☆22Dec 5, 2022Updated 3 years ago
Alternatives and similar repositories for Security_Learning
Users that are interested in Security_Learning are comparing it to the libraries listed below
Sorting:
- 收集了java XXE漏洞的demo及修复方式☆19Mar 11, 2024Updated 2 years ago
- ☆20Nov 11, 2022Updated 3 years ago
- 用来存储Cheetah的脚本文件☆12Mar 31, 2021Updated 4 years ago
- 《深入理解Semgrep》Finding vulnerabilities with Semgrep.☆58Jul 20, 2023Updated 2 years ago
- JavaSec☆46Mar 18, 2024Updated 2 years ago
- 2023HW漏洞整理,收集整理漏洞EXp/POC,大部分漏洞来源网络,目前收集整理了200多个poc/exp☆14Sep 14, 2024Updated last year
- ☆16Oct 30, 2022Updated 3 years ago
- ☆19Jul 6, 2023Updated 2 years ago
- ☆22Feb 21, 2025Updated last year
- GitHub Action安全工具,可以将Action Secrets还原拿到明文,用于证明Secrets并不是绝对的安全。(测试通过,放心使用,再有问题来issues区锤我...)☆24Sep 12, 2022Updated 3 years ago
- MinIO敏感信息泄露漏洞批量扫描poc&exp☆36Mar 24, 2023Updated 2 years ago
- 支持Tomcat内存马查杀的JSP脚本☆65Jun 16, 2025Updated 9 months ago
- 白嫖国外临时主机 🐶☆60May 16, 2024Updated last year
- Security tool to encode/decode Golang web-frameworks' client-side session cookie which use `gorilla/securecookie` or `gorilla/sessions`, …☆36Oct 7, 2019Updated 6 years ago
- ☆19Aug 28, 2022Updated 3 years ago
- generate facts from bytecode (source is https://github.com/plast-lab/doop-mirror/tree/master/generators)☆23Nov 24, 2024Updated last year
- Go 调用DLL添加计划任务维持权限☆16Nov 13, 2022Updated 3 years ago
- AppImage bundled version xfreerdp with pass the hash function☆15Apr 17, 2018Updated 7 years ago
- 自动采集代理IP池工具☆17May 30, 2022Updated 3 years ago
- 一个验证对CVE-2024-21733☆26Aug 16, 2024Updated last year
- javaGGC for generate commons.collections gadget chain☆12Nov 10, 2021Updated 4 years ago
- NCTF 2024 challenges and writeups☆10Apr 11, 2025Updated 11 months ago
- 【两万字原创】零基础学fastjson漏洞(提高篇),公众号:追梦信安☆211Dec 7, 2023Updated 2 years ago
- CodeVulnScan 是一款基于正则表达式的代码安全审计工具,专为红队成员快速定位sink设计。它能够快速扫描目标代码库,定位潜在的漏洞 Sink 点,提升代码审计效率。☆65Feb 11, 2026Updated last month
- javaDeserializeLabs☆70Apr 18, 2023Updated 2 years ago
- BurpCrypto officially confirms the supported JS library (BurpCrypto官方确认支持的JS库).☆12Sep 21, 2021Updated 4 years ago
- Pickle decompiler plugin for Radare2☆18Aug 6, 2023Updated 2 years ago
- JSFindAPI是一款自动从html页面中获取js链接,并自动访问js提取js中的api路径,然后自动进行api未授权测试的插件,同时也可被动监听,当访问js时自动提取api进行访问,提取api接口主要根据AJAX,XMLHttpRequest,axios,Vue.js等…☆30Oct 20, 2025Updated 5 months ago
- ☆35Jul 5, 2020Updated 5 years ago
- Java安全 学习记录☆209Aug 27, 2022Updated 3 years ago
- CVE-2021-34371.jar☆32Sep 6, 2021Updated 4 years ago
- ysoserial修改版,着重修改ysoserial.payloads.util.Gadgets.createTemplatesImpl使其可以通过引入自定义class的形式来执行命令、内存马、反序列化回显。☆754Jan 11, 2024Updated 2 years ago
- JavaWeb MemoryShell Inject/Scan/Killer/Protect Research & Exploring☆654Jun 25, 2021Updated 4 years ago
- Quarks PwDump is a native Win32 tool to extract credentials from Windows operating systems.☆12Jun 25, 2015Updated 10 years ago
- A neo4j procedure for tabby☆137May 17, 2025Updated 10 months ago
- 一些总结出来的gadget的flow,后续合适和加入新的flow☆68Dec 6, 2025Updated 3 months ago
- CodeQL extractor for java, which don't need to compile java source☆348Nov 25, 2022Updated 3 years ago
- 红方人员作战执行手册☆11Feb 22, 2020Updated 6 years ago
- 基于函数级污点分析的 Java 源代码漏洞审计工具JavaSinkTracer,通过 Model Context Protocol (MCP) 为 AI 助手提供安全分析能力。☆106Oct 7, 2025Updated 5 months ago