su18's Stars
chaitin/SafeLine
SafeLine is a self-hosted WAF(Web Application Firewall) / reverse proxy to protect your web apps from attacks and exploits.
jassics/security-study-plan
Complete Practical Study Plan to become a successful cybersecurity engineer based on roles like Pentest, AppSec, Cloud Security, DevSecOps and so on...
zxh0/jvm.go
A toy JVM written in Go
neargle/my-re0-k8s-security
:atom: [WIP] 整理过去的分享,从零开始的Kubernetes攻防 🧐
ashemery/exploitation-course
Offensive Software Exploitation Course
zema1/suo5
一款高性能 HTTP 代理隧道工具 | A high-performance http proxy tunneling tool
pen4uin/java-memshell-generator
一款支持自定义的 Java 内存马生成工具|A customizable Java in-memory webshell generation tool.
zxh0/jvmgo-book
《自己动手写Java虚拟机》随书源代码
zema1/watchvuln
一个高价值漏洞采集与推送服务 | collect valueable vulnerability and push it
youthlql/JavaYouth
主要是Java技术栈的文章
obiscr/ChatGPT
This project is a plugin that supports ChatGPT running on JetBrains series IDE.
f0ng/autoDecoder
Burp插件,根据自定义来达到对数据包的处理(适用于加解密、爆破等),类似mitmproxy,不同点在于经过了burp中转,在自动加解密的基础上,不影响APP、网站加解密正常逻辑等。
chaitin/blazehttp
BlazeHTTP 是一款简单易用的 WAF 防护效果测试工具。BlazeHTTP stands as a user-friendly WAF protection efficacy evaluation tool.
rebeyond/JNDInjector
一个高度可定制化的JNDI和Java反序列化利用工具
burpheart/koko-moni
一个基于网络空间搜索引擎的攻击面管理平台,可定时进行资产信息爬取,及时发现新增资产,本项目聚合了 Fofa、Hunter、Quake、Zoomeye 和 Threatbook 的数据源,并对获取到的数据进行去重与清洗
qtc-de/beanshooter
JMX enumeration and attacking tool.
Esonhugh/sshd_backdoor
/root/.ssh/authorized_keys evil file watchdog with ebpf tracepoint hook.
Ppsoft1991/CodeReviewTools
通过正则搜索、批量反编译特定Jar包中的class名称
AdoptOpenJDK/jdk9-jigsaw
Examples and exercises based on some of the features of jigsaw in JDK9/Jigsaw (Early Access builds)
soot-oss/heros
IFDS/IDE Solver for Soot and other frameworks
quentinhardy/jndiat
JNDI Attacking Tool
4ra1n/java-gate
Java JNI HellsGate/HalosGate/TartarusGate/RecycledGate/SSN Syscall/Many Shellcode Loaders
woodpecker-appstore/jexpr-encoder-utils
Java表达式语句生成器
horizon3ai/vRealizeLogInsightRCE
POC for RCE using vulnerabilities described in VMSA-2023-0001
BeichenDream/JDR
flowerwind/AutoGenerateXalanPayload
cve-2022-34169 延伸出的Jdk Xalan的payload自动生成工具,可根据不同的Jdk生成出其所对应的xslt文件
r00tuser111/SerializationDumper-Shiro
基于SerializationDumper的Shiro Cookie序列化数据解密小工具
ODDFuzz/ODDFuzz
S&P2023 Paper
waderwu/nativeRasp
nativeRasp that can hook native methods
johnngugi/CORBA-Example
A simple CORBA implementation using Java