Skip to content
View b1ackc4t's full-sized avatar
🚩
flag
🚩
flag

Block or report b1ackc4t

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Stars

java_exp

13 repositories

JNDI注入测试工具(A tool which generates JNDI links can start several servers to exploit JNDI Injection vulnerability,like Jackson,Fastjson,etc)

Java 2,782 738 Updated Mar 22, 2023

不那么一样的 Java Agent 内存马

Java 289 37 Updated Nov 27, 2023

spring boot Fat Jar 任意写文件漏洞到稳定 RCE 利用技巧

Java 754 75 Updated Apr 14, 2021

A CAT called tabby ( Code Analysis Tool )

Java 1,637 178 Updated Jan 17, 2026

纯 Java 实现的 MySQL Fake Server | 支持 GUI 版和命令行版 | 支持反序列化和文件读取的利用方式 | 支持常见的 GADGET 和自定义 GADGET 数据 | 根据目标环境自动生成匹配的 PAYLOAD | 支持 PGSQL 和 DERBY 的利用

Java 825 95 Updated Sep 18, 2023

SpringBoot 相关漏洞学习资料,利用方法和技巧合集,黑盒安全评估 check list

Java 6,117 1,323 Updated Mar 10, 2021

JNDI服务利用工具 RMI/LDAP,支持部分场景回显、内存shell,高版本JDK场景下利用等,fastjson rce命令执行,log4j rce命令执行 漏洞检测辅助工具

2,012 322 Updated May 21, 2024

Common Exploitation Techniques for Java RCE Vulnerabilities in Real-World Scenarios | 实战场景较通用的 Java Rce 相关漏洞的利用方式

Java 545 61 Updated Mar 6, 2025

shiro反序列化漏洞综合利用,包含(回显执行命令/注入内存马)修复原版中NoCC的问题 https://github.com/j1anFen/shiro_attack

Java 2,380 282 Updated Apr 10, 2024

Weblogic一键漏洞检测工具,V1.5,更新时间:20200730

Python 2,266 407 Updated May 22, 2023

weblogic t3 deserialization rce

Java 268 96 Updated Jul 13, 2017

A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.

Java 8,765 1,852 Updated Dec 4, 2025