在Java安全学习过程中的笔记和代码
☆89Mar 15, 2026Updated last week
Alternatives and similar repositories for MyJavaSecStudy
Users that are interested in MyJavaSecStudy are comparing it to the libraries listed below
Sorting:
- 一些总结出来的gadget的flow,后续合适和加入新的flow☆68Dec 6, 2025Updated 3 months ago
- YongYou U8C deserialization file upload exploit tool targeting IPFxxFileService and IFileTrans services☆28Sep 28, 2025Updated 5 months ago
- JeecgCracker 是一个专门针对 JeecgBoot 框架的密码爆破工具。☆29Oct 29, 2024Updated last year
- 利用代理驱动绕过JDBC Attack检测☆143Jun 15, 2025Updated 9 months ago
- PHP文件上传50+绕过手法全景解析☆17Mar 16, 2025Updated last year
- No One(无名):Next Generation Polyglot Website Manager☆76Updated this week
- 用于快速启动tabby 分析漏洞或者gadget的环境☆94Jul 14, 2025Updated 8 months ago
- 适用于某EHR&HRM的加解密工具,可直接用于sqlmap☆25Jan 14, 2024Updated 2 years ago
- Java bytecode line number restoration tool☆135Aug 31, 2025Updated 6 months ago
- 一个基于 Vineflower 引擎的多线程 Java 批量反编译工具,支持快速处理大量的 class 文件和 JAR 文件。☆58Apr 28, 2025Updated 10 months ago
- 方便自己搭建codeql环境和数据库的工具。☆64Aug 16, 2025Updated 7 months ago
- 某软最新公开gadgegt,新加入不出网利用。☆89Sep 6, 2024Updated last year
- ASP & ASP.NET WebShell Bypass☆68Jan 4, 2026Updated 2 months ago
- A powerful JNDI injection exploitation framework that supports RMI, LDAP and LDAPS protocols, including various bypass methods for high-v…☆573Feb 4, 2026Updated last month
- MySQL_Fake_Server-啄木鸟yso适配版☆45Sep 20, 2024Updated last year
- JavaGadgetGenerator 工具,支持 ysoserial,Hessian,字节码,Expr/SSTI,Shiro,JDBC 等 Gadget 生成,封装,混淆,出网延迟探测,内存马注入等...☆552Dec 7, 2025Updated 3 months ago
- 用Go+Fyne开发的,展示JAVA序列化流以及集成一键插入脏数据,UTF过长编码绕WAF(Utf OverLoad Encoding),修改类SerializeVersionUID功能的图形化工具。☆125Jan 14, 2025Updated last year
- 配合 CVE-2023-22515 后台上传jar包实现RCE☆23Nov 9, 2023Updated 2 years ago
- VBS-Obfuscator-GO is a Go-based tool designed for obfuscating VBScript (VBS) files. It transforms readable VBScript code into a less reco…☆38Apr 21, 2025Updated 11 months ago
- 《深 入JDBC安全:特殊URL构造与不出网反序列化利用技术揭秘》对应研究总结项目 "Deep Dive into JDBC Security: Special URL Construction and Non-Networked Deserialization Explo…☆572Feb 7, 2026Updated last month
- java-web 自动化鉴权绕过☆377Apr 3, 2025Updated 11 months ago
- CVE-2024-21006 exp☆17Jul 29, 2024Updated last year
- Memory Webshell for Spring Web - 适用于 Spring Web 的内存马☆26Jan 18, 2024Updated 2 years ago
- JeecgBoot Go版本综合漏洞检测工具☆81Feb 24, 2026Updated 3 weeks ago
- 【两万字原创】零基础学fastjson漏洞(提高篇),公众号:追梦信安☆211Dec 7, 2023Updated 2 years ago
- 漏洞poc☆110Jan 4, 2026Updated 2 months ago
- vcenter图形化漏洞利用工具☆70Nov 17, 2024Updated last year
- 无需文件落地Agent内存马生成器☆249May 30, 2024Updated last year
- 记录一些代码审计过的源码☆182Feb 26, 2025Updated last year
- 一款简单好用的漏洞管理工具,支持本地和协作两种模式。☆165Nov 21, 2024Updated last year
- xxl-job内存马☆227Jan 26, 2025Updated last year
- Burp插件,自动化挖掘SSRF,Redirect,Sqli漏洞,自定义匹配参数☆464Sep 10, 2023Updated 2 years ago
- 专注于java代码审计skills☆285Mar 10, 2026Updated last week
- 一款Java内存马生成、测试工具,搭配@ax1sX的MemShell食用。☆262Feb 15, 2026Updated last month
- Burp条件竞争测试插件☆26Aug 21, 2025Updated 7 months ago
- Hessian UTF-8 Overlong Encoding☆21Mar 9, 2024Updated 2 years ago
- 哥斯拉Hikvision综合安防后渗透插件,运行中心/web前台/MinIO 配置提取(解密)重置密码,还原密码。☆170Oct 8, 2024Updated last year
- 代码审计知识点整理-Java☆529Jun 15, 2020Updated 5 years ago
- 之前方便自己研究RASP原理和绕过时顺手写的,用于快速启动和重置RASP环境☆71Oct 13, 2024Updated last year