Pinned Repositories
0day-security-software-vulnerability-analysis-technology
0day安全_软件漏洞分析技术
JAVA_Env-Poc
JByteMod-Beta
Java bytecode editor
Motan-rce
RedTeamer
红方人员作战执行手册
redtool
日常积累的一些红队工具及自己写的脚本,更偏向于一些diy的好用的工具,并不是一些比较常用的msf/awvs/xray这种
rogue-jndi
A malicious LDAP server for JNDI injection attacks
Struts2_Vuln
Struts2历史漏洞分析复现
Weblogic_Vuln
CVE-2015-4852、CVE-2016-0638、CVE-2016-3510、CVE-2019-2890漏洞POC
zhzhdoai.github.io
个人博客!!!
zhzhdoai's Repositories
zhzhdoai/Weblogic_Vuln
CVE-2015-4852、CVE-2016-0638、CVE-2016-3510、CVE-2019-2890漏洞POC
zhzhdoai/JAVA_Env-Poc
zhzhdoai/Motan-rce
zhzhdoai/rogue-jndi
A malicious LDAP server for JNDI injection attacks
zhzhdoai/ActiveMQ_putshell-CVE-2016-3088
ActiveMQ_putshell直接获取webshell
zhzhdoai/AndroidSecurityStudy
安卓应用安全学习
zhzhdoai/batch-java-decompile
This is a small tool which can be used to decompile jars in bulk. Sometimes maybe helpful:-)
zhzhdoai/Behinder
Behinder source code
zhzhdoai/cas4.x-execution-rce
exp for 4.1.x-4.1.6, 4.1.7-4.2.x, padding oracle attack
zhzhdoai/classpy
GUI tool for investigating Java class files
zhzhdoai/fafuscan
课程设计作业 Course design assignments
zhzhdoai/fastjson-bypass-autotype-1.2.68
fastjson bypass autotype 1.2.68 with Throwable and AutoCloseable.
zhzhdoai/FileMonitor
文件变化实时监控工具(代码审计/黑盒/白盒审计辅助工具)
zhzhdoai/footprint
个人笔记
zhzhdoai/frps-onekey
Frps 一键安装脚本&管理脚本 A tool to auto-compile & install frps on Linux
zhzhdoai/Java-Deserialization-Cheat-Sheet
The cheat sheet about Java Deserialization vulnerabilities
zhzhdoai/JavaDemo
专注于梳理Java知识点,解析开源项目!这里都是文章代码的项目示例,好好学哈!
zhzhdoai/javaseccode
zhzhdoai/log-agent
利用agent hock指定的class,在jar运行周期内,用于跟踪被执行的方法,辅助做一些事情,比如挖洞啊
zhzhdoai/OA-Seeyou
note
zhzhdoai/RemoteObjectInvocationHandler
bypass JEP290 RaspHook code
zhzhdoai/RMIDeserialize
RMI 反序列化环境 一步步
zhzhdoai/self_codeql_java
zhzhdoai/SerializationDumper
A tool to dump Java serialization streams in a more human readable form.
zhzhdoai/SomePoc
Some 2020 poc
zhzhdoai/Team-Ares
Repository for all TeamARES POC code and tools.
zhzhdoai/Tentacle
Tentacle is a POC vulnerability verification and exploit framework. It supports free extension of exploits and uses POC scripts. It supports calls to zoomeye, fofa, shodan and other APIs to perform bulk vulnerability verification for multiple targets.
zhzhdoai/WeblogicEnvironment
Weblogic环境搭建工具
zhzhdoai/xray-crack
xray社区高级版证书生成,仅供学习研究,正常使用请支持正版
zhzhdoai/ysoserial
A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.