☆61Sep 21, 2020Updated 5 years ago
Alternatives and similar repositories for JavaSearchTools
Users that are interested in JavaSearchTools are comparing it to the libraries listed below
Sorting:
- bypass JEP290 RaspHook code☆63Sep 21, 2020Updated 5 years ago
- XxlJob<=2.1.2配置不当情况下反序列化RCE☆120Nov 2, 2020Updated 5 years ago
- ☆835Jun 7, 2022Updated 3 years ago
- ☆31Apr 23, 2020Updated 5 years ago
- 帮助java环境下任意文件下载情况自动化读取源码的小工具☆166Apr 5, 2019Updated 6 years ago
- A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.☆103Mar 10, 2020Updated 6 years ago
- 一个利用ASM对字节码进行污点传播分析的静态代码审计应用(添加了大量代码注释,适合大家进行源码学习)。也加入了挖掘Fastjson反序列化gadget chains和SQLInject(JdbcTemplate、MyBatis、JPA、Hibernate、原生jdbc等)静…☆458Mar 24, 2022Updated 3 years ago
- JDBC Connection URL Attack☆441Sep 10, 2021Updated 4 years ago
- tomcat使用了自带session同步功能时,不安全的配置(没有使用EncryptInterceptor)导致存在的反序列化漏洞,通过精心构造的数据包, 可以对使用了tomcat自带session同步功能的服务器进行攻击。PS:这个不是CVE-2020-9484,9484…☆212May 19, 2020Updated 5 years ago
- attackRmi☆258Oct 14, 2020Updated 5 years ago
- ☆231Jan 3, 2022Updated 4 years ago
- A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.☆357Sep 20, 2022Updated 3 years ago
- jre8u20 gadget☆34May 23, 2021Updated 4 years ago
- 利用任意文件下载漏洞循环下载反编译 Class 文件获得网站 Java 源代码☆712May 10, 2021Updated 4 years ago
- JWT_Brute☆32Oct 10, 2019Updated 6 years ago
- Weblogic IIOP CVE-2020-2551☆338Apr 7, 2020Updated 5 years ago
- Java RCE 回显测试代码☆1,015Oct 15, 2020Updated 5 years ago
- shiro反序列化检测(只是个玩具23333)☆10Jan 16, 2024Updated 2 years ago
- 适用于weblogic和Tomcat的无文件的内存马(memshell)☆270Mar 4, 2022Updated 4 years ago
- CAS 硬编码 远程代码执行漏洞☆125Jun 4, 2021Updated 4 years ago
- ☆41Mar 10, 2021Updated 5 years ago
- Automatically scan jar packages by using ast to find fastjson gadgets. In particular, this project is limited to mining Gadgets that may …☆49Mar 8, 2022Updated 4 years ago
- rmi、jndi、ldap、jrmp、jmx、jms一些demo测试☆311Jun 17, 2022Updated 3 years ago
- A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.优化了一些东西。☆214Jan 17, 2022Updated 4 years ago
- 通过正则搜索、批量反编译特定Jar包中的class名称☆321Dec 9, 2021Updated 4 years ago
- java内存对象搜索辅助工具☆823Sep 23, 2022Updated 3 years ago
- spring boot Fat Jar 任意写文件漏洞到稳定 RCE 利用技巧☆754Apr 14, 2021Updated 4 years ago
- (周瑜)Java - SpringBoot 持久化 WebShell(不仅仅是SpringBoot,适合任何符合JavaEE规范的服务)☆614Dec 29, 2021Updated 4 years ago
- Java XMLDecoder payload generator☆16Jul 27, 2021Updated 4 years ago
- 一些Java编写的小工具。☆317Aug 5, 2021Updated 4 years ago
- ☆25May 4, 2020Updated 5 years ago
- Celestion 是一个无回显漏洞测试辅助平台,平台使用flask编写,提供DNSLOG,HTTPLOG等功能。 (界面懒得弄,后续有需要再说)。☆30Aug 24, 2023Updated 2 years ago
- 未授权批量检测脚本☆14Oct 9, 2019Updated 6 years ago
- ☆318Jun 4, 2021Updated 4 years ago
- JNDI服务利用工具 RMI/LDAP,支持部分场景回显、内存shell,高版本JDK场景下利用等,fastjson rce命令执行,log4j rce命令执行 漏洞检测辅助工具☆2,014May 21, 2024Updated last year
- Shiro_721 exp 纯手工实现Padding Oracle整个过程☆67Nov 20, 2019Updated 6 years ago
- 内存马Demo合集 memshell demo for java / php / python☆425May 31, 2021Updated 4 years ago
- CVE-2019-2725 命令回显☆436May 8, 2023Updated 2 years ago
- Weblogic环境搭建工具☆796Apr 23, 2020Updated 5 years ago