总结了一下2019年在JVM环境中使用XXE攻击的知识
☆58Oct 31, 2019Updated 6 years ago
Alternatives and similar repositories for java_xxe_2019
Users that are interested in java_xxe_2019 are comparing it to the libraries listed below
Sorting:
- CVE-2020-10199 回显版本☆31Jun 24, 2024Updated last year
- Native Java serialization filter blacklist for common gadgets☆20Sep 12, 2019Updated 6 years ago
- java xxe defense demo☆49Jul 18, 2019Updated 6 years ago
- xray社区高级版证书生成,支持到 1.2.0 版本☆35Nov 21, 2020Updated 5 years ago
- 更快速的进行Web应用指纹识别☆170May 9, 2019Updated 6 years ago
- fastjson-1.2.61-RCE☆33Sep 26, 2019Updated 6 years ago
- Slides/Demos from the BSides Munich 2019 talk "Attacking Java RMI in 2019"☆101Sep 20, 2019Updated 6 years ago
- MySQL JDBC Deserialization Payload / MySQL客户端jdbc反序列化漏洞payload☆13Feb 8, 2020Updated 6 years ago
- 蚁剑其他脚本AES编/解码器☆36Aug 28, 2019Updated 6 years ago
- 泛微ecology OA系统接口存在数据库配置信息泄露漏洞☆50Jul 13, 2020Updated 5 years ago
- CVE-2019-11580 Atlassian Crowd and Crowd Data Center RCE☆106Jul 18, 2019Updated 6 years ago
- ☆85Oct 8, 2019Updated 6 years ago
- cobalt strike 自启动脚本☆71Aug 23, 2016Updated 9 years ago
- Spring Cloud SnakeYAML 反序列化一键注入cmdshell和reGeorg☆135Sep 24, 2020Updated 5 years ago
- A fastjson payload generator☆59Oct 13, 2020Updated 5 years ago
- A Java runtime information-gathering tool which uses the Java Attach API for information acquisition☆204Apr 26, 2021Updated 4 years ago
- linux内核提权后门模块demo☆36Jun 11, 2019Updated 6 years ago
- CommonsBeanutils1,CommonsCollectionsK1☆58Nov 16, 2020Updated 5 years ago
- ☆835Jun 7, 2022Updated 3 years ago
- FasterXML/jackson-databind 远程代码执行漏洞☆73Feb 21, 2020Updated 6 years ago
- CVE-2019-2725 命令回显☆436May 8, 2023Updated 2 years ago
- Citrix ADC从权限绕过到RCE☆45Jul 12, 2020Updated 5 years ago
- fastjson 1.2.68 版本 autotype bypass☆142Jun 17, 2022Updated 3 years ago
- 绿盟科技漏洞扫描器(RSAS)漏洞库☆366May 30, 2019Updated 6 years ago
- WeblogicScanLot系列 ,Weblogic漏洞批量检测工具,V2.2☆184Aug 1, 2020Updated 5 years ago
- HackerOne Staffs☆29Dec 9, 2019Updated 6 years ago
- 个人用于在自动化挖掘gadget时,方便查找gadget chains中class所在jar包,以助于便捷审计测试gadget有效性的那么一个小工具。☆60Mar 25, 2020Updated 5 years ago
- 一个轻量级、多线程、支持管道的自动化互联网漏洞挖掘框架。☆21Oct 30, 2018Updated 7 years ago
- ☆16Jul 25, 2023Updated 2 years ago
- Shiro RememberMe 1.2.4 反序列化 漏洞☆56Oct 25, 2019Updated 6 years ago
- 基于burpsuite headless 的代理式被动扫描系统☆95Feb 10, 2020Updated 6 years ago
- ThinkCMF 框架上的任意内容包含漏洞☆36Oct 28, 2019Updated 6 years ago
- tomcat使用了自带session同步功能时,不安全的配置(没有使用EncryptInterceptor)导致存在的反序列化漏洞,通过精心构造的数据包, 可以对使用了tomcat自带session同步功能的服务器进行攻击。PS:这个不是CVE-2020-9484,9484…☆212May 19, 2020Updated 5 years ago
- Reference:https://www.w2n1ck.com/article/44/☆155Mar 7, 2020Updated 5 years ago
- A JSP backdoor that enables under Tomcat hiding arbitrary JSP files, in addition to their access logs.☆216Mar 31, 2019Updated 6 years ago
- Web Security Technology & Vulnerability Analysis Whitepapers☆549Jan 1, 2019Updated 7 years ago
- Java层frida hook学习笔记 https://uknowsec.cn☆47Feb 6, 2020Updated 6 years ago
- Shiro-721 RCE Via RememberMe Padding Oracle Attack☆269Oct 29, 2020Updated 5 years ago
- Apache Tomcat + MongoDB Remote Code Execution☆113Jan 15, 2021Updated 5 years ago