Ar3h / utf8-overlong-agentView external linksLinks
使用 agent 实现反序列化 utf8 overlong
☆83Apr 24, 2024Updated last year
Alternatives and similar repositories for utf8-overlong-agent
Users that are interested in utf8-overlong-agent are comparing it to the libraries listed below
Sorting:
- 一款支持自定义的 Java 回显载荷生成工具|A customizable Java echo payload generation tool.☆460Jan 12, 2025Updated last year
- 抽离出 utf-8-overlong-encoding 的序列化逻辑,实现 2 3 字节加密序列化数组☆139Mar 11, 2024Updated last year
- 用java实现构造openwire协议,利用activeMQ < 5.18.3 RCE 回显利用 内存马注入☆288Nov 20, 2023Updated 2 years ago
- 无需文件落地Agent内存马生成器☆248May 30, 2024Updated last year
- JavaPassDump☆272Jan 7, 2022Updated 4 years ago
- 用Go+Fyne开发的,展示JAVA序列化流以及集成一键插入脏数据,UTF过长编码绕WAF(Utf OverLoad Encoding),修改类SerializeVersionUID功能的图形化工具。☆125Jan 14, 2025Updated last year
- CVE-2023-22527 内存马注入工具☆76Feb 21, 2024Updated last year
- JavaGadgetGenerator 工具,支持 ysoserial,Hessian,字节码,Expr/SSTI,Shiro,JDBC 等 Gadget 生成,封装,混淆,出网延迟探测,内存马注入等...☆546Dec 7, 2025Updated 2 months ago
- woodpecker插件生成hessian利用payload☆20Sep 19, 2023Updated 2 years ago
- burp手工检测fastjson辅助☆88Mar 4, 2024Updated last year
- Hessian UTF-8 Overlong Encoding☆21Mar 9, 2024Updated last year
- Java Js Engine Payloads All in one☆289Aug 21, 2023Updated 2 years ago
- 基于 jdwp-shellifier 的进阶JDWP漏洞利用脚本(动态执行Java/Js代码并获得回显)☆321Dec 22, 2024Updated last year
- xxl-job内存马☆226Jan 26, 2025Updated last year
- 闭源系统半自动漏洞挖掘工具,针对 jar/war/zip 进行静态代码分析,输出从source到sink的可达路径。LLM将验证路径可达性,并根据上下文给出该路径可信分数☆503Jan 12, 2026Updated last month
- 用友的一些反序列化链子以及1day,二开了狼组的YongYouNcTool,改了一下逻辑以及poc☆123Oct 12, 2024Updated last year
- 一款Java内存马生成、测试工具,搭配@ax1sX的MemShell食用。☆260Jul 4, 2024Updated last year
- ☆306Feb 27, 2025Updated 11 months ago
- 记录一些代码审计过的源码☆182Feb 26, 2025Updated 11 months ago
- 亿赛通电子文档安全管理系统XStream反序列化漏洞任意文件上传利用☆120Aug 9, 2024Updated last year
- 适用于某EHR&HRM的加解密工具,可直接用于sqlmap☆25Jan 14, 2024Updated 2 years ago
- Some ReadObject Sink With JDBC☆243May 8, 2024Updated last year
- ☆122Jun 7, 2023Updated 2 years ago
- Common Exploitation Techniques for Java RCE Vulnerabilities in Real-World Scenarios | 实 战场景较通用的 Java Rce 相关漏洞的利用方式☆545Mar 6, 2025Updated 11 months ago
- A Java Route Collection Tool☆102Aug 1, 2024Updated last year
- Jar Obfuscator V2 - 一个 JAR 文件保护混淆工具,支持包名/类名/方法名/字段名/参数名引用分析和重命名混淆方式,支持字符串加密/整型异或混淆/垃圾代码花指令混淆/等方式,支持方法和字段的隐藏,支持 SpringBoot 和 war 包,配置简单,文档…☆429Sep 5, 2025Updated 5 months ago
- 80+ Gadgets(30 More than ysoserial). JNDI-Injection-Exploit-Plus is a tool for generating workable JNDI links and provide background serv…☆866Jun 24, 2024Updated last year
- 用Java agent实现内存马等功能☆197Jul 27, 2023Updated 2 years ago
- ☆36Mar 4, 2025Updated 11 months ago
- 入侵痕迹清理/Cleaning up traces of intrusion☆241Nov 6, 2024Updated last year
- ☆28Aug 12, 2023Updated 2 years ago
- JNDI在java高版本的利用工具,FUZZ利用链☆597Oct 8, 2022Updated 3 years ago
- nginx WebShell/内存马,更优雅的nignx backdoor☆325Jan 4, 2024Updated 2 years ago
- ☆79Nov 22, 2024Updated last year
- 收集内存马打入方式☆506May 20, 2022Updated 3 years ago
- 不那么一样的 Java Agent 内存马☆289Nov 27, 2023Updated 2 years ago
- 《深入JDBC安全:特殊URL构造与不出网反序列化利用技术揭秘》对应研究总结项目 "Deep Dive into JDBC Security: Special URL Construction and Non-Networked Deserialization Explo…☆569Updated this week
- Confluence CVE 2021,2022,2023 利用工具,支持命令执行,哥斯拉,冰蝎 内存马注入☆548Feb 1, 2024Updated 2 years ago
- 一个能够利用MSSQL的xp_cmdshell功能来进行流量代理的脚本,用于在站酷分离且不出网SQL注入进行代理☆107Sep 19, 2022Updated 3 years ago