☆41Mar 10, 2021Updated 4 years ago
Alternatives and similar repositories for non_RCE
Users that are interested in non_RCE are comparing it to the libraries listed below
Sorting:
- S&P2023 Paper☆39Aug 20, 2022Updated 3 years ago
- cve-2022-34169 延伸出的Jdk Xalan的payload自动生成工具,可根据不同的Jdk生成出其所对应的xslt文件☆93Jan 17, 2023Updated 3 years ago
- 一些Java RASP demo☆11Sep 26, 2019Updated 6 years ago
- java 漏洞平台包含各种CVE☆23Jun 17, 2022Updated 3 years ago
- Writeup and environment for XCTF2021Final-Dubbo☆44May 31, 2021Updated 4 years ago
- Java After-Deserialization Attack☆79Apr 26, 2021Updated 4 years ago
- POC for leaking java version through file and ftp protocols☆24Nov 1, 2020Updated 5 years ago
- ☆78Jan 12, 2021Updated 5 years ago
- A declarative static analysis tool for jvm bytecode based Datalog like CodeQL☆345Jan 6, 2024Updated 2 years ago
- JRE8u20_RCE_Gadget☆255Jul 1, 2016Updated 9 years ago
- A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.☆357Sep 20, 2022Updated 3 years ago
- 一个Java攻击框架☆23Nov 27, 2020Updated 5 years ago
- Slides/Demos from the BSides Munich 2019 talk "Attacking Java RMI in 2019"☆101Sep 20, 2019Updated 6 years ago
- 《深入理解DAST动态应用程序安全测试》Dynamic Application Security Testing.☆55Oct 29, 2022Updated 3 years ago
- 一个利用ASM对字节码进行污点传播分析的静态代码审计应用(添加了大量代码注释,适合大家进行源码学习)。也加入了挖掘Fastjson反序列化gadget chains和SQLInject(JdbcTemplate、MyBatis、JPA、Hibernate、原生jdbc等)静…☆458Mar 24, 2022Updated 3 years ago
- GitHub Satellite 2020 workshops on finding security vulnerabilities with CodeQL for Java/JavaScript.☆211Sep 27, 2024Updated last year
- tomcat使用了自带session同步功能时,不安全的配置(没有使用EncryptInterceptor)导致存在的反序列化漏洞,通过精心构造的数据包, 可以对使用了tomcat自带session同步功能的服务器进行攻击。PS:这个不是CVE-2020-9484,9484…☆212May 19, 2020Updated 5 years ago
- bypass JEP290 RaspHook code☆63Sep 21, 2020Updated 5 years ago
- TongASDP漏洞测试环境☆35Mar 22, 2023Updated 2 years ago
- (周瑜)Java - SpringBoot 持久化 WebShell(不仅仅是SpringBoot,适合任何符合JavaEE规范的服务)☆615Dec 29, 2021Updated 4 years ago
- 超硬核!使用图数据技术发现软件漏洞☆185Sep 1, 2021Updated 4 years ago
- ☆12May 28, 2021Updated 4 years ago
- ☆12Aug 5, 2021Updated 4 years ago
- 自动反编译闭源应用,创建codeql数据库☆316Mar 2, 2022Updated 4 years ago
- ☆26Mar 17, 2021Updated 4 years ago
- A CAT called tabby ( Code Analysis Tool )☆1,637Jan 17, 2026Updated last month
- COVA - A static analysis tool to compute path conditions☆40Jul 12, 2025Updated 7 months ago
- spring boot Fat Jar 任意写文件漏洞到稳定 RCE 利用技巧☆754Apr 14, 2021Updated 4 years ago
- Taint analysis implementation based on Heros and Soot☆45May 6, 2024Updated last year
- ☆835Jun 7, 2022Updated 3 years ago
- WebLogic T3/IIOP RCE ExternalizableHelper.class of coherence.jar☆81Jan 27, 2021Updated 5 years ago
- SCTF2020☆86Jul 10, 2020Updated 5 years ago
- ☆16Jan 5, 2021Updated 5 years ago
- WALA 学习笔记☆14Aug 8, 2023Updated 2 years ago
- ☆15Aug 6, 2021Updated 4 years ago
- springboot getRequestURI acl bypass☆37Oct 13, 2020Updated 5 years ago
- Static code auditing system☆468Jan 8, 2021Updated 5 years ago
- Bypass JVM Class ByteCode Verifier , 对抗反编译器☆116Sep 21, 2023Updated 2 years ago
- rmi、jndi、ldap、jrmp、jmx、jms一些demo测试☆310Jun 17, 2022Updated 3 years ago