Skip to content
View Lotus6's full-sized avatar
🤪
🤪

Block or report Lotus6

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

侦查守卫(observer_ward)Web应用和服务指纹识别工具

Rust 1,379 142 Updated Mar 23, 2025

Deserialization payload generator for a variety of .NET formatters

C# 3,364 487 Updated Dec 23, 2024

帆软bi反序列化漏洞利用工具

Java 313 24 Updated Jan 25, 2025

内网资产收集、探测主机存活、端口扫描、域控定位、文件搜索、各种服务爆破(SSH、SMB、MsSQL等)、Socks代理,一键自动化+无文件落地扫描

C# 359 31 Updated Nov 20, 2024

一款代码审计辅助插件

Kotlin 282 24 Updated Nov 28, 2024

Java表达式语句生成器

Java 184 13 Updated Oct 9, 2023
Java 8 1 Updated Oct 27, 2024

Hessian UTF-8 Overlong Encoding

Java 17 1 Updated Mar 9, 2024

抽离出 utf-8-overlong-encoding 的序列化逻辑,实现 2 3 字节加密序列化数组

Java 121 11 Updated Mar 11, 2024

ysoSimple:简易的Java漏洞利用工具,集成Java反序列化,Hessian反序列化,XStream反序列化,SnakeYaml反序列化,Shiro550,JSF反序列化,SSTI模板注入,JdbcAttackPayload,JNDIAttack,字节码生成。

Java 79 7 Updated Mar 26, 2025

一款支持自定义的 Java 回显载荷生成工具|A customizable Java echo payload generation tool.

Java 421 40 Updated Jan 12, 2025

DockerApiRCE

200 16 Updated Oct 22, 2024

Proof of Concept Exploit for vCenter CVE-2021-21972

Python 260 85 Updated Feb 25, 2021

jolokia Realm JNDI RCE 漏洞检测,并获取明文密码

Go 16 1 Updated May 29, 2023

这是一款图形化的代码审计工具,支持对规则进行增删改查。可协助代码审计人员在日常代审中对于规则的积累。其中配置页面可配置:审计文件后缀、审计路径关键字、禁止审计路径关键字。支持 java php net项目审计。

100 7 Updated Jan 16, 2025

An advanced memory forensics framework

Python 7,604 1,313 Updated Jun 14, 2023

ActiveMQ RCE (CVE-2023-46604) 漏洞利用工具

Go 239 30 Updated Jan 29, 2024

CVE-2021-21972 Exploit

Python 490 145 Updated Jun 8, 2023

一款针对Vcenter的综合利用工具,包含目前最主流的CVE-2021-21972、CVE-2021-21985以及CVE-2021-22005、One Access的CVE-2022-22954、CVE-2022-22972/31656以及log4j,提供一键上传webshell,命令执行或者上传公钥使用SSH免密连接

Go 1,385 167 Updated Apr 25, 2024

项目是根据LandGrey/SpringBootVulExploit清单编写,目的hvv期间快速利用漏洞、降低漏洞利用门槛。

Java 1,850 314 Updated Jan 15, 2024

📦 Make security testing of K8s, Docker, and Containerd easier.

Go 4,127 565 Updated Mar 8, 2025

netspy是一款快速探测内网可达网段工具(深信服深蓝实验室天威战队强力驱动)

Go 2,064 213 Updated Jul 25, 2023

一款帮助云租户发现和测试云上风险、增强云上防护能力的综合性开源工具

Go 427 34 Updated Mar 8, 2025

今日热榜是聚合热榜热搜平台,汇集了各大网站的热榜信息,包括微博热搜、今日头条、知乎日报、澎湃新闻、虎扑步行街、36氪、哔哩哔哩热榜,知乎、IT资讯、虎嗅网、人人都是产品经理、百度、抖音热点豆瓣小组精选等。

Less 223 36 Updated Mar 19, 2025

FlatLaf - Swing Look and Feel (with Darcula/IntelliJ themes support)

Java 3,645 287 Updated Mar 22, 2025

PHPGGC is a library of PHP unserialize() payloads along with a tool to generate them, from command line or programmatically.

PHP 3,407 514 Updated Mar 12, 2025

KunLun-M是一个完全开源的静态白盒扫描工具,支持PHP、JavaScript的语义扫描,基础安全、组件安全扫描,Chrome Ext\Solidity的基础扫描。

Python 2,299 312 Updated Nov 2, 2024

404StarLink - 推荐优质、有意义、有趣、坚持维护的安全开源项目

9,033 853 Updated Mar 24, 2025

基于 jdwp-shellifier 的进阶JDWP漏洞利用脚本(动态执行Java/Js代码并获得回显)

Python 272 28 Updated Dec 22, 2024
Next
Showing results