Skip to content
View yhy0's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report yhy0

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse

Starred repositories

61 stars written in Java
Clear filter

Ghidra is a software reverse engineering (SRE) framework

Java 66,733 7,348 Updated Apr 9, 2026

A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.

Java 8,837 1,854 Updated Dec 4, 2025

MCP Server for Ghidra

Java 8,268 779 Updated Jun 23, 2025

The modern Java bytecode editor

Java 7,099 518 Updated Apr 1, 2026

AdSkip — an Android assistant for automatically skipping app launch ads

Java 5,298 502 Updated Mar 20, 2026

一个漏洞 PoC 知识库。A knowledge base for vulnerability PoCs(Proof of Concept), with 1k+ vulnerabilities.

Java 4,901 1,009 Updated Mar 23, 2026

JNDI注入测试工具(A tool which generates JNDI links can start several servers to exploit JNDI Injection vulnerability,like Jackson,Fastjson,etc)

Java 2,799 741 Updated Mar 22, 2023

shiro反序列化漏洞综合利用,包含(回显执行命令/注入内存马)修复原版中NoCC的问题 https://github.com/j1anFen/shiro_attack

Java 2,448 284 Updated Mar 28, 2026

APIKit:Discovery, Scan and Audit APIs Toolkit All In One.

Java 2,260 181 Updated Apr 2, 2024

一款支持自定义的 Java 内存马生成工具|A customizable Java in-memory webshell generation tool.

Java 2,179 234 Updated Aug 21, 2025

domain_hunter的高级版本,SRC挖洞、HW打点之必备!自动化资产收集;快速Title获取;外部工具联动;等等

Java 2,122 209 Updated Apr 9, 2026

Jar Analyzer - 一个 JAR 包 GUI 分析工具,方法调用关系搜索,方法调用链 DFS 算法分析,模拟 JVM 的污点分析验证 DFS 结果,字符串搜索,Java Web 组件入口分析,CFG 程序分析,JVM 栈帧分析,自定义表达式搜索,紧跟 AI 技术发展,支持 MCP 调用,支持 n8n 工作流

Java 2,043 194 Updated Apr 3, 2026

项目是根据LandGrey/SpringBootVulExploit清单编写,目的hvv期间快速利用漏洞、降低漏洞利用门槛。

Java 1,903 314 Updated Jan 15, 2024

captcha-killer的修改版,支持关键词识别base64编码的图片,添加免费ocr库,用于验证码爆破,适配新版Burpsuite

Java 1,893 177 Updated Aug 26, 2025

The new bridge between Burp Suite and Frida!

Java 1,865 227 Updated Oct 30, 2025

一款基于BurpSuite的被动式shiro检测插件

Java 1,799 159 Updated Dec 14, 2022

Burp extension to evade TLS fingerprinting. Bypass WAF, spoof any browser.

Java 1,787 116 Updated Apr 7, 2026

JNDIExploit or a ysoserial.

Java 1,749 190 Updated Mar 30, 2026

A CAT called tabby ( Code Analysis Tool )

Java 1,642 181 Updated Jan 17, 2026

WebSocket 内存马/Webshell,一种新型内存马/WebShell技术

Java 1,492 230 Updated Apr 10, 2023

Burp被动扫描流量转发插件

Java 1,461 172 Updated Jun 17, 2024

Ghidra MCP Server — 194 MCP tools for AI-powered reverse engineering. GUI plugin + headless server, lazy tool loading, convention enforcement, batch operations, Ghidra Server integration, and Docke…

Java 1,428 90 Updated Apr 9, 2026

Collect JSP webshell of various implementation methods. 梳理和发现的JSP Webshell各种姿势

Java 1,406 329 Updated Jan 18, 2022

一款专注于 Java 主流 Web 中间件的内存马快速生成工具,致力于简化安全研究人员和红队成员的工作流程,提升攻防效率

Java 1,403 143 Updated Apr 9, 2026

Burp插件,根据自定义来达到对数据包的处理(适用于加解密、爆破等),类似mitmproxy,不同点在于经过了burp中转,在自动加解密的基础上,不影响APP、网站加解密正常逻辑等。

Java 1,363 97 Updated Mar 20, 2026

xia SQL (瞎注) burp 插件 ,在每个参数后面填加一个单引号,两个单引号,一个简单的判断注入小插件。

Java 1,250 85 Updated May 18, 2023

A helpful Java Deserialization exploit framework.

Java 1,244 149 Updated Feb 17, 2025

A malicious LDAP server for JNDI injection attacks

Java 1,078 228 Updated Sep 28, 2023

Java RCE 回显测试代码

Java 1,017 174 Updated Oct 15, 2020

一个简单的Fastjson反序列化检测burp插件

Java 973 75 Updated Jun 18, 2021
Next