Skip to content
View tr0uble-mAker's full-sized avatar

Block or report tr0uble-mAker

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
21 stars written in Java
Clear filter

A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.

Java 8,835 1,854 Updated Dec 4, 2025

SpringBoot 相关漏洞学习资料,利用方法和技巧合集,黑盒安全评估 check list

Java 6,126 1,320 Updated Mar 10, 2021

一个漏洞 PoC 知识库。A knowledge base for vulnerability PoCs(Proof of Concept), with 1k+ vulnerabilities.

Java 4,906 1,010 Updated Mar 23, 2026

Decompiler from Java bytecode to Java, used in IntelliJ IDEA.

Java 4,239 727 Updated Apr 10, 2026

Java web common vulnerabilities and security code which is base on springboot and spring security

Java 2,660 763 Updated Dec 2, 2024

a rep for documenting my study, may be from 0 to 0.1

Java 2,264 339 Updated Mar 25, 2026

一款支持自定义的 Java 内存马生成工具|A customizable Java in-memory webshell generation tool.

Java 2,179 234 Updated Aug 21, 2025

Jar Analyzer - 一个 JAR 包 GUI 分析工具,方法调用关系搜索,方法调用链 DFS 算法分析,模拟 JVM 的污点分析验证 DFS 结果,字符串搜索,Java Web 组件入口分析,CFG 程序分析,JVM 栈帧分析,自定义表达式搜索,紧跟 AI 技术发展,支持 MCP 调用,支持 n8n 工作流

Java 2,048 194 Updated Apr 11, 2026

Burp extension to evade TLS fingerprinting. Bypass WAF, spoof any browser.

Java 1,786 116 Updated Apr 7, 2026

攻防演练过程中,我们通常会用浏览器访问一些资产,但很多未授权/敏感信息/越权隐匿在已访问接口过html、JS文件等,该插件能让我们发现未授权/敏感信息/越权/登陆接口等。

Java 1,384 75 Updated Oct 3, 2024

BurpSuite插件集成Ehole指纹库并进行常见OA弱口令爆破插件

Java 745 38 Updated Sep 5, 2024

SpringScan 漏洞检测 Burp插件

Java 607 49 Updated Nov 14, 2023

《深入JDBC安全:特殊URL构造与不出网反序列化利用技术揭秘》对应研究总结项目 "Deep Dive into JDBC Security: Special URL Construction and Non-Networked Deserialization Exploitation Techniques Revealed" - Research Summary Project

Java 575 44 Updated Feb 7, 2026

一款用于JNDI注入利用的工具,大量参考/引用了Rogue JNDI项目的代码,支持直接植入内存shell,并集成了常见的bypass 高版本JDK的方式,适用于与自动化工具配合使用。

Java 369 29 Updated Sep 6, 2022

JavaPassDump

Java 275 14 Updated Jan 7, 2022

A memory shell for ruoyi

Java 267 37 Updated Apr 28, 2023

Some ReadObject Sink With JDBC

Java 245 18 Updated May 8, 2024

Java bytecode line number restoration tool

Java 139 11 Updated Aug 31, 2025

Apache-Log4j漏洞复现笔记

Java 116 65 Updated Feb 17, 2022