Whoami 👋 About: Security Research、WAF Attack and Defense、Code Review、AISec 🔭 CTFer: @R3kapig/@0x401 Team ⭐️ Github: https://github.com/Y4tacker 🍔 Blog: http://y4tacker.github.io/ Overview Top Repositories Contributions in the last year…
Whoami
- 👋 About: Security Research、WAF Attack and Defense、Code Review、AISec
- 🔭 CTFer: @R3kapig/@0x401 Team
- ⭐️ Github: https://github.com/Y4tacker
- 🍔 Blog: http://y4tacker.github.io/
Overview
Top Repositories
Contributions in the last year
-
JavaSec
a rep for documenting my study, may be from 0 to 0.1
Java ★ 2.3k 3mo agoExplain → -
HackingFernFlower
2023白帽补天大会部分代码
Java ★ 128 2y agoExplain → -
CobaltStrike4.7ServerDocker
docker运行cs4.7server端
Dockerfile ★ 39 3y agoExplain → -
CTFBackup
备份下比赛附件
Java ★ 22 3y agoExplain → -
Waymark
A durable blackboard runtime for verifiable Claude Code agent loops.
Python ★ 19 1mo agoExplain → -
phpfuck-6characters
only 5 characters to rce
PHP ★ 15 3y agoExplain → -
codex-ai-ppt
Review-gated image-based PPT generation for Codex
Python ★ 14 26d agoExplain → -
CodeqlLearn ⑂
记录学习codeql的过程
★ 10 4y agoExplain → -
y4tacker.github.io
my websites
HTML ★ 9 25d agoExplain → -
Secs
No description.
★ 9 3y agoExplain → -
HackJava ⑂
《Java安全-只有Java安全才能拯救宇宙》Only Java Security Can Save The Universe.
★ 8 4y agoExplain → -
Laravel-exploit
No description.
PHP ★ 6 4y agoExplain → -
WeblogicEnvironment ⑂
Weblogic环境搭建工具
Shell ★ 6 4y agoExplain → -
ThinkPHP-Vuln ⑂
关于ThinkPHP框架的历史漏洞分析集合
★ 4 6y agoExplain → -
pop_master-AutoPoP
强网杯十六万行代码自动获得POP链
PHP ★ 4 4y agoExplain → -
hue-hive-rce ⑂
Use Hive to hijack a Hadoop cluster+
★ 4 4y agoExplain → -
goShellCodeByPassVT ⑂
通过线程注入及-race参数免杀全部VT
★ 3 5y agoExplain → -
Spring-Kafka-POC-CVE-2023-34040 ⑂
POC for Spring Kafka Deserialization Vulnerability CVE-2023-34040
★ 3 2y agoExplain → -
pxplanbackup ⑂
backup
★ 3 2y agoExplain → -
MagicStick
No description.
PHP ★ 3 4y agoExplain → -
practiceTraining
实训项目
Java ★ 3 6y agoExplain → -
JDBC-Attack ⑂
JDBC Connection URL Attack
★ 3 4y agoExplain → -
HackSpring ⑂
《Spring漏洞学习》
★ 2 4y agoExplain → -
Y4tacker
self
★ 2 10h agoExplain → -
Advanced-SQL-Injection-Cheatsheet ⑂
A cheat sheet that contains advanced queries for SQL Injection of all types.
★ 2 4y agoExplain → -
SCU-Thesis-LaTeX-Template ⑂
四川大学本科、硕士、博士论文LaTeX模版
TeX ★ 2 3y agoExplain → -
Fastjson ⑂
Fastjson姿势技巧集合
★ 2 5y agoExplain → -
redis-ssrf ⑂
redis ssrf gopher generater && redis ssrf to rce by master-slave-sync
★ 2 5y agoExplain → -
killer ⑂
Killer Agent
★ 1 8mo agoExplain → -
ysoserial ⑂
在原有yso基础上实现依赖分离,内存马注入等功能。A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.
★ 1 4y agoExplain → -
chatbox ⑂
User-friendly Desktop Client App for AI Models/LLMs (GPT, Claude, Gemini, Ollama...)
★ 1 11mo agoExplain → -
JSP-Webshells ⑂
Collect JSP webshell of various implementation methods. 收集JSP Webshell的各种姿势
★ 1 4y agoExplain → -
Bt-exploit
No description.
Python ★ 1 4y agoExplain → -
Mind-Map ⑂
各种安全相关思维导图整理收集
★ 1 8y agoExplain → -
Struts2-Vulenv ⑂
struts2 漏洞环境源代码
★ 1 4y agoExplain → -
cf ⑂
云环境利用框架 Cloud Exploitation Framework 方便红队人员在获得 AK 的后续工作
★ 1 4y agoExplain → -
HideShell ⑂
A JSP backdoor that enables under Tomcat hiding arbitrary JSP files, in addition to their access logs.
★ 1 7y agoExplain → -
Cobalt_Strike_wiki ⑂
Cobalt Strike系列
★ 1 7y agoExplain → -
SpringBootVulExploit ⑂
SpringBoot 相关漏洞学习资料,利用方法和技巧合集,黑盒安全评估 check list
★ 1 5y agoExplain → -
websiteComments
my website Comments
★ 1 4y agoExplain → -
log4j2-vaccine ⑂
log4j2-vaccine
★ 1 4y agoExplain → -
JNDIExploit ⑂
A malicious LDAP server for JNDI injection attacks
★ 1 4y agoExplain → -
HaE ⑂
HaE - BurpSuite Highlighter and Extractor
★ 0 4y agoExplain → -
milvus ⑂
Milvus is a high-performance, cloud-native vector database built for scalable vector ANN search
★ 0 1mo agoExplain → -
claude-code-source ⑂
No description.
