Hardw01f / Vulnerability-goapp
Web application build Golang with Vulnerability
☆251Updated 2 years ago
Alternatives and similar repositories for Vulnerability-goapp:
Users that are interested in Vulnerability-goapp are comparing it to the libraries listed below
- 个人笔记☆214Updated 4 years ago
- 用cel-go重现了长亭xray的poc检测功能的轮子☆294Updated 2 years ago
- ☆160Updated 2 years ago
- ☆212Updated 5 months ago
- 一个由长亭自研,直观而可扩展的容器安全 SDK☆119Updated last year
- 利用链、漏洞检测工具☆367Updated 6 months ago
- codemillx is a tool for CodeQL, extract the comments in the code and generate codeql module. 强化Go开源项目安全检测(内含开源项目漏洞挖掘方法)☆205Updated 2 years ago
- XSS discovery tool☆202Updated 2 years ago
- IAST 灰盒扫描工具☆444Updated 2 years ago
- 🧬 辅助生成 XRay YAML POC☆263Updated 2 years ago
- python 代码审计项目☆283Updated 3 years ago
- 一个利用ASM对字节码进行污点传播分析的静态代码审计应用(添加了大量代码注释,适合大家进行源码学习)。也加入了挖掘Fastjson反序列化gadget chains和SQLInject(JdbcTemplate、MyBatis、JPA、Hibernate、原生jdbc等)静…☆446Updated 2 years ago
- An awesome reverse engine for xray poc. | 一个自动化根据 xray poc 生成对应靶站的工具☆410Updated last year
- 笔记☆9Updated last month
- RMI 反序列化环境 一步步☆211Updated 4 years ago
- 内存马Demo合集 memshell demo for java / php / python☆407Updated 3 years ago
- 用于漏洞排查的pocsuite3验证POC代码☆348Updated 2 years ago
- 通用的指纹识别 规则☆368Updated 2 years ago
- CVE Data Analysis, CVE Monitor, CVE EXP Prediction Based on Deep Learning. 1999-2020年存量CVE数据分析、监控CVE增量更新、基于深度学习的CVE EXP预测和自动化推送☆175Updated last year
- A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.优化了一些东西。☆215Updated 3 years ago
- tomcat使用了自带session同步功能时,不安全的配置(没有使用EncryptInterceptor)导致存在的反序列化漏洞,通过精心构造的数据包, 可以对使用了tomcat自带session同步功能的服务器进行 攻击。PS:这个不是CVE-2020-9484,9484…☆213Updated 4 years ago
- Struts2漏洞实例源码☆205Updated 4 years ago
- k0otkit is a universal post-penetration technique which could be used in penetrations against Kubernetes clusters.☆281Updated 3 years ago
- 一款通过污点追踪发现Jsp webshell的工具(A tool to find Jsp Webshell through stain tracking)☆175Updated 3 years ago
- rmi、jndi、ldap、jrmp、jmx、jms一些demo测试☆306Updated 2 years ago
- An exquisite dns&http log server for verify SSRF/XXE/RFI/RCE vulnerability☆467Updated last year
- Chrome 蜜罐检测插件☆297Updated 4 years ago
- Security & Development☆263Updated last year
- A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.☆353Updated 2 years ago
- 基于AST的JSONP劫持漏洞自动化挖掘☆93Updated 4 years ago