Skip to content
View yzkc's full-sized avatar

Sponsoring

@openclaw

Block or report yzkc

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
80 stars written in Java
Clear filter

Ghidra is a software reverse engineering (SRE) framework

Java 66,562 7,325 Updated Apr 2, 2026

Free universal database tool and SQL client

Java 49,388 4,097 Updated Apr 3, 2026

😱 从源码层面,剖析挖掘互联网行业主流技术的底层实现原理,为广大开发者 “提升技术深度” 提供便利。目前开放 Spring 全家桶,Mybatis、Netty、Dubbo 框架,及 Redis、Tomcat 中间件等

Java 23,136 4,254 Updated Jan 9, 2026

A simple app to use Xposed without root, unlock the bootloader or modify system image, etc.

Java 15,982 2,520 Updated Mar 8, 2024

Virtual Engine for Android(Support 14.0 in business version)

Java 10,954 3,020 Updated Mar 30, 2026

SpringBoot 相关漏洞学习资料,利用方法和技巧合集,黑盒安全评估 check list

Java 6,127 1,320 Updated Mar 10, 2021

HaE - Highlighter and Extractor, Empower ethical hacker for efficient operations.

Java 4,131 300 Updated Mar 31, 2026

JNDI注入测试工具(A tool which generates JNDI links can start several servers to exploit JNDI Injection vulnerability,like Jackson,Fastjson,etc)

Java 2,799 740 Updated Mar 22, 2023

Java安全相关的漏洞和技术demo,原生Java、Fastjson、Jackson、Hessian2、XML反序列化漏洞利用和Spring、Dubbo、Shiro、CAS、Tomcat、RMI、Nexus等框架\中间件\功能的exploits以及Java Security Manager绕过、Dubbo-Hessian2安全加固等等实践代码。

Java 2,697 496 Updated Mar 14, 2024

shiro反序列化漏洞综合利用,包含(回显执行命令/注入内存马)修复原版中NoCC的问题 https://github.com/j1anFen/shiro_attack

Java 2,440 283 Updated Mar 28, 2026

MDUT - Multiple Database Utilization Tools

Java 2,207 234 Updated Sep 22, 2023

一款支持自定义的 Java 内存马生成工具|A customizable Java in-memory webshell generation tool.

Java 2,176 234 Updated Aug 21, 2025

domain_hunter的高级版本,SRC挖洞、HW打点之必备!自动化资产收集;快速Title获取;外部工具联动;等等

Java 2,121 209 Updated Apr 1, 2026

Burp suite 分块传输辅助插件

Java 2,031 297 Updated Feb 23, 2022

Share Things Related to Java - Java安全漫谈笔记相关内容

Java 2,002 229 Updated Apr 9, 2025

Shiro550/Shiro721 一键化利用工具,支持多种回显方式

Java 1,958 298 Updated Jun 4, 2021

高危漏洞利用工具

Java 1,833 246 Updated Feb 12, 2025

一款基于BurpSuite的被动式shiro检测插件

Java 1,798 159 Updated Dec 14, 2022

Burp Bounty (Scan Check Builder in BApp Store) is a extension of Burp Suite that allows you, in a quick and simple way, to improve the active and passive scanner by means of personalized rules thro…

Java 1,792 341 Updated Apr 26, 2024

A simple FOFA client written in JavaFX. Made by WgpSec, Maintained by f1ashine.

Java 1,777 164 Updated Dec 26, 2025

TCP/UDP Non-HTTP Proxy Extension (NoPE) for Burp Suite.

Java 1,654 241 Updated May 25, 2024

服务端配置错误情况下用于伪造ip地址进行测试的Burp Suite插件

Java 1,649 234 Updated Sep 29, 2022

HackBar plugin for Burpsuite

Java 1,619 257 Updated Apr 15, 2021

WebSocket 内存马/Webshell,一种新型内存马/WebShell技术

Java 1,493 230 Updated Apr 10, 2023

OAExploit一款基于产品的一键扫描工具。

Java 1,482 197 Updated Sep 20, 2022

Burp被动扫描流量转发插件

Java 1,461 172 Updated Jun 17, 2024

CaA - Collector and Analyzer, Insight into information, exploring with intelligence in a thousand ways.

Java 1,449 83 Updated Mar 19, 2026

Collect JSP webshell of various implementation methods. 梳理和发现的JSP Webshell各种姿势

Java 1,406 330 Updated Jan 18, 2022

Fastjson vulnerability quickly exploits the framework(fastjson漏洞快速利用框架)

Java 1,393 176 Updated Dec 16, 2022

Burp插件,根据自定义来达到对数据包的处理(适用于加解密、爆破等),类似mitmproxy,不同点在于经过了burp中转,在自动加解密的基础上,不影响APP、网站加解密正常逻辑等。

Java 1,358 97 Updated Mar 20, 2026
Next