HackJava / Spring
《Spring漏洞研究》
☆44Updated 2 years ago
Alternatives and similar repositories for Spring:
Users that are interested in Spring are comparing it to the libraries listed below
- CodeQL 寻找 JNDI利用 Lookup接口☆163Updated 2 years ago
- java☆54Updated 2 years ago
- Apache Dubbo Hessian2 CVE-2021-43297 demo☆46Updated 3 years ago
- 《JNDI-深入理解Java万恶之源》☆38Updated last year
- Java漏洞分析汇合☆142Updated 3 years ago
- Java命令行文件监控小工具(代码审计)☆100Updated 3 years ago
- 当死去的记忆突然开始攻击我,我终于想起了我还写过一款十分十分垃圾的 rasp 靶场。☆77Updated 2 years ago
- [fastjson 1.2.80] CVE-2022-25845 aspectj fileread & groovy remote classload☆91Updated 2 years ago
- springboot跨线程注入内存马☆115Updated 2 years ago
- A Go library for generating Java deserialization payloads.☆155Updated 5 months ago
- Spel-research☆26Updated 2 years ago
- ☁️Tencent Cloud AccessKey tools☆16Updated 7 months ago
- 一个简单的批量反编译jar包的小脚本☆35Updated 2 years ago
- Apache Dubbo漏洞测试Demo及其POC☆61Updated last year
- Java 内存马生成插件☆50Updated last year
- A vul-finder for loading CPG and automated finding vul-call-chains☆37Updated 4 months ago
- pyyso is a Python package that generate java serialized poc. Including CommonsCollections1-7, JDK7u21, JDK8u20, ldap for jndi, shiro-550,…☆50Updated 2 years ago
- 在原有yso基础上实现依赖分离,内存马注入等功能。A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.☆68Updated 3 years ago
- 一个Spring4Shell 被动式检测的Burp插件☆93Updated 2 years ago
- ☆51Updated 2 years ago
- ☆13Updated 2 years ago
- 收录go语言编写的项目、框架和组件出现的cve,或者一些相关的利用方式的文章☆37Updated 2 years ago
- ☆81Updated 3 years ago
- XxlJob<=2.1.2配置不当情况下反序列化RCE☆89Updated 4 years ago
- Web Cache Poisoning Vulnerability Scanner☆35Updated last month
- GO语言漏洞靶场 GIN框架 支持docker一键启动☆75Updated last year
- docker运行cs4.7server端☆39Updated 2 years ago
- The purpose of this script is to bypass disablefund, provide some useful information, and dig the hook function of PHP extension.☆14Updated 3 years ago
- 安服面经☞渗透测试/代码审计/安全研究☆26Updated 2 years ago
- fastjson 80 远程代码执行漏洞复现☆190Updated 2 years ago