总结了一下2019年在JVM环境中使用XXE攻击的知识
☆58Oct 31, 2019Updated 6 years ago
Alternatives and similar repositories for java_xxe_2019
Users that are interested in java_xxe_2019 are comparing it to the libraries listed below
Sorting:
- CVE-2020-10199 回显版本☆31Jun 24, 2024Updated last year
- java xxe defense demo☆49Jul 18, 2019Updated 6 years ago
- Native Java serialization filter blacklist for common gadgets☆20Sep 12, 2019Updated 6 years ago
- Slides/Demos from the BSides Munich 2019 talk "Attacking Java RMI in 2019"☆101Sep 20, 2019Updated 6 years ago
- xray社区高级版证书生成,支持到 1.2.0 版本☆35Nov 21, 2020Updated 5 years ago
- 更快速的进行Web应用指纹识别☆171May 9, 2019Updated 6 years ago
- MySQL JDBC Deserialization Payload / MySQL客户端jdbc反序列化漏洞payload☆13Feb 8, 2020Updated 6 years ago
- ☆835Jun 7, 2022Updated 3 years ago
- 个人用于在自动化挖掘gadget时,方便查找gadget chains中class所在jar包,以助于便捷审计测试gadget有效性的那么一个小工具。☆60Mar 25, 2020Updated 5 years ago
- fastjson-1.2.61-RCE☆33Sep 26, 2019Updated 6 years ago
- A Java runtime information-gathering tool which uses the Java Attach API for information acquisition☆204Apr 26, 2021Updated 4 years ago
- 泛微ecology OA系统接口存在数据库配置信息泄露漏洞☆50Jul 13, 2020Updated 5 years ago
- ☆85Oct 8, 2019Updated 6 years ago
- A fastjson payload generator☆59Oct 13, 2020Updated 5 years ago
- CommonsBeanutils1,CommonsCollectionsK1☆58Nov 16, 2020Updated 5 years ago
- CVE-2019-2725 命令回显☆436May 8, 2023Updated 2 years ago
- 蚁剑其他脚本AES编/解码器☆36Aug 28, 2019Updated 6 years ago
- Spring Cloud SnakeYAML 反序列化一键注入cmdshell和reGeorg☆136Sep 24, 2020Updated 5 years ago
- 绿盟科技漏洞扫描器(RSAS)漏洞库☆367May 30, 2019Updated 6 years ago
- Citrix ADC从权限绕过到RCE☆45Jul 12, 2020Updated 5 years ago
- 一个轻量级、多线程、支持管道的自动化互联网漏洞挖掘框架。☆21Oct 30, 2018Updated 7 years ago
- cobalt strike 自启动脚本☆71Aug 23, 2016Updated 9 years ago
- tomcat使用了自带session同步功能时,不安全的配置(没有使用EncryptInterceptor)导致存在的反序列化漏洞,通过精心构造的数据包, 可以对使用了tomcat自带session同步功能的服务器进行攻击。PS:这个不是CVE-2020-9484,9484…☆212May 19, 2020Updated 5 years ago
- CVE-2019-11580 Atlassian Crowd and Crowd Data Center RCE☆106Jul 18, 2019Updated 6 years ago
- A BurpSuite extension written by Python,used to find API interface in JS file.☆114Mar 13, 2023Updated 3 years ago
- ☆16Jul 20, 2020Updated 5 years ago
- HackerOne Staffs☆29Dec 9, 2019Updated 6 years ago
- FasterXML/jackson-databind 远程代码执行漏洞☆73Feb 21, 2020Updated 6 years ago
- fastjson 1.2.68 版本 autotype bypass☆142Jun 17, 2022Updated 3 years ago
- mssql 终端连接工具|命令执行☆40Sep 29, 2019Updated 6 years ago
- 基于burpsuite headless 的代理式被动扫描系统☆95Feb 10, 2020Updated 6 years ago
- oauth2研究: 实现代码、漏洞利用、修复方案☆19May 21, 2019Updated 6 years ago
- Java-Web-Security - Sichere Webanwendungen mit Java entwickeln☆221Updated this week
- 从入门到放弃的产物,学习过程中用python实现的一个单点c2基本功能☆11Mar 11, 2020Updated 6 years ago
- RCE on Apache Solr using deserialization of untrusted data via jmx.serviceUrl☆210Mar 10, 2019Updated 7 years ago
- WeblogicScanLot系列,Weblogic漏洞批量检测工具,V2.2☆184Aug 1, 2020Updated 5 years ago
- Shiro RememberMe 1.2.4 反序列化 漏洞☆56Oct 25, 2019Updated 6 years ago
- linux内核提权后门模块demo☆36Jun 11, 2019Updated 6 years ago
- A fake JDBC driver that allows OS command execution.☆125Oct 2, 2022Updated 3 years ago