在ShiroAttack2基础上增加 Header 长度绕过、分块、短 Payload等功能
☆98Apr 14, 2026Updated 4 months ago
Alternatives and similar repositories for ShiroAttack2_bypass
Users that are interested in ShiroAttack2_bypass are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- LingXiLabs是凌曦安全团队依托攻防实战经验与SRC漏洞挖掘经验打造的漏洞靶场集合,以“锤炼攻防技能、赋能漏洞挖掘”为核心,免费为网络安全爱好者、从业人员供练习环境。☆48Mar 14, 2026Updated 5 months ago
- Shiro反序列化漏洞一站式综合利用工具☆174Jan 22, 2026Updated 6 months ago
- SQLMap-FluX 是针对sql注入的改造版本。本项目核心在于通过重构工具的静态特征、逻辑载荷以及交互行为,使其能够模拟拟人化的访问模式,从而在渗透测试中,有效检测并绕过现代Web应用防火墙的特征识别与频率检测。☆49Mar 11, 2026Updated 5 months ago
- APIKit 是Burp Suite 的一个API接口扫描插件,该版本APIKit是对API-Security项目的APIKit1.0进行的二开,增加了扫描开关,避免直接打开burp乱扫被抓起来☆106Dec 19, 2025Updated 7 months ago
- 一款针对K8s综合利用GUI工具☆181Apr 26, 2026Updated 3 months ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- JeecgBoot Go版本综合漏洞检测工具☆103Feb 24, 2026Updated 5 months ago
- 幽狼AI Shell:首款支持AI渗透的高级WebShell & C2管理工具 ,内置WebShell MCP服务器,支持多层内网级联的ASPX、ASHX高级WebShell管理工具,AES加密通信,无需代理,内存加载渗透工具,无文件落地隐蔽渗透目标,动态代码执行,Shell…☆269Updated this week
- TongWebExploit 是一款面向 TongWeb 反序列化漏洞场景的图形化检测与利用工具,支持漏洞探测、命令回显、EL 表达式执行、内存马注入和批量检测。☆46Jun 20, 2026Updated last month
- Apache ActiveMQ漏洞综合利用工具(CVE-2015-5254,CVE-2016-3088,CVE-2022-41678,CVE-2023-46604,CVE-2024-32114,CVE-2026-34197,CVE-2026-40466, CVE-2026-…☆83Jun 27, 2026Updated last month
- burpsuit插件,解析swagger/openapi接口文档并进行请求,模拟参数方便渗透测试人员快速发现可用接口 (最新使用源码编译,release有时候没空搞)☆46Oct 23, 2025Updated 9 months ago
- ☆121Jun 17, 2026Updated 2 months ago
- 基于 Y4er/ysoserial 与 marshalsec 的 Java 反序列化利用 GUI 工具,集成 Payload 生成、JNDI Reference、LDAP 反序列化与调用图编辑。☆44May 5, 2026Updated 3 months ago
- 一款用于网页敏感信息检测,指纹识别的chrome插件☆902Aug 10, 2026Updated last week
- 由ABC_123编写的Web日志分析工具☆154Jun 28, 2026Updated last month
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- 综合后渗透方面的杂烩☆601Mar 1, 2026Updated 5 months ago
- OneScan扩展,原项目已停更,此项目为二开项目,插件ID精简为OST☆54Aug 11, 2026Updated last week
- MPET (Multi-Protocol Exploitation Toolkit) 是一款专业的多协议安全测试工具,基于 Wails 框架构建的现代化桌面应用。它提供了对 25+ 种主 流服务协议的连接测试、未授权访问检测、弱口令检测和漏洞利用能力,是安全研究人员和渗透测试…☆221Jan 22, 2026Updated 6 months ago
- 后渗透信息/密码/凭证收集工具☆308May 7, 2025Updated last year
- ☆127Dec 16, 2025Updated 8 months ago
- xxl-job漏洞综合利用工具☆161Jun 3, 2025Updated last year
- 对原版https://github.com/feihong-cs/JNDIExploit 进行了实用化修改☆24Apr 19, 2022Updated 4 years ago
- Nacos 综合漏洞利用工具☆680Nov 3, 2025Updated 9 months ago
- 专注于代码审计skill,最小化轻量化skill,只负责安全边界。☆1,000Jun 16, 2026Updated 2 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- 哥斯拉Godzilla定制化插件,接收恶意类Base64编码与恶意类类名进行实例化,达到注入任意类型内存马的目的。☆49Dec 30, 2025Updated 7 months ago
- JavaGadgetGenerator 工具,支持 ysoserial,Hessian,字节码,Expr/SSTI,Shiro,JDBC 等 Gadget 生成,封装,混淆,出网延迟探测,内存马注入等...☆577Apr 3, 2026Updated 4 months ago
- Professional file upload vulnerability testing tool with 263+ bypass techniques, proxy capture, dynamic scanning(专业的文件上传漏洞检测工具,支持263+绕过技术…☆229Updated this week
- api接口测试工具,包括swagger文档,asp接口文档,wsdl接口,wadl接口,一键自动跑接口☆179Mar 30, 2026Updated 4 months ago
- FastjsonScan4Burp 一款基于burp被动扫描的fastjson漏洞探测插件,可针对数据包中存在json的参数或请求体进行payload测试。旨在帮助安全人员更加便捷的发现、探测、深入利用fastjson漏洞,目前已实现fastjson探测、版本、依赖探测、出…☆174Mar 13, 2025Updated last year
- Burpsuite存储桶配置不当漏洞检测插件☆200Jul 16, 2025Updated last year
- Shiro漏洞利用工具☆160Jan 12, 2026Updated 7 months ago
- 浏览器存储桶配置漏洞检测插件☆276Nov 27, 2025Updated 8 months ago
- ☆45Sep 8, 2025Updated 11 months ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- ☆77Sep 10, 2025Updated 11 months ago
- PHP-Code-Audit-Skill是一个专注于PHP代码审计的Skill☆390Mar 25, 2026Updated 4 months ago
- ☆268Mar 31, 2026Updated 4 months ago
- GodzillaNodeJsPayload☆171Dec 10, 2025Updated 8 months ago
- 用Go+Fyne开发的,展示JAVA序列化流以及集成一键插入脏数据,UTF过长编码绕WAF(Utf OverLoad Encoding),修改类SerializeVersionUID功能的图形化工具。☆126Jul 30, 2026Updated 2 weeks ago
- Shiro反序列化漏洞综合利用,在原版工具上进行一些功能增加。☆163Apr 3, 2025Updated last year
- ☆47Jul 30, 2026Updated 2 weeks ago