Skip to content
View baozongwi's full-sized avatar
🥰
Out sick
🥰
Out sick

Block or report baozongwi

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

一个用 Go 写的轻量聊天室:基于 TCP 长连接、自定义帧协议(4-byte length + payload)、AES-GCM 端到端加密,支持命令行交互、在线用户列表、改名、以及文件上传/下载。

Go 4 Updated Dec 31, 2025

A `.git` folder disclosure exploit

Python 3,488 814 Updated Feb 1, 2023

BurpLoaderKeygen backup

49 29 Updated Aug 21, 2023

基于Django 的漏洞管理预警系统

CSS 30 3 Updated Feb 13, 2025

a rep for documenting my study, may be from 0 to 0.1

Java 2,230 338 Updated Nov 10, 2025

Jar Analyzer - 一个 JAR 包 GUI 分析工具,方法调用关系搜索,方法调用链 DFS 算法分析,模拟 JVM 的污点分析验证 DFS 结果,字符串搜索,Java Web 组件入口分析,CFG 程序分析,JVM 栈帧分析,自定义表达式搜索,支持 MCP 调用,文档:https://docs.qq.com/doc/DV3pKbG9GS0pJS0tk

Java 1,850 170 Updated Nov 22, 2025

用于快速启动tabby 分析漏洞或者gadget的环境

Shell 94 4 Updated Jul 14, 2025

A vul-finder for loading CPG and automated finding vul-call-chains

Java 70 4 Updated Jul 22, 2025

A neo4j procedure for tabby

Java 136 8 Updated May 17, 2025

Graphs for Everyone

Java 15,645 2,548 Updated Dec 19, 2025

A IntelliJ Plugin for Tabby to Find Vulnerabilities Easily

Java 39 2 Updated Nov 12, 2024

DuckDB extension allowing shell commands to be used for input and output.

C++ 88 4 Updated Dec 4, 2025

Attack surface mapping

1,497 155 Updated Feb 29, 2024

JNDI-Exploitation-Kit(A modified version of the great JNDI-Injection-Exploit created by @welk1n. This tool can be used to start an HTTP Server, RMI Server and LDAP Server to exploit java web apps v…

Java 934 170 Updated Sep 2, 2025

一款支持自定义的 Java 回显载荷生成工具|A customizable Java echo payload generation tool.

Java 456 43 Updated Jan 12, 2025

拿来即用的Tomcat7/8/9/10版本Listener/Filter/Servlet内存马,支持注入CMD内存马和冰蝎内存马

Java 513 76 Updated Aug 31, 2022

Memshell-攻防内存马研究

Java 923 111 Updated Apr 13, 2025

JavaSecLab is a comprehensive Java vulnerability platform|​ JavaSecLab是一款综合型Java漏洞平台,提供相关漏洞缺陷代码、修复代码、漏洞场景、审计SINK点、安全编码规范,覆盖多种漏洞场景,友好用户交互UI……

JavaScript 799 67 Updated Mar 23, 2025

Nuclei POC,每2小时更新 | 自动整合全网Nuclei的漏洞POC,实时同步更新最新POC,保存已被删除的POC。通过批量克隆Github项目,获取Nuclei POC,并将POC按类别分类存放,使用Github Action实现。已有41w+POC,其中3.5w+高质量POC

Rust 1,840 523 Updated Jan 2, 2026

A lightweight tool for integrating and testing SheerID verification workflows. It simplifies API requests, handles responses, and supports eligibility checks for programs like student.

Python 1,793 242 Updated Jan 2, 2026

MySQL fake server for read files of connected clients

Python 606 150 Updated Jul 23, 2017

A rouge mysql server supports reading files from most mysql libraries of multiple programming languages.

Go 752 81 Updated Dec 2, 2022

A powerful JNDI injection exploitation framework that supports RMI, LDAP and LDAPS protocols, including various bypass methods for high-version JDK restrictions

Java 553 38 Updated Dec 9, 2025

An OOB interaction gathering server and client library

Go 4,104 435 Updated Dec 29, 2025
Python 107 36 Updated May 4, 2020

⬆️ ☠️ 🔥 Automatic Linux privesc via exploitation of low-hanging fruit e.g. gtfobins, pwnkit, dirty pipe, +w docker.sock

Go 7,085 660 Updated Mar 12, 2024
Next