Skip to content
View Niiiiko's full-sized avatar

Block or report Niiiiko

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

XxlJob<=2.1.2配置不当情况下反序列化RCE

Java 85 6 Updated Nov 2, 2020

burp插件,Oss漏洞被动扫描

Java 11 Updated Jan 1, 2025

Nacos 综合利用工具

309 17 Updated Dec 21, 2024

🚀 在线简历生成器

TypeScript 2,667 637 Updated Aug 30, 2023

Web 版 Java Payload 生成与利用工具,提供 Java 反序列化、Hessian 1/2 反序列化等Payload生成,以及 JNDI、Fake Mysql、JRMPListener 等利用|The web version of Java Payload generation and utilization tool provides Payload generation su…

Dockerfile 983 72 Updated Jan 4, 2025

轻量级的无害化钓鱼~

Go 229 28 Updated Nov 28, 2024

netspy是一款快速探测内网可达网段工具(深信服深蓝实验室天威战队强力驱动)

Go 2,039 213 Updated Jul 25, 2023

Asset discovery and identification tools 快速识别 Web 指纹信息,定位资产类型。辅助红队快速定位目标资产信息,辅助蓝队发现疑似脆弱点

Go 2,061 267 Updated Jan 29, 2024

"chanzi" is a simple and user-friendly JAVA SAST tool that utilizes taint analysis technology, includes built-in common vulnerability rules, supports decompile, custom rule, and is compatible with …

337 12 Updated Jan 5, 2025

EHole(棱洞)魔改。可对路径进行指纹识别;支持识别出来的重点资产进行漏洞检测(支持从hunter和fofa中提取资产)支持对ftp服务识别及爆破

Go 827 51 Updated Mar 6, 2024

开发和安全和运营:DevSecOps-Software development (Dev) and Security (Sec) and IT operations (Ops).

23 4 Updated Apr 13, 2024

《深入理解CodeQL》Finding vulnerabilities with CodeQL.

1,546 171 Updated Nov 21, 2023

鹏 RocB - Java代码审计IDEA插件 SAST

147 17 Updated Sep 16, 2021

《深入理解SAST静态应用安全测试》Static Application Security Testing.

329 29 Updated Apr 13, 2024

SpringBoot集成JWT实现token验证

Java 5 1 Updated Jun 17, 2022

Find, verify, and analyze leaked credentials

Go 17,827 1,749 Updated Jan 20, 2025

IDEA代码审计辅助插件(深信服深蓝实验室天威战队强力驱动)

Java 431 38 Updated Nov 26, 2024

此项目的POC来源为2024年以来各大威胁情报的高危漏洞复现,POC已通过nuclei或xray武器化,本项目旨在为网络安全爱好者们提供一点参考资料,可供个人研究使用,共勉

Python 270 44 Updated Aug 14, 2024

ysoserial修改版,着重修改ysoserial.payloads.util.Gadgets.createTemplatesImpl使其可以通过引入自定义class的形式来执行命令、内存马、反序列化回显。

Java 653 106 Updated Jan 11, 2024

DecryptTools-综合解密

1,076 113 Updated Sep 30, 2024

漏洞文库 wiki.wy876.cn

HTML 499 102 Updated Dec 31, 2024

FastJson全版本Docker漏洞环境(涵盖1.2.47/1.2.68/1.2.80等版本),主要包括JNDI注入及高版本绕过、waf绕过、文件读写、原生反序列化、利用链探测绕过、不出网利用等。从黑盒的角度覆盖FastJson深入利用

Python 927 112 Updated Jul 12, 2024

ysoserial 图形化,探测 Gadget,探测 Class,命令执行,注入哥斯拉冰蝎内存马,加载字节码等

324 13 Updated Nov 27, 2024

Cyber Security ALL-IN-ONE Platform

TypeScript 6,130 716 Updated Jan 21, 2025

javaeasyscanner - 富婆系列,代码审计辅助工具,致力于解放大脑,方便双手

Java 269 11 Updated Jun 18, 2024

Common Exploitation Techniques for Java RCE Vulnerabilities in Real-World Scenarios | 实战场景较通用的 Java Rce 相关漏洞的利用方式

Java 479 54 Updated Sep 29, 2024

收集整理漏洞EXP/POC,大部分漏洞来源网络,目前收集整理了1400多个poc/exp,长期更新。

4,738 1,035 Updated Jan 7, 2025

Xtools 是一款 Sublime Text 插件,同时是一款简单的资产处理|命令行调用工具。

Python 202 13 Updated Nov 10, 2024

WeChatOpenDevTool 微信小程序强制开启开发者工具

Python 2,521 656 Updated Sep 15, 2024

渗透测试常规操作记录

3,796 947 Updated May 22, 2023
Next