Starred repositories
🔥「企业级低代码平台」前后端分离架构SpringBoot 2.x/3.x,SpringCloud,Ant Design&Vue3,Mybatis,Shiro,JWT。强大的代码生成器让前后端代码一键生成,无需写任何代码! 引领新的开发模式,引入AI模型能力 OnlineCoding->代码生成->手工MERGE,帮助Java项目解决70%重复工作,让开发更关注业务,既能快速提高效率,帮助公司…
A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.
HaE - Highlighter and Extractor, Empower ethical hacker for efficient operations.
Java安全相关的漏洞和技术demo,原生Java、Fastjson、Jackson、Hessian2、XML反序列化漏洞利用和Spring、Dubbo、Shiro、CAS、Tomcat、RMI、Nexus等框架\中间件\功能的exploits以及Java Security Manager绕过、Dubbo-Hessian2安全加固等等实践代码。
Java web common vulnerabilities and security code which is base on springboot and spring security
一款高性能 HTTP 代理隧道工具 | A high-performance http proxy tunneling tool
溯光 (TrackRay) 3 beta⚡渗透测试框架(资产扫描|指纹识别|暴力破解|网页爬虫|端口扫描|漏洞扫描|代码审计|AWVS|NMAP|Metasploit|SQLMap)
MDUT - Multiple Database Utilization Tools
domain_hunter的高级版本,SRC挖洞、HW打点之必备!自动化资产收集;快速Title获取;外部工具联动;等等
APIKit:Discovery, Scan and Audit APIs Toolkit All In One.
Shiro550/Shiro721 一键化利用工具,支持多种回显方式
Share Things Related to Java - Java安全漫谈笔记相关内容
A burp extension that add some useful function to Context Menu 添加一些右键菜单让burp用起来更顺畅
A simple FOFA client written in JavaFX. Made by WgpSec, Maintained by f1ashine.
captcha-killer的修改版,支持关键词识别base64编码的图片,添加免费ocr库,用于验证码爆破,适配新版Burpsuite
latest version of scanners for IIS short filename (8.3) disclosure vulnerability
Burp extension to evade TLS fingerprinting. Bypass WAF, spoof any browser.
Burpsuite - Route Vulnerable Scanning 递归式被动检测脆弱路径的burp插件
攻防演练过程中,我们通常会用浏览器访问一些资产,但很多未授权/敏感信息/越权隐匿在已访问接口过html、JS文件等,该插件能让我们发现未授权/敏感信息/越权/登陆接口等。
Burp插件,根据自定义来达到对数据包的处理(适用于加解密、爆破等),类似mitmproxy,不同点在于经过了burp中转,在自动加解密的基础上,不影响APP、网站加解密正常逻辑等。
This repository will serve as the "master" repo containing all trainings and tutorials done in preperation for OSWE in conjunction with the AWAE course. This repo will likely contain custom code by…