H3rmesk1t / Fastjson-Gadgets-Automatic-Scanner
Automatically scan jar packages by using ast to find fastjson gadgets. In particular, this project is limited to mining Gadgets that may be exploited, and screening results need to be excluded by themselves. Looking forward to Fork and Star.
☆50Updated 3 years ago
Alternatives and similar repositories for Fastjson-Gadgets-Automatic-Scanner:
Users that are interested in Fastjson-Gadgets-Automatic-Scanner are comparing it to the libraries listed below
- ☆50Updated 2 years ago
- java☆54Updated 2 years ago
- e-mesaage <=4.15 后台jar包上传exp☆47Updated 6 years ago
- NoPacScan is a CVE-2021-42287/CVE-2021-42278 Scanner,it scan for more domain controllers than other script☆86Updated 3 years ago
- 卸载冰蝎内存马☆67Updated 3 years ago
- [fastjson 1.2.80] CVE-2022-25845 aspectj fileread & groovy remote classload☆90Updated 2 years ago
- ☆42Updated 5 years ago
- CVE-2021-43297 POC,Apache Dubbo<= 2.7.13时可以实现RCE☆38Updated 3 years ago
- 一些结合第三方组件的Fastjson POC,在1.2.48以后版本中陆续被添加至黑名单。☆56Updated 5 years ago
- woodpecker-framework框架http发包库,专门为漏洞检测与利用场景设计。☆67Updated last year
- CVE-2021-4034, For Webshell Version.☆34Updated 3 years ago
- 该项目是通过go语言实现防止rmi利用被反置的问题。☆44Updated 3 years ago
- CVE-2015-4852、CVE-2016-0638、CVE-2016-3510、CVE-2019-2890漏洞POC☆17Updated 4 years ago
- jre8u20 gadget☆33Updated 3 years ago
- 2020年~2021年 网站CMS、中间件、框架系统漏洞集合☆36Updated 4 years ago
- mvn clean package -DskipTests☆46Updated last year
- ☆4Updated 4 years ago
- 利用shiro反序列化注入冰蝎内存马☆35Updated 3 years ago
- 在spring-aop中新发现的反序列化gadget-chain☆43Updated 2 months ago
- ThinkPHP各版本反序列化利用代码☆32Updated 4 years ago
- Spring Cloud Netflix Hystrix Dashboard template resolution vulnerability CVE-2021-22053☆37Updated 2 years ago
- 打CTF实在厌倦了找利用链,就知道一个fastjson的版本,一堆依赖找啊找,头都疼。为了解决这个烦恼,用了卓卓师傅的fastjson黑名单工具和库,自己改造了一下。☆32Updated 5 years ago
- 后台插件getshell☆49Updated 3 years ago
- ☆13Updated 2 years ago
- 魔改的冰蝎,仅供测试连接内存webshell使用☆38Updated 4 years ago
- CodeQL 寻找 JNDI利用 Lookup接口☆163Updated 2 years ago
- payloads☆15Updated 4 years ago
- ☆38Updated 4 years ago
- (批量化改造)sharpwmi是一个基于rpc的横向移动工具,具有上传文件和执行命令功能。☆107Updated 4 years ago
- 如何将Java反序列化Payload极致缩小☆48Updated 3 years ago