Lists (1)
Sort Name ascending (A-Z)
Starred repositories
Tsunami is a general purpose network security scanner with an extensible plugin system for detecting high severity vulnerabilities with high confidence.
LSPatch: A non-root Xposed framework extending from LSPosed
OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies.
This is a tool to repackage apk file, then the apk can load any xposed modules installed in the device. It is another way to hook an app without root device.
Java安全相关的漏洞和技术demo,原生Java、Fastjson、Jackson、Hessian2、XML反序列化漏洞利用和Spring、Dubbo、Shiro、CAS、Tomcat、RMI、Nexus等框架\中间件\功能的exploits以及Java Security Manager绕过、Dubbo-Hessian2安全加固等等实践代码。
Java web common vulnerabilities and security code which is base on springboot and spring security
shiro反序列化漏洞综合利用,包含(回显执行命令/注入内存马)修复原版中NoCC的问题 https://github.com/j1anFen/shiro_attack
Companion Android application for EdXposed
The new bridge between Burp Suite and Frida!
An easy-to-learn/use static analysis framework for Java
xposed安卓虚拟摄像头 android virtual camera on xposed hook
Thinkphp(GUI)漏洞利用工具,支持各版本TP漏洞检测,命令执行,getshell。
Samples and Unpacker of malicious backdoors and exploits developed and used by Pinduoduo
AndroRAT | Remote Administrator Tool for Android OS Hacking
A malicious LDAP server for JNDI injection attacks
将安卓远控Apk附加进普通的App中,运行新生成的App时,普通App正常运行,远控正常上线。Attach the Android remote control APK to a regular app. When the newly generated app is launched, the regular app operates as normal while the remote …
建议使用新版:https://github.com/jar-analyzer/jar-analyzer
This project aims to provide a central repository for many useful Tsunami Security Scanner plugins.
搜集了市面上绝大部分weblogic解密方式,整理了7种解密weblogic的方法及响应工具。
Shiro RememberMe 1.2.4 反序列化漏洞图形化检测工具(Shiro-550)