Skip to content
View octa's full-sized avatar

Block or report octa

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

Content-Type Research

545 56 Updated Feb 8, 2024

CVE-2017-12149 jboss反序列化 可回显

Java 206 58 Updated Mar 13, 2019

Apache Shiro 反序列化漏洞检测与利用工具

Python 513 124 Updated Jan 29, 2020

Supplemental templates for securing the cloud.

Python 35 30 Updated Nov 19, 2024

Reverse proxies cheatsheet

Python 1,787 207 Updated Nov 4, 2023

Grafana Unauthorized arbitrary file reading vulnerability

Go 354 89 Updated Feb 14, 2023

開源的正體中文 Web Hacking 學習資源 - 程式安全 2021 Fall

PHP 515 50 Updated Mar 21, 2022

There is no pre-auth RCE in Jenkins since May 2017, but this is the one!

Python 601 132 Updated May 17, 2019

Collection of CTF Web challenges I made

PHP 2,696 476 Updated Nov 8, 2023

Collections of Orange Tsai's public presentation slides.

717 77 Updated Aug 9, 2024

Our main goal is to share tips from some well-known bughunters. Using recon methodology, we are able to find subdomains, apis, and tokens that are already exploitable, so we can report them. We wis…

Go 4,276 825 Updated Aug 3, 2024

Tool for discovering the origin host behind a reverse proxy. Useful for bypassing cloud WAFs!

Go 852 109 Updated Jan 12, 2024

A walkthrough of security controls for a serverless architecture via a demo application

HCL 11 Updated May 11, 2022

💀 Generate a bunch of malicious pdf files with phone-home functionality. Can be used with Burp Collaborator or Interact.sh

Python 2,896 388 Updated Oct 20, 2024

域控安全one for all

726 110 Updated Sep 9, 2024

Linux EDR written in Golang and based on eBPF.

Go 232 44 Updated May 24, 2022

Redis 漏洞利用工具

Go 840 113 Updated Dec 7, 2024

收集的文章 https://mrwq.github.io/tools/paper/

Python 1,825 414 Updated Nov 20, 2024

Proof of concept code for Datadog Security Labs referenced exploits.

C 419 58 Updated Oct 13, 2023

ffffffff0x 团队维护的安全知识框架,内容包括不仅限于 web安全、工控安全、取证、应急、蓝队设施部署、后渗透、Linux安全、各类靶机writup

C++ 5,383 1,221 Updated Jun 6, 2024

🛠 Knowledge about the topic of x86 assembly & disassembly 🛠

Assembly 133 30 Updated Mar 1, 2024

JNDI-Exploitation-Kit(A modified version of the great JNDI-Injection-Exploit created by @welk1n. This tool can be used to start an HTTP Server, RMI Server and LDAP Server to exploit java web apps v…

Java 903 164 Updated Jan 11, 2022

JNDI注入测试工具(A tool which generates JNDI links can start several servers to exploit JNDI Injection vulnerability,like Jackson,Fastjson,etc)

Java 2,620 726 Updated Mar 22, 2023

😎 Awesome lists about all kinds of interesting topics

338,640 28,094 Updated Dec 12, 2024

A curated list of resources for learning about application security

PHP 6,383 741 Updated Jul 8, 2024

Java反序列化漏洞利用工具V1.0 Java反序列化相关漏洞的检查工具,采用JDK 1.8+NetBeans8.2开发,软件运行必须安装JDK 1.8或者以上版本。 支持:weblogic xml反序列化漏洞 CVE-2017-10271/CNVD-C-2019-48814/CVE-2019-2725检查。

Java 460 115 Updated Oct 1, 2020

XStream相关漏洞POC及分析复现环境

Java 4 3 Updated Dec 15, 2020

Payload Arsenal for Pentration Tester and Bug Bounty Hunters

PHP 895 187 Updated May 6, 2023

一些关于渗透测试的Tips

592 86 Updated Dec 19, 2022
Next