ssr's repositories

burpsuite_hack

一款代理扫描器

shiro_attack

shiro attack

Language:PythonStargazers:8Issues:1Issues:0

smallscripts

渗透测试中用到的一些小脚本

Language:PythonStargazers:8Issues:1Issues:0

Hello-Java-Sec

☕️ Java Security,安全编码和代码审计

Language:JavaStargazers:2Issues:0Issues:0

API-T00L

互联网厂商API利用工具。

Language:JavaLicense:GPL-3.0Stargazers:1Issues:0Issues:0

Galaxy

Burp插件,主要实现在HTTP报文二次加密场景下自动解密以使得Burp中展示明文报文的功能

Language:JavaLicense:Apache-2.0Stargazers:1Issues:0Issues:0

JavaRce

Common Exploitation Techniques for Java RCE Vulnerabilities in Real-World Scenarios | 实战场景较通用的 Java Rce 相关漏洞的利用方式

Language:JavaStargazers:1Issues:0Issues:0

KillWxapkg

自动化反编译微信小程序,小程序安全利器,自动解密,解包,可最大程度还原工程目录

Language:GoLicense:MITStargazers:1Issues:0Issues:0

Autorize

Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application security people work and allow them perform an automatic authorization tests

Language:PythonStargazers:0Issues:0Issues:0

bashFuck

exec BashCommand with only ! # $ ' ( ) < \ { } just 10 charset used in Bypass or CTF

Language:PythonStargazers:0Issues:0Issues:0

cs-self-learning

计算机自学指南

Language:HTMLLicense:NOASSERTIONStargazers:0Issues:0Issues:0

e0e1-wx

微信小程序辅助渗透-自动化

Language:PythonStargazers:0Issues:0Issues:0

FakeToa

TCP IP伪造,建议使用 ubuntu 22.04

Language:PythonStargazers:0Issues:0Issues:0

FastJsonParty

FastJson全版本Docker漏洞环境(涵盖1.2.47/1.2.68/1.2.80等版本),主要包括JNDI注入及高版本绕过、waf绕过、文件读写、原生反序列化、利用链探测绕过、不出网利用等。从黑盒的角度覆盖FastJson深入利用

Language:PythonStargazers:0Issues:0Issues:0

fuzzDicts

Web Pentesting Fuzz 字典,一个就够了。

Language:PythonStargazers:0Issues:0Issues:0

Go_Bypass

Golang Bypass Av Generator template

Language:GoStargazers:0Issues:0Issues:0

impacket

Impacket is a collection of Python classes for working with network protocols.

Language:PythonLicense:NOASSERTIONStargazers:0Issues:0Issues:0

Java

关于学习java安全的一些知识,正在学习中ing,欢迎fork and star

Language:JavaStargazers:0Issues:0Issues:0

java-sec-code

Java web common vulnerabilities and security code which is base on springboot and spring security

Language:JavaStargazers:0Issues:0Issues:0

JavaGuide

「Java学习+面试指南」一份涵盖大部分 Java 程序员所需要掌握的核心知识。准备 Java 面试,首选 JavaGuide!

Language:JavaStargazers:0Issues:0Issues:0

kscan

Kscan是一款纯go开发的全方位扫描器,具备端口扫描、协议检测、指纹识别,暴力破解等功能。支持协议1200+,协议指纹10000+,应用指纹2000+,暴力破解协议10余种。

Language:GoLicense:GPL-3.0Stargazers:0Issues:0Issues:0
Stargazers:0Issues:0Issues:0

name-fuzz

针对目标已知信息的字典生成工具

Language:PythonLicense:Apache-2.0Stargazers:0Issues:0Issues:0

poc2jar

java编写,python作为辅助依赖的漏洞验证、利用工具,另外添加了进程查找模块、编码模块、命令模块、常见漏洞利用GUI模块,加快测试效率

Language:PythonStargazers:0Issues:0Issues:0

secator

secator - the pentester's swiss knife

Language:PythonLicense:NOASSERTIONStargazers:0Issues:0Issues:0

spray

Next Generation HTTP Dir/File Fuzz Tool

Language:GoLicense:GPL-3.0Stargazers:0Issues:0Issues:0

SSRF-Testing

SSRF (Server Side Request Forgery) testing resources

Stargazers:0Issues:0Issues:0

wxapkg

微信小程序反编译工具,.wxapkg 文件扫描 + 解密 + 解包工具

Language:GoStargazers:0Issues:0Issues:0

ysomap

A helpful Java Deserialization exploit framework.

Language:JavaLicense:Apache-2.0Stargazers:0Issues:0Issues:0

ysoserial-1

此项目为su18大佬的仓库镜像,如有问题可发issuse删库

Language:JavaLicense:MITStargazers:0Issues:0Issues:0