScript
- VBA
- VBScript
- Vim Script
- Visual Basic
- Vue
- XSLT
- YARA
- Zeek
Starred repositories
An Android app that lets you use your access control card cloning devices in the field.
Collection of bypass gadgets to extend and wrap ysoserial payloads
一款用于JNDI注入利用的工具,大量参考/引用了Rogue JNDI项目的代码,支持直接植入内存shell,并集成了常见的bypass 高版本JDK的方式,适用于与自动化工具配合使用。
A malicious LDAP server for JNDI injection attacks
rmi、jndi、ldap、jrmp、jmx、jms一些demo测试
😈 Jenkins RCE PoC. From unauthenticated user to remote code execution, it's a hacker's dream!
Mallet is an intercepting proxy for arbitrary protocols
psychoPATH - an advanced path traversal tool. Features: evasive techniques, dynamic web root list generation, output encoding, site map-searching payload generator, LFI mode, nix & windows support,…
Burp Extender plugin that generates a sitemap of a website using Wayback Machine
Burp extension to perform Java Deserialization Attacks
QAQ Just study unserialize vulnerabilities in Java :)
Mogwai Java Management Extensions (JMX) Exploitation Toolkit
An auditing tool for Wi-Fi or wired Ethernet connections
Burp and ZAP plugin to analyse Content-Security-Policy headers or generate template CSP configuration from crawling a Website