Maskhe / javasec
自己学习java安全的一些总结,主要是安全审计相关
☆1,608Updated 3 years ago
Alternatives and similar repositories for javasec:
Users that are interested in javasec are comparing it to the libraries listed below
- Share Things Related to Java - Java安全漫谈笔记相关内容☆1,823Updated 6 months ago
- a rep for documenting my study, may be from 0 to 0.1☆1,993Updated last month
- Getting started with java code auditing 代码审计入门的小项目☆905Updated 2 years ago
- JNDI服务利用工具 RMI/LDAP,支持部分场景回显、内存shell,高版本JDK场景下利用等,fastjson rce命令执行,log4j rce命令执行 漏洞检测辅助工具☆1,957Updated 9 months ago
- Fastjson姿势技巧集合☆1,716Updated last year
- ☆936Updated 4 months ago
- ☕️ Java Security,安全编码和代码审计☆1,472Updated 2 months ago
- 一款支持自定义的 Java 内存马生成工具|A customizable Java in-memory webshell generation tool.☆1,802Updated last month
- shiro反序列化漏洞综合利用,包含(回显执行命令/注入内存马)修复原版中NoCC的问题 https://github.com/j1anFen/shiro_attack☆2,148Updated 10 months ago
- MDUT - Multiple Database Utilization Tools☆2,062Updated last year
- Burp suite 分块传输辅助插件☆1,959Updated 3 years ago
- 项目是根据LandGrey/SpringBootVulExploit清单编写,目的hvv期间快速利用漏洞、降低漏洞利用门槛。☆1,845Updated last year
- 一款基于BurpSuite的被动式shiro检测插件☆1,712Updated 2 years ago
- 工欲善其事,必先利其器☆1,554Updated 3 years ago
- Java漏洞学习笔记 Deserialization Vulnerability☆926Updated last year
- 《Java安全-只有Java安全才能拯救宇宙》Only Java Security Can Save The Universe.☆2,672Updated last year
- HeapDump敏感信息提取工具☆1,389Updated 2 months ago
- Shiro550/Shiro721 一键化利用工具,支持多种回显方式☆1,919Updated 3 years ago
- shiro 反序列 命令执行辅助检测工具☆1,442Updated 9 months ago
- 一款红队在大量的资产中存活探测与重点攻击系统指纹探测工具☆1,617Updated last year
- Fastjson vulnerability quickly exploits the framework(fastjson漏洞快速利用框架)☆1,302Updated 2 years ago
- 基于 docsify 快速部署 Awesome-POC 中的漏洞文档☆1,753Updated this week
- OAExploit一款基于产品的一键扫描工具。☆1,468Updated 2 years ago
- Collect JSP webshell of various implementation methods. 收集JSP Webshell的各种姿势☆1,371Updated 3 years ago
- Burp被动扫描流量转发插件☆1,420Updated 8 months ago
- WeblogicTool,GUI漏洞利用工具,支持漏洞检测、命令执行、内存马注入、密码解密等(深信服深蓝实验室天威战队强力驱动)☆1,633Updated last year
- WebSocket 内存马/Webshell,一种新型内存马/WebShell技术☆1,431Updated last year
- domain_hunter的高级版本,SRC挖洞、HW打点之必备!自动化资产收集;快速Title获取;外部工具联动;等等☆2,011Updated this week
- 关于红队方面的学习资料☆1,279Updated last year
- A list for Web Security and Code Audit☆1,012Updated 3 months ago