Stars
Azure Security Resources and Notes
Python script wrote to automate the process of generating various reverse shells.
用于辅助安全工程师漏洞挖掘、测试、复现,集合了mock、httplog、dns tools、xss,可用于测试各类无回显、无法直观判断或特定场景下的漏洞。
heapdump敏感信息查询工具,例如查找 spring heapdump中的密码明文,AK,SK等
MySQL Fake Server use to help MySQL Client File Reading and JDBC Client Java Deserialize
some learning notes about Web Application Security、 Penetration Test
evilzip lets you create a zip file(with password) that contains files with directory traversal characters in their embedded path.
spring boot Fat Jar 任意写文件漏洞到稳定 RCE 利用技巧
内存马Demo合集 memshell demo for java / php / python
Shiro反序列化利用工具,支持新版本(AES-GCM)Shiro的key爆破,配合ysoserial,生成回显Payload