Skip to content
View hack-umbrella's full-sized avatar

Block or report hack-umbrella

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

存储桶遍历漏洞利用工具

Java 300 15 Updated Jul 25, 2024

MDUT-Extend(扩展版本)

695 32 Updated Dec 19, 2024

一款支持自定义的 Java 内存马生成工具|A customizable Java in-memory webshell generation tool.

Java 1,781 202 Updated Jan 12, 2025

当死去的记忆突然开始攻击我,我终于想起了我还写过一款十分十分垃圾的 rasp 靶场。

PLpgSQL 77 5 Updated Jul 21, 2022

Java安全相关的漏洞和技术demo,原生Java、Fastjson、Jackson、Hessian2、XML反序列化漏洞利用和Spring、Dubbo、Shiro、CAS、Tomcat、RMI、Nexus等框架\中间件\功能的exploits以及Java Security Manager绕过、Dubbo-Hessian2安全加固等等实践代码。

Java 2,625 496 Updated Mar 14, 2024

Windows安全基线核查加固助手

C# 465 63 Updated May 12, 2024

A helpful Java Deserialization exploit framework.

Java 1,196 150 Updated Jun 20, 2024

SafeLine is a self-hosted WAF(Web Application Firewall) / reverse proxy to protect your web apps from attacks and exploits.

Go 15,434 928 Updated Feb 14, 2025

Jar Analyzer - 一个JAR包分析工具,批量分析,SCA漏洞分析,方法调用关系搜索,字符串搜索,Spring组件分析,信息泄露检查,CFG程序分析,JVM栈帧分析,进阶表达式搜索,字节码指令级的动态调试分析,反编译JAR包一键导出,一键提取序列化数据恶意代码,一键分析BCEL字节码

Java 1,342 118 Updated Jan 25, 2025

利用任意文件下载漏洞循环下载反编译 Class 文件获得网站 Java 源代码

Python 699 93 Updated May 10, 2021

基于go编写的跨平台、稳定、隐秘的多级代理内网穿透工具

Go 1,030 145 Updated Apr 23, 2023

一款针对Vcenter的综合利用工具,包含目前最主流的CVE-2021-21972、CVE-2021-21985以及CVE-2021-22005、One Access的CVE-2022-22954、CVE-2022-22972/31656以及log4j,提供一键上传webshell,命令执行或者上传公钥使用SSH免密连接

Go 1,369 167 Updated Apr 25, 2024

一个利用Shodan搜索引擎查询Jetbrains系列产品激活服务器的网页端工具

Python 57 16 Updated Dec 1, 2022

Store the exps and attachments for my blog and articles.

Python 4 1 Updated Apr 13, 2023

🌴Linux、macOS、Windows Kernel privilege escalation vulnerability collection, with compilation environment, demo GIF map, vulnerability details, executable file (提权漏洞合集)

C 2,963 668 Updated Feb 15, 2023

General purpose JavaScript deobfuscator

TypeScript 854 118 Updated Jan 26, 2025

Next generation RedTeam heuristic intranet scanning | 下一代RedTeam启发式内网扫描

1,073 121 Updated Sep 16, 2023

HeapDump敏感信息提取工具

Java 1,383 136 Updated Dec 12, 2024

A simple FOFA client written in JavaFX. Made by WgpSec, Maintained by f1ashine.

Java 1,638 164 Updated Jun 11, 2024

A collection of simple demos of CORS

JavaScript 580 182 Updated Jun 19, 2024

Tools for developers to create truly open IoT products using standard JavaScript on low cost microcontrollers.

C 1,385 239 Updated Jan 30, 2025

ZKar is a Java serialization protocol analysis tool implement in Go.

Go 604 52 Updated Feb 15, 2025

An awesome reverse engine for xray poc. | 一个自动化根据 xray poc 生成对应靶站的工具

Go 410 50 Updated Mar 22, 2023

分布式资产安全扫描核心管理系统(弱口令扫描,漏洞扫描)

Python 603 119 Updated Dec 8, 2022

When MVC magic turns black

Java 290 27 Updated Sep 4, 2020

AntSword(蚁剑)全参数流量XOR和Base64加伪装WebShell

163 20 Updated Sep 28, 2021

A tool to analyze the network flow during attack/defence Capture the Flag competitions

JavaScript 604 84 Updated Dec 7, 2022

网络信息安全从业者面试指南

1,488 150 Updated Nov 1, 2023

一个cobaltstrike shellcode加载器,过国内主流杀软

C# 121 15 Updated May 21, 2021

This is a easy tool for gen VBA code, and bypass most antivirus

59 16 Updated Sep 30, 2021
Next