Ape1ron / SpringAopInDeserializationDemo1
在spring-aop中新发现的反序列化gadget-chain
☆45Updated 4 months ago
Alternatives and similar repositories for SpringAopInDeserializationDemo1
Users that are interested in SpringAopInDeserializationDemo1 are comparing it to the libraries listed below
Sorting:
- 添加Connector内存马与ws内存马检测逻辑☆16Updated 2 years ago
- cve-2022-34169 延伸出的Jdk Xalan的payload自动生成工具,可根据不同的Jdk生成出其所对应的xslt文件☆90Updated 2 years ago
- Netty/WebFlux 内存马☆25Updated last year
- Automatically scan jar packages by using ast to find fastjson gadgets. In particular, this project is limited to mining Gadgets that may …☆50Updated 3 years ago
- A IntelliJ Plugin for Tabby to Find Vulnerabilities Easily☆34Updated 6 months ago
- ☆50Updated 2 years ago
- 如何将Java反序列化Payload极致缩小☆52Updated 3 years ago
- My security presentations☆28Updated last year
- ☆33Updated 2 years ago
- PoC of Apache Dubbo CVE-2023-23638☆31Updated last year
- JNDI/LDAP注入利用工具,对命令进行两种编码,支持多种绕过高版本JDK的方式(参考大佬代码造的轮子)☆44Updated 3 years ago
- [fastjson 1.2.80] CVE-2022-25845 aspectj fileread & groovy remote classload☆90Updated 2 years ago
- NoPacScan is a CVE-2021-42287/CVE-2021-42278 Scanner,it scan for more domain controllers than other script☆88Updated 3 years ago
- CVE-2020-4464 / CVE-2020-4450☆32Updated 3 years ago
- ☆19Updated 2 months ago
- Show the application of fuzzy in penetration test~☆13Updated 3 years ago
- CVE-2021-43297 POC,Apache Dubbo<= 2.7.13时可以实现RCE☆38Updated 3 years ago
- Java 内存马生成插件☆50Updated last year
- java☆54Updated 2 years ago
- Easy burp sign extension!☆55Updated 3 months ago
- Hessian UTF-8 Overlong Encoding☆18Updated last year
- Topic: The Swiss Army Knife of Java Exploitation☆22Updated 2 months ago
- This is a Cheatsheet for CTF Challenges categorized by different Privilege Escalation Methods☆22Updated 5 years ago
- 多组件客户端☆74Updated 2 weeks ago
- Collect JSP webshell of various implementation methods. 收集JSP Webshell的各种姿势☆15Updated 3 years ago
- Yapi mock script RCE another version. Webshell way. 另一种 Webshell 方式的 Yapi 命令执行的方法 相比于其他的利用方式 更加微操和可控 影响更小☆65Updated 10 months ago
- 安全升级jar包时,辅助检测Java Archive (JAR) 包之间兼容性☆14Updated 10 months ago
- 解密DBeaver数据库软件保存的密码☆29Updated last year
- Spring-Kafka-Deserialization-Remote-Code-Execution☆30Updated last year
- Spel-research☆26Updated 2 years ago