Skip to content
View christarcher's full-sized avatar

Block or report christarcher

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse

Starred repositories

Showing results

ysoserial修改版,着重修改ysoserial.payloads.util.Gadgets.createTemplatesImpl使其可以通过引入自定义class的形式来执行命令、内存马、反序列化回显。

Java 726 118 Updated Jan 11, 2024

A powerful JNDI injection exploitation framework that supports RMI, LDAP and LDAPS protocols, including various bypass methods for high-version JDK restrictions

Java 506 34 Updated Oct 9, 2025

Exploit for CVE-2025-11001 or CVE-2025-11002

Python 53 4 Updated Oct 17, 2025

Redis 漏洞利用工具

Go 925 119 Updated Jan 26, 2025

JavaGadgetGenerator 工具,支持 ysoserial,Hessian,字节码,Expr/SSTI,Shiro,JDBC 等 Gadget 生成,封装,混淆,出网延迟探测,内存马注入等...

480 26 Updated Sep 23, 2025

针对SpringBoot的开源渗透框架,以及Spring相关高危漏洞利用工具

Python 2,093 170 Updated Oct 16, 2025

一款专注于 Java 主流 Web 中间件的内存马快速生成工具,致力于简化安全研究人员和红队成员的工作流程,提升攻防效率

Java 1,129 117 Updated Oct 13, 2025

图形化Java反序列化利用工具,集成Ysoserial

Java 313 24 Updated May 8, 2024

专为CTF设计的AI Agent,可自动解CTF题,也能与用户协作交互解题~

Python 38 8 Updated Oct 9, 2025

《深入JDBC安全:特殊URL构造与不出网反序列化利用技术揭秘》对应研究总结项目 "Deep Dive into JDBC Security: Special URL Construction and Non-Networked Deserialization Exploitation Techniques Revealed" - Research Summary Project

Java 501 36 Updated Oct 9, 2025

全网首发!!!上万道网安面试题总结(涵盖护网、渗透、红队、逆向、密码、二进制、区块链、AI、云)

355 59 Updated Oct 12, 2025

一款针对Shiro550漏洞进行快速漏洞利用工具。 对 @SummerSec 大佬的项目https://github.com/SummerSec/ShiroAttack2 进行了一些改进。

Java 250 10 Updated May 29, 2023

Shiro550/Shiro721 一键化利用工具,支持多种回显方式

Java 1,942 298 Updated Jun 4, 2021

ColorOS短信漏洞,以及用户自救方案

Java 373 41 Updated Oct 15, 2025

用Go编写的轻量文件监控器. 可以监控终端上指定文件夹内的变化, 阻止删除,修改,新增操作. 可以用于AWD比赛或者终端应急响应

Go 31 7 Updated Sep 28, 2025

JNDI服务利用工具 RMI/LDAP,支持部分场景回显、内存shell,高版本JDK场景下利用等,fastjson rce命令执行,log4j rce命令执行 漏洞检测辅助工具

1,998 323 Updated May 21, 2024

shiro反序列化漏洞综合利用,包含(回显执行命令/注入内存马)修复原版中NoCC的问题 https://github.com/j1anFen/shiro_attack

Java 2,323 278 Updated Apr 10, 2024

HeapDump敏感信息提取工具

Java 1,579 144 Updated Apr 9, 2025

通过jsp脚本扫描java web Filter/Servlet型内存马

Java 960 131 Updated Mar 9, 2023

泛微最近的漏洞利用工具(PS:2023)

Go 476 44 Updated Dec 14, 2023

A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.

Java 8,550 1,841 Updated Mar 31, 2024

Go implementation of XTLS protocol.

Go 295 47 Updated Jan 7, 2023

Various *nix tools built as statically-linked binaries

Shell 3,488 608 Updated Aug 21, 2023

内网渗透过程中搜寻指定文件内容,从而找到突破口的一个小工具

Python 347 34 Updated Aug 13, 2025

Interactive, locally hosted tool to migrate Open-WebUI SQLite databases to PostgreSQL

Python 164 29 Updated Oct 8, 2025

思源笔记免登录版本;可以不登录使用同步功能

TypeScript 1,071 170 Updated Oct 14, 2025

人人都是哈基米大王

Python 877 278 Updated Aug 9, 2025
Go 1,382 138 Updated Oct 15, 2025

Jsmn is a world fastest JSON parser/tokenizer. This is the official repo replacing the old one at Bitbucket

C 3,960 804 Updated Jun 9, 2024
Next