chen1sheng's Stars
toeverything/AFFiNE
There can be more than Notion and Miro. AFFiNE(pronounced [ə‘fain]) is a next-gen knowledge base that brings planning, sorting and creating all together. Privacy first, open-source, customizable and ready to use.
AloneMonkey/MonkeyDev
CaptainHook Tweak、Logos Tweak and Command-line Tool、Patch iOS Apps, Without Jailbreak.
rev1si0n/lamda
⚡️ Android reverse engineering & automation framework | 史上最强安卓抓包/逆向/HOOK & 云手机/远程桌面/自动化取证框架,你的工作从未如此简单快捷。
AloneMonkey/frida-ios-dump
pull decrypted ipa from jailbreak device
gdbinit/MachOView
MachOView fork
vvmdx/Sec-Interview-4-2023
一个2023届毕业生在毕业前持续更新、收集的安全岗面试题及面试经验分享~
White-hua/Apt_t00ls
高危漏洞利用工具
JSREI/ast-hook-for-js-RE
浏览器内存漫游解决方案(探索中...)
ASTTeam/CodeQL
《深入理解CodeQL》Finding vulnerabilities with CodeQL.
xiecat/goblin
一款适用于红蓝对抗中的仿真钓鱼系统
jxhczhl/JsRpc
远程调用(rpc)浏览器方法,免去抠代码补环境
Schira4396/VcenterKiller
一款针对Vcenter的综合利用工具,包含目前最主流的CVE-2021-21972、CVE-2021-21985以及CVE-2021-22005、One Access的CVE-2022-22954、CVE-2022-22972/31656以及log4j,提供一键上传webshell,命令执行或者上传公钥使用SSH免密连接
wyzxxz/heapdump_tool
heapdump敏感信息查询工具,例如查找 spring heapdump中的密码明文,AK,SK等
sleeyax/burp-awesome-tls
Burp extension to evade TLS fingerprinting. Bypass WAF, spoof any browser.
t3l3machus/toxssin
An XSS exploitation command-line interface and payload generator.
SexyBeast233/SecDictionary
实战沉淀字典
f0ng/autoDecoder
Burp插件,根据自定义来达到对数据包的处理(适用于加解密、爆破等),类似mitmproxy,不同点在于经过了burp中转,在自动加解密的基础上,不影响APP、网站加解密正常逻辑等。
luzhisheng/js_reverse
主要用来收集/学习爬虫相关技术如:js逆向、app逆向、抓包、验证码、加密技术、自动化技术、机器学习。
safe6Sec/CodeqlNote
Codeql学习笔记
W01fh4cker/LearnJavaMemshellFromZero
【三万字原创】完全零基础从0到1掌握Java内存马,公众号:追梦信安
4ch12dy/xia0LLDB
LLDB python scripts for iOS arm64 reversing by xia0
ning1022/SQLInjectionWiki
一个专注于聚合和记录各种SQL注入方法的wiki
Bl0omZ/JNDIEXP
JNDI在java高版本的利用工具,FUZZ利用链
ben-sb/obfuscator-io-deobfuscator
A deobfuscator for scripts obfuscated by Obfuscator.io
Lakr233/Iridium
An iOS app decrypter, full static using fouldecrypt.
alipay/ant-application-security-testing-benchmark
xAST评价体系,让安全工具不再“黑盒”. The xAST evaluation benchmark makes security tools no longer a "black box".
uselibrary/KeepMyGoogleVoice
Send SMS regularly through Python to keep Google Voice active
satan1a/awesome-ios-security-cn
iOS安全资料整理(中文)
TheKingOfDuck/jsproxy
一个利用浏览器当代理的demo项目,让所有访问者的浏览器成为自己的代理池,所到之处皆为代理节点.
XiaoCC/ParallelsDesktopCrack