一款基于污点分析的PHP扫描工具,能快速匹配从常见Source点如$_POST、$GET到Sink点system等的路径,同时支持单独对函数的扫描。
☆169Apr 10, 2025Updated 11 months ago
Alternatives and similar repositories for TaintScaner
Users that are interested in TaintScaner are comparing it to the libraries listed below
Sorting:
- 《深入JDBC安全:特殊URL构造与不出网反序列化利用技术揭秘》对应研究总结项目 "Deep Dive into JDBC Security: Special URL Construction and Non-Networked Deserialization Explo…☆572Feb 7, 2026Updated last month
- ctf awd比赛快速hook java题,提供一键流量转发,无痛修复☆56Mar 17, 2025Updated last year
- 一个基于 Vineflower 引擎的多线程 Java 批量反编译工具,支持快速处理大量的 class 文件和 JAR 文件。☆58Apr 28, 2025Updated 10 months ago
- JavaSec☆46Mar 18, 2024Updated 2 years ago
- 如何将Java反序列化Payload极致缩小☆70Jan 18, 2022Updated 4 years ago
- 一款轻量级匹配Sink点的代码审计扫描器,为了帮助红队过程中快速代码审计的小工具☆409Oct 6, 2024Updated last year
- A Java Route Collection Tool☆102Aug 1, 2024Updated last year
- Hessian UTF-8 Overlong Encoding☆21Mar 9, 2024Updated 2 years ago
- 某软最新公开gadgegt,新加入不出网利用。☆89Sep 6, 2024Updated last year
- Java Chains 插件编写 demo☆14Mar 5, 2025Updated last year
- 🔍 CodeAuditAssistant - JetBrains Code Audit Plugin (Beta) ⚡ Deep Call-Chain Tracking | 🚀 Method/Class Search | 🔥 Prebuilt Vuln Sink…☆781Updated this week
- CVE-2022-25845(fastjson1.2.80) exploit in Spring Env!☆107Nov 7, 2024Updated last year
- Some ReadObject Sink With JDBC☆243May 8, 2024Updated last year
- Java bytecode line number restoration tool☆135Aug 31, 2025Updated 6 months ago
- 阿里巴巴安全SDK,提供SSRF、JDBC、XXE防护能力☆118Oct 15, 2025Updated 5 months ago
- 抽离出 utf-8-overlong-encoding 的序列化逻辑,实现 2 3 字节加密序列化数组☆140Mar 11, 2024Updated 2 years ago
- 让"WAF绕过"变得简单☆432Jan 26, 2025Updated last year
- 一款专注于 Java 主流 Web 中间件的内存马快速生成工具,致力于简化安全研究人员和红队成员的工作流程,提升攻防效率☆1,355Mar 4, 2026Updated 2 weeks ago
- tsh多终端代理通信☆19Feb 26, 2025Updated last year
- Java Vulnerability Exploitation Platform☆1,998Jan 6, 2026Updated 2 months ago
- 记录自己在云安全上的学习笔记等。☆134Sep 18, 2024Updated last year
- Fenrir 是一个基于 MCP 协议与 AST 技术的代码审计工具,旨在解决安全研究与自动化代码审计领域中,面对大规模、结构复杂甚至反编译代码时,传统代码搜索与分析手段效率低、准确性差的问题。☆175Oct 21, 2025Updated 4 months ago
- JDBC Attack Tricks☆154Sep 3, 2023Updated 2 years ago
- A powerful JNDI injection exploitation framework that supports RMI, LDAP and LDAPS protocols, including various bypass methods for high-v…☆572Feb 4, 2026Updated last month
- 金蝶星空云反序列化漏洞内存马☆52Mar 27, 2024Updated last year
- 之前方便自己研究RASP原理和绕过时顺手写的,用于快速启动和重置RASP环境☆71Oct 13, 2024Updated last year
- 一款基于Zjackky/CodeScan的轻量级匹配Sink点并AI审计的代码审计扫描器☆247Feb 13, 2025Updated last year
- 闭源系统半自动漏洞挖掘工具,针对 jar/war/zip 进行静态代码分析,输出从source到sink的可达路径。LLM将验证路径可达性,并根据上下文给出该路径可信分数☆506Jan 12, 2026Updated 2 months ago
- 关于内存马的学习研究支持新手从0到1,从内存马原理,内存马植入 内存马检测 到内存马防御与内存马应急以及内存马查杀全系列java内存马/php/.net/c++/python 喜欢可以点个star 后续持续更新☆141Apr 24, 2024Updated last year
- 利用EFSRPC协议批量探测出网☆67Oct 12, 2023Updated 2 years ago
- 一些总结出来的gadget的flow,后续合适和加入新的flow☆67Dec 6, 2025Updated 3 months ago
- proof-of-concept for generating Java deserialization payload | Proxy MemShell☆222Jun 8, 2024Updated last year
- ☆206Oct 27, 2025Updated 4 months ago
- 新一代Webshell管理器,兼容蚁剑与冰蝎的PHP webshell☆672Feb 12, 2026Updated last month
- 用于快速启动tabby 分析漏洞或者gadget的环境☆94Jul 14, 2025Updated 8 months ago
- simpleIAST- 基于污点追踪的灰盒漏洞扫描工具。☆101Dec 23, 2025Updated 2 months ago
- 帆软报表漏洞检测工具☆114Jun 10, 2025Updated 9 months ago
- 综合后渗透方面的杂烩☆575Mar 1, 2026Updated 2 weeks ago
- 关于我在CTF中的所有东西☆423Sep 22, 2025Updated 5 months ago