基于多种策略, 对已有 JAR 包中的全限定类名进行变换, 无限生成高度相似的虚假类名
Repository
Repository di X1r0z
test dll hijacking
利用 Exchange 服务器 Web 接口爆破邮箱账户 | Brute force email accounts using Exchange server web endpoints
A powerful JNDI injection exploitation framework that supports RMI, LDAP and LDAPS protocols, including various bypass methods for high-version JDK restrictions
bugscan scanner
Profile
c++ shellcode loader
dork everything
PoC of Apache Dubbo CVE-2023-23638
基于原版 frp 二开, 添加了一些小功能
NTLM/Negotiate authentication over HTTP that supports Pass The Hash Mode (PtH)
Hacking GraalVM Espresso - Abusing Continuation API to Make ROP-like Attack
Hessian UTF-8 Overlong Encoding
A command-line tool for Java Web memory shell incident response
MSFvenom-NG
PoC of Nacos JRaft Hessian RCE
A lightweight port-forwarding and socks proxy tool written in Rust 🦀
My presentation slides