Lonely-night / fastjson_gadgets_scannerLinks
☆131Updated 3 years ago
Alternatives and similar repositories for fastjson_gadgets_scanner
Users that are interested in fastjson_gadgets_scanner are comparing it to the libraries listed below
Sorting:
- SerialWriter is an incomplete implementation of Java serialization for study of Java deserialization vulnerabilities.☆103Updated 7 years ago
- Struts2 vuln env☆43Updated 3 years ago
- A modified reGeorg for One-line PHP Shell.☆86Updated 7 years ago
- Java Security Documents☆81Updated 6 years ago
- ☆146Updated 7 years ago
- fastjson-1.2.47☆67Updated 6 years ago
- ☆83Updated 8 years ago
- 🚀Faster Github Monitor🚀☆104Updated 3 years ago
- MySQL JDBC Deserialization Payload / MySQL客户端jdbc反序列化漏洞payload☆13Updated 5 years ago
- ☆57Updated 5 years ago
- RememberMe Padding Oracle Vulnerability RCE☆72Updated 6 years ago
- Java 反序列化学习的实验代码 Java_deserialize_vuln_lab☆87Updated 7 years ago
- java xxe defense demo☆49Updated 6 years ago
- ☆62Updated 5 years ago
- 个人用于在自动化挖掘gadget时,方便查找gadget chains中class所在jar包,以助于便捷审计测试gadget有效性的那么一个小工具。☆60Updated 5 years ago
- Java After-Deserialization Attack☆79Updated 4 years ago
- ☆153Updated 6 years ago
- tomcat使用了自带session同步功能时,不安全的配置(没有使用EncryptInterceptor)导致存在的反序列化漏洞,通过精心构造的数据包, 可以对使用了tomcat自带session同步功能的服务器进行攻击。PS:这个不是CVE-2020-9484,9484…☆212Updated 5 years ago
- PHP 扩展, 用于 PHP-FPM、FastCGI、LD_PRELOAD等模式下突破 disabled_functions☆106Updated 4 years ago
- Remote Command Execution Over Spark☆97Updated 8 years ago
- QAQ Just study unserialize vulnerabilities in Java :)☆197Updated 7 years ago
- kibana < 6.6.0 未授权远程代码命令执行 (Need Timelion And Canvas),CVE-2019-7609☆89Updated 6 years ago
- bypass JEP290 RaspHook code☆63Updated 5 years ago
- ☆44Updated 8 years ago
- Test repository for verifying compatibility between adjacent minor versions☆36Updated 10 months ago
- struts2 漏洞环境源代码☆75Updated 3 years ago
- A list of interesting payloads, tips and tricks for bug bounty hunters.☆24Updated 6 years ago
- python audit tool 审计 注入 inject☆34Updated 9 years ago
- VulHint是辅助代码审计的 sublime text 3 插件☆67Updated 7 years ago
- 总结了一下2019年在JVM环境中使用XXE攻击的知识☆58Updated 6 years ago