高版本Fastjson在Java原生反序列化中的利用演示
☆26Jan 12, 2025Updated last year
Alternatives and similar repositories for FastjsonInDeserializationDemo1
Users that are interested in FastjsonInDeserializationDemo1 are comparing it to the libraries listed below
Sorting:
- 在spring-aop中新发现的反序列化gadget-chain☆52Jan 12, 2025Updated last year
- 使用 Docker 一键构建 JDK 源码的 CodeQL 数据库,方便使用 CodeQL 查找 JDK 中的数据。☆27May 14, 2025Updated 9 months ago
- Attack Active Directory Trusts with a single tool☆14Jan 15, 2025Updated last year
- ☆22Feb 21, 2025Updated last year
- 基于多种策略, 对已有 JAR 包中的全限定类名进行变换, 无限生成高度相似的虚假类名☆18Jul 30, 2025Updated 7 months ago
- A C#-implemented malware that dynamically modifies its own hash upon each execution to evade detection.☆17Feb 3, 2025Updated last year
- Get sql server connection configuration information☆28Aug 26, 2024Updated last year
- tsh多终端代理通信☆19Feb 26, 2025Updated last year
- ctf awd比赛快速hook java题,提供一键流量转发,无痛修复☆56Mar 17, 2025Updated 11 months ago
- 内存加载FRP☆10Sep 11, 2023Updated 2 years ago
- Active Directory share enumeration tool☆12Apr 28, 2025Updated 10 months ago
- Stack integrity verification to Detect SleepMask or CallStack Spoofer☆53Jul 13, 2025Updated 7 months ago
- A work in progress of constructing a minimal http(s) beacon for Cobalt Strike.☆27Apr 28, 2022Updated 3 years ago
- Detect BypassUAC using AMSI☆29Feb 18, 2025Updated last year
- y4er的ysoserial修改版,加入mysql不出网pipe文件生成☆24Jan 30, 2026Updated last month
- Cobaltstrike UDRL with memory evasion☆15May 16, 2024Updated last year
- Extract entire function source code based on giving line number using Javaparser☆21Jul 15, 2025Updated 7 months ago
- ☆17Jun 16, 2025Updated 8 months ago
- 在线安软识别☆12Aug 6, 2025Updated 6 months ago
- Dumping LSASS Evaded Endpoint Security Solutions☆18Feb 15, 2025Updated last year
- 抽离出 utf-8-overlong-encoding 的序列化逻辑,实现 2 3 字节加密序列化数组☆139Mar 11, 2024Updated last year
- Kill Everything AV/EDR☆27Nov 18, 2024Updated last year
- ASPX ShellCode Loader☆54Jan 27, 2024Updated 2 years ago
- ☆28Aug 12, 2023Updated 2 years ago
- 此文件用于配套“卫界安全-阿呆攻防”中所涉及的代码类文档☆11Apr 26, 2025Updated 10 months ago
- Just a nice little shellcode loader using unconventional methods to avoid using signatured APIs☆23Jul 11, 2025Updated 7 months ago
- 通过JavaAgent与Javassist技术对JVM加载的类对象进行动态插桩,可以做一些破解、加密验证的绕过等操作☆116Jun 18, 2024Updated last year
- ☆79Nov 22, 2024Updated last year
- idea插件,快速生成反序列化中常用的方法,比如setFieldValue、createTemplatesImpl等☆29Oct 2, 2024Updated last year
- 用于快速启动tabby 分析漏洞或者gadget的环境☆94Jul 14, 2025Updated 7 months ago
- NTLM/Negotiate authentication over HTTP that supports Pass The Hash Mode (PtH)☆17Sep 13, 2024Updated last year
- ☆15Nov 24, 2022Updated 3 years ago
- Cobalt Strike Beacon Object File (BOF) that obtain SYSTEM privilege with SeImpersonate privilege by passing a malicious IUnknwon object t…☆13Feb 4, 2024Updated 2 years ago
- Basic Psexec clone, but in golang.☆16Jul 2, 2022Updated 3 years ago
- GitHubApi CVE Poc监控工具☆14Jan 23, 2026Updated last month
- A command-line tool for testing RocketMQ vulnerabilities.☆13Feb 7, 2025Updated last year
- A simple C2 using Google Translate Webpage for data evasion☆12Jan 30, 2023Updated 3 years ago
- A tool to assist DLL hijacking via the Havoc GUI☆12Jan 9, 2024Updated 2 years ago
- 寻找可注入进程☆13Jul 16, 2020Updated 5 years ago