Skip to content
View timwhitez's full-sized avatar
💭
💭

Block or report timwhitez

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
92 stars written in Java
Clear filter

Ghidra is a software reverse engineering (SRE) framework

Java 61,167 6,793 Updated Oct 8, 2025

A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.

Java 8,542 1,837 Updated Mar 31, 2024

Tsunami is a general purpose network security scanner with an extensible plugin system for detecting high severity vulnerabilities with high confidence.

Java 8,468 920 Updated Oct 2, 2025

SpringBoot 相关漏洞学习资料,利用方法和技巧合集,黑盒安全评估 check list

Java 6,037 1,323 Updated Mar 10, 2021

Angry IP Scanner - fast and friendly network scanner

Java 4,619 772 Updated Aug 19, 2025

HaE - Highlighter and Extractor, Empower ethical hacker for efficient operations.

Java 3,834 278 Updated Sep 22, 2025

JNDI注入测试工具(A tool which generates JNDI links can start several servers to exploit JNDI Injection vulnerability,like Jackson,Fastjson,etc)

Java 2,756 737 Updated Mar 22, 2023

Java安全相关的漏洞和技术demo,原生Java、Fastjson、Jackson、Hessian2、XML反序列化漏洞利用和Spring、Dubbo、Shiro、CAS、Tomcat、RMI、Nexus等框架\中间件\功能的exploits以及Java Security Manager绕过、Dubbo-Hessian2安全加固等等实践代码。

Java 2,674 498 Updated Mar 14, 2024

一款高性能 HTTP 代理隧道工具 | A high-performance http proxy tunneling tool

Java 2,518 234 Updated Apr 14, 2025

The SpotBugs plugin for security audits of Java web applications and Android applications. (Also work with Kotlin, Groovy and Scala projects)

Java 2,380 484 Updated Jun 17, 2025

shiro反序列化漏洞综合利用,包含(回显执行命令/注入内存马)修复原版中NoCC的问题 https://github.com/j1anFen/shiro_attack

Java 2,318 278 Updated Apr 10, 2024

APIKit:Discovery, Scan and Audit APIs Toolkit All In One.

Java 2,180 177 Updated Apr 2, 2024

MDUT - Multiple Database Utilization Tools

Java 2,169 237 Updated Sep 22, 2023

溯光 (TrackRay) 3 beta⚡渗透测试框架(资产扫描|指纹识别|暴力破解|网页爬虫|端口扫描|漏洞扫描|代码审计|AWVS|NMAP|Metasploit|SQLMap)

Java 2,076 374 Updated Dec 16, 2023

Shiro550/Shiro721 一键化利用工具,支持多种回显方式

Java 1,940 298 Updated Jun 4, 2021

在我很多项目中用到的CV算法推理框架应用。

Java 1,935 401 Updated Nov 9, 2021

Share Things Related to Java - Java安全漫谈笔记相关内容

Java 1,934 223 Updated Apr 9, 2025

项目是根据LandGrey/SpringBootVulExploit清单编写,目的hvv期间快速利用漏洞、降低漏洞利用门槛。

Java 1,887 317 Updated Jan 15, 2024

服务端配置错误情况下用于伪造ip地址进行测试的Burp Suite插件

Java 1,603 233 Updated Sep 29, 2022

BurpCrypto is a collection of burpsuite encryption plug-ins, support AES/RSA/DES/ExecJs(execute JS encryption code in burpsuite). 支持多种加密算法或直接执行JS代码的用于爆破前端加密的BurpSuite插件

Java 1,589 173 Updated Aug 4, 2023

HeapDump敏感信息提取工具

Java 1,573 145 Updated Apr 9, 2025

Thinkphp(GUI)漏洞利用工具,支持各版本TP漏洞检测,命令执行,getshell。

Java 1,525 183 Updated Jun 1, 2022

OAExploit一款基于产品的一键扫描工具。

Java 1,480 201 Updated Sep 20, 2022

WebSocket 内存马/Webshell,一种新型内存马/WebShell技术

Java 1,475 231 Updated Apr 10, 2023

Collect JSP webshell of various implementation methods. 梳理和发现的JSP Webshell各种姿势

Java 1,399 328 Updated Jan 18, 2022

一款基于BurpSuite的被动式FastJson检测插件

Java 1,223 134 Updated Oct 1, 2022

Alibaba-Nacos-Unauthorized/ApacheDruid-RCE_CVE-2021-25646/MS-Exchange-SSRF-CVE-2021-26885/Oracle-WebLogic-CVE-2021-2109_RCE/RG-CNVD-2021-14536/RJ-SSL-VPN-UltraVires/Redis-Unauthorized-RCE/TDOA-V11.…

Java 1,080 318 Updated May 11, 2023

分享几个直接可用的内存马,记录一下学习过程中看过的文章

Java 972 154 Updated Mar 23, 2022

🐱‍💻 ✂️ 🤬 CVE-2021-44228 - LOG4J Java exploit - WAF bypass tricks

Java 955 138 Updated Jan 15, 2022

通过jsp脚本扫描java web Filter/Servlet型内存马

Java 954 131 Updated Mar 9, 2023
Next