Topic: The Swiss Army Knife of Java Exploitation
☆21Feb 25, 2025Updated last year
Alternatives and similar repositories for papers
Users that are interested in papers are comparing it to the libraries listed below
Sorting:
- ☆36Mar 4, 2025Updated last year
- y4er的ysoserial修改版,加入mysql不出网pipe文件生成☆25Mar 8, 2026Updated last week
- 哥斯拉 Suo5 一款高性能 HTTP 代理隧道工具☆15Sep 24, 2023Updated 2 years ago
- cloudflare socks5 server☆40Jul 18, 2025Updated 8 months ago
- AntSword 出网探测插件☆22Jul 6, 2022Updated 3 years ago
- php decrypt environment for study☆17Jan 10, 2024Updated 2 years ago
- ☆41Mar 12, 2025Updated last year
- 一款使用Yaml定义搜索规则来搜索Class的工具☆108Aug 2, 2023Updated 2 years ago
- PHP文件上传50+绕过手法全景解析☆17Mar 16, 2025Updated last year
- 关于GadgetInspector的二开的一些思考和改进。☆18Sep 4, 2023Updated 2 years ago
- Just mindmapping according to official document ( useful for further study )☆28May 20, 2022Updated 3 years ago
- 使用 Docker 一键构建 JDK 源码的 CodeQL 数据库,方便使用 CodeQL 查找 JDK 中的数据。☆27May 14, 2025Updated 10 months ago
- 抽离出 utf-8-overlong-encoding 的序列化逻辑,实现 2 3 字节加密序列化数组☆140Mar 11, 2024Updated 2 years ago
- PoC for CVE-2019-10207☆20Mar 27, 2022Updated 3 years ago
- Bypass JVM Class ByteCode Verifier , 对抗反编译器☆116Sep 21, 2023Updated 2 years ago
- 方便自己搭建codeql环境和数据库的工具。☆64Aug 16, 2025Updated 7 months ago
- Java JNI HellsGate/HalosGate/TartarusGate/RecycledGate/SSN Syscall/Many Shellcode Loaders☆196Jul 7, 2023Updated 2 years ago
- c3p0 new gadget☆28Apr 1, 2025Updated 11 months ago
- This is a patched version of ExchangeRelayX☆14Aug 13, 2020Updated 5 years ago
- Java表达式语句生成器☆194Oct 9, 2023Updated 2 years ago
- Ruby-SAML / GitLab Authentication Bypass (CVE-2024-45409) exploit☆83Oct 7, 2024Updated last year
- 用于快速启动tabby 分析漏洞或者gadget的环境☆94Jul 14, 2025Updated 8 months ago
- ☆53Mar 25, 2025Updated 11 months ago
- Code audit (code review) with VIM.☆17Jan 3, 2025Updated last year
- CVE-2022-25845(fastjson1.2.80) exploit in Spring Env!☆107Nov 7, 2024Updated last year
- record some AD security and Red Team contents☆14Dec 10, 2019Updated 6 years ago
- 利用agent hock指定的class,在jar运行周期内,用于跟踪被执行的方法,辅助做一些事情,比如挖洞啊☆125Jul 17, 2020Updated 5 years ago
- The source code of [S&P'25] Detecting Taint-Style Vulnerabilities in Microservice-Structured Web Applications.☆66Nov 20, 2025Updated 4 months ago
- Java bytecode line number restoration tool☆135Aug 31, 2025Updated 6 months ago
- CVE-2022-25636 exploit rewritten with pipe primitive☆20Apr 5, 2022Updated 3 years ago
- ysoserial for 1nhann☆11Sep 26, 2022Updated 3 years ago
- A VBA implementation of the RunPE technique or how to bypass application whitelisting.☆14Dec 30, 2018Updated 7 years ago
- FinalShellGetPass是一款FinalShell密码读取工具☆103Nov 27, 2022Updated 3 years ago
- Use the Netlogon Remote Protocol (MS-NRPC) to dump the target hash.☆62Feb 25, 2025Updated last year
- 使用 agent 实现反序列化 utf8 overlong☆84Apr 24, 2024Updated last year
- Common Exploitation Techniques for Java RCE Vulnerabilities in Real-World Scenarios | 实战场景较通用的 Java Rce 相关漏洞的利用方式☆544Mar 6, 2025Updated last year
- ☆147Jan 16, 2023Updated 3 years ago
- ☆309Feb 27, 2025Updated last year
- Memshell☆294Dec 7, 2021Updated 4 years ago