★ 0 3mo agoExplain → -
MineContext ⑂
MineContext is your proactive context-aware AI partner(Context-Engineering+ChatGPT Pulse)
★ 0 8mo agoExplain → -
gpt-oss ⑂
What does gpt-oss tell us about OpenAI's training data?
★ 0 10mo agoExplain → -
WeKnora ⑂
LLM-powered framework for deep document understanding, semantic retrieval, and context-aware answers using RAG paradigm.
★ 0 10mo agoExplain → -
tabby ⑂
A CAT called tabby ( Code Analysis Tool )
★ 0 4y agoExplain → -
chatlog ⑂
chat log tool, easily use your own chat data. 聊天记录工具,轻松使用自己的聊天数据
★ 0 1y agoExplain → -
CVE-2020-1938 ⑂
No description.
★ 0 6y agoExplain → -
Apache-NiFi-Api-RCE ⑂
No description.
★ 0 5y agoExplain → -
wsMemShell ⑂
websocket cmd内存马 wscmd.jsp websocket 代理内存马 wsproxy.jsp
★ 0 4y agoExplain → -
PHP-binary-bugs ⑂
PHP binary bugs advisory
★ 0 4y agoExplain → -
Rogue-MySql-Server ⑂
Rogue MySql Server
★ 0 13y agoExplain → -
scripts ⑂
Utils
★ 0 10y agoExplain → -
eagrundy ⑂
No description.
★ 0 5y agoExplain → -
MysqlHoneypot ⑂
mysql蜜罐,获取攻击者微信。公众号:台下言书
★ 0 5y agoExplain → -
Fortify ⑂
源代码漏洞の审计
★ 0 5y agoExplain → -
ShiroAttack2 ⑂
shiro反序列化漏洞综合利用,包含(回显执行命令/注入内存马)修复原版中NoCC的问题 https://github.com/j1anFen/shiro_attack
★ 0 4y agoExplain → -
java-object-searcher ⑂
java内存对象搜索辅助工具
★ 0 5y agoExplain → -
ZhouYu ⑂
(周瑜)Java - SpringBoot 持久化 WebShell 学习demo(不仅仅是SpringBoot,适合任何符合JavaEE规范的服务)
★ 0 4y agoExplain → -
ascii-jar ⑂
构造字节在ASCII范围内的jar
★ 0 4y agoExplain → -
heapdump_tool ⑂
heapdump敏感信息查询工具,例如查找 spring heapdump中的密码明文,AK,SK等
★ 0 4y agoExplain → -
donut ⑂
Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs them with parameters
★ 0 4y agoExplain → -
JNDI-Injection-Exploit ⑂
JNDI注入测试工具(A tool which generates JNDI links can start several servers to exploit JNDI Injection vulnerability,like Jackson,Fastjson,etc)
★ 0 4y agoExplain → -
after-deserialization-attack ⑂
Java After-Deserialization Attack
★ 0 5y agoExplain → -
ysoserial-for-woodpecker ⑂
给woodpecker框架量身定制的ysoserial
★ 0 4y agoExplain → -
PaddingZip ⑂
PaddingZip is a tool that you can craft a zip file that contains the padding characters between the file content.
★ 0 4y agoExplain → -
JNDI ⑂
JNDI 注入利用工具
★ 0 5y agoExplain → -
ascii-zip ⑂
A deflate compressor that emits compressed data that is in the [A-Za-z0-9] ASCII byte range.
★ 0 4y agoExplain → -
java-memshell-scanner ⑂
通过jsp脚本扫描java web Filter/Servlet型内存马
★ 0 4y agoExplain → -
KpLi0rn ⑂
No description.
★ 0 4y agoExplain → -
vulnerability ⑂
No description.
★ 0 4y agoExplain → -
AgentMemShell ⑂
JavaAgent内存马
★ 0 5y agoExplain → -
MemoryShellLearn ⑂
分享几个直接可用的内存马,记录一下学习过程中看过的文章
★ 0 5y agoExplain → -
Rogue-MySql-Server-1 ⑂
Rogue-MySql-Server
★ 0 6y agoExplain → -
WindowsElevation ⑂
Windows Elevation(持续更新)
★ 0 5y agoExplain → -
JavaThings ⑂
Share Things Related to Java - Java安全漫谈笔记相关内容
★ 0 5y agoExplain → -
php7-internal ⑂
PHP7内核剖析
★ 0 5y agoExplain → -
geek-2020-challenges ⑂
No description.
★ 0 5y agoExplain → -
Java-Tutorial ⑂
【Java工程师面试复习指南】本仓库涵盖大部分Java程序员所需要掌握的核心知识,整合了互联网上的很多优质Java技术文章,力求打造为最完整最实用的Java开发者学习指南,如果对你有帮助,给个star告诉我吧,谢谢!
★ 0 5y agoExplain → -
happywd
No description.
★ 0 5y agoExplain → -
js-html2canvas-canvas2image-dom- ⑂
js配合html2canvas和canvas2image将dom元素转化成图片
★ 0 7y agoExplain →
No repos match these filters.