用于自动搜索 Python 沙箱逃逸、SSTI 攻击链的小工具
☆38Jan 22, 2025Updated last year
Alternatives and similar repositories for dibber
Users that are interested in dibber are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- xsleaks-wiki 中文版☆15May 31, 2022Updated 4 years ago
- A tool for converting Python source code to opcode(pickle)☆21Mar 19, 2026Updated 4 months ago
- 自动化的 Python 沙箱逃逸 payload bypass 框架 / Automated Python Sandbox(pyjail) Escape Payload Bypass Framework☆101Apr 5, 2026Updated 3 months ago
- 第十七届全国大学生信息安全竞赛创新实践能力赛决赛 - AWDP☆11Jul 20, 2024Updated 2 years ago
- ☆24Jul 2, 2024Updated 2 years ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- My presentation slides☆18Oct 31, 2025Updated 8 months ago
- 抽离出 utf-8-overlong-encoding 的序列化逻辑,实现 2 3 字节加密序列化数组☆141Mar 11, 2024Updated 2 years ago
- Hacking GraalVM Espresso - Abusing Continuation API to Make ROP-like Attack☆36Aug 27, 2025Updated 10 months ago
- CTF-Java-Gadget专注于收集CTF中Java赛题的反序列化片段☆288Dec 13, 2024Updated last year
- ☆31Sep 1, 2025Updated 10 months ago
- ☆16Aug 1, 2025Updated 11 months ago
- 一个基于 Vineflower 引擎的多线程 Java 批量反编译工具,支持快速处理大量的 class 文件和 JAR 文件。☆60Apr 28, 2025Updated last year
- websocket内存马类全版本构造样例☆17Jun 4, 2025Updated last year
- [Bugku-AWD专版]一款用于AWD比赛中的自动化攻击框架☆54Feb 4, 2022Updated 4 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- 用于快速启动tabby 分析漏洞或者gadget的环境☆92Jul 14, 2025Updated last year
- 关于我在CTF中的所有东西☆442Sep 22, 2025Updated 10 months ago
- 专为CTF设计的Jinja2 SSTI全自动绕WAF脚本 | A Jinja2 SSTI cracker for bypassing WAF, designed for CTF☆1,292Updated this week
- ☆98Sep 2, 2024Updated last year
- 一款全自动化弱口令检测工具☆18Aug 11, 2025Updated 11 months ago
- ☆16Apr 20, 2023Updated 3 years ago
- Java JDK 8-18 CodeQL databases☆17Jun 2, 2024Updated 2 years ago
- 高版本Fastjson在Java原生反序列化中的利用演示☆26Jan 12, 2025Updated last year
- A lab to help you learning SSTI☆126Aug 30, 2023Updated 2 years ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- 某软最新公开gadgegt,新加入不出网利用。☆90Sep 6, 2024Updated last year
- Many yaml scanner plugin parser [nuclei-template, xray-poc, ez-poc] - for Python☆14Mar 27, 2022Updated 4 years ago
- memory-shell for hook tcp connection and impl origin socks5 proxy☆44Aug 5, 2025Updated 11 months ago
- 阿里巴巴安全SDK,提供SSRF、JDBC、XXE防护能力☆117Oct 15, 2025Updated 9 months ago
- Extract entire function source code based on giving line number using Javaparser☆21Jul 15, 2025Updated last year
- 一些总结出来的gadget的flow,后续合适和加入新的flow☆68Dec 6, 2025Updated 7 months ago
- SUCTF 2026 归档☆32Mar 26, 2026Updated 3 months ago
- 手把手教你写IAST系列☆24Jan 12, 2024Updated 2 years ago
- ☆30Apr 6, 2022Updated 4 years ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- Official Writeup of SUCTF 2025☆67Feb 25, 2025Updated last year
- 收集整理漏洞EXP/POC,大部分漏洞来源网络,目前收集整理了900多个poc/exp,长期更新。☆46Jun 13, 2025Updated last year
- Fastjson + MySQL 条件下不出网利用测试环境☆51Dec 6, 2025Updated 7 months ago
- 一款基于污点分析的PHP扫描工具,能快速匹配从常见Source点如$_POST、$GET到Sink点system等的路径,同时支持单独对函数的扫描。☆175Apr 10, 2025Updated last year
- 0xGame 2023 challenges and writeups☆18Nov 7, 2023Updated 2 years ago
- Vulnerability database generator: a submodule for VUDDY☆14May 28, 2024Updated 2 years ago
- Apache OFBIZ Path traversal leading to RCE POC[CVE-2024-32113 & CVE-2024-36104]☆27Jun 3, 2024Updated 2 years ago