关于Struts2框架的历史漏洞个人分析文章
☆54Jun 17, 2020Updated 5 years ago
Alternatives and similar repositories for Struts2-Vuln
Users that are interested in Struts2-Vuln are comparing it to the libraries listed below
Sorting:
- fastjson 1.2.68 版本 autotype bypass☆142Jun 17, 2022Updated 3 years ago
- Thinkphp rce扫描脚本,附带日志扫描☆241Jun 19, 2020Updated 5 years ago
- Weblogic环境搭建工具☆796Apr 23, 2020Updated 5 years ago
- 整理收集Struts2漏洞环境☆270Jan 9, 2018Updated 8 years ago
- 关于ThinkPHP框架的历史漏洞分析集合☆1,118Jan 18, 2020Updated 6 years ago
- rmi、jndi、ldap、jrmp、jmx、jms一些demo测试☆310Jun 17, 2022Updated 3 years ago
- 卸载冰蝎内存马☆68Apr 13, 2021Updated 4 years ago
- 一款用于攻击spring boot actuator的集成环境,目前集成三种攻击方式,支持1.x、2.x☆86Jul 26, 2021Updated 4 years ago
- Shiro反序列化回显利用、内存shell、检查 Burp插件☆217Sep 1, 2022Updated 3 years ago
- JNDI注入测试工具改版(A tool which generates JNDI links can start several servers to exploit JNDI Injection vulnerability,like Jackson,Fastjson,et…☆49Nov 14, 2020Updated 5 years ago
- a AWVS12 api tool☆119Aug 30, 2020Updated 5 years ago
- a Burp Extender that add an random X-Forward-For IP address for each request☆31Aug 12, 2016Updated 9 years ago
- Fastjson <= 1.2.47 远程命令执行漏洞利用工具及方法☆400Jan 24, 2025Updated last year
- Behinder3.0 Beta4 源码(Decompile and Fixed)☆207Sep 1, 2020Updated 5 years ago
- 通过gzip一边压缩一边使用tcp上传文件夹。☆17Nov 12, 2022Updated 3 years ago
- 使得Cobaltstrike支持Atexec☆89Jun 30, 2020Updated 5 years ago
- ☆318Jun 4, 2021Updated 4 years ago
- 几条关于CVE-2020-15148(yii2反序列化)的绕过☆75Sep 21, 2020Updated 5 years ago
- 在渗透测试中快速检测常见中间件、组件的高危漏洞。☆728Mar 21, 2022Updated 3 years ago
- JavaAgent内存马实现、检测、修复demo☆11Dec 7, 2022Updated 3 years ago
- Windows杀软在线对比辅助☆288Jul 26, 2022Updated 3 years ago
- 帮助java环境下任意文件下载情况自动化读取源码的小工具☆167Apr 5, 2019Updated 6 years ago
- 一款渗透时快速资产探测工具☆220Sep 17, 2021Updated 4 years ago
- Struts2漏洞实例源码☆209Dec 25, 2020Updated 5 years ago
- 此脚本用于测试 Rdies 未授权访问,在没权限写ssh私钥和定时任务又不知道web绝对路径的情况下,进行WEB目录探测☆73May 3, 2019Updated 6 years ago
- ☆198Sep 26, 2024Updated last year
- CodeQL 寻找 JNDI利用 Lookup接口☆166Apr 10, 2022Updated 3 years ago
- ☆11Mar 14, 2019Updated 6 years ago
- ☆13Feb 1, 2024Updated 2 years ago
- xray社区高级版证书生成,仅供学习研究,正常使用请支持正版。removed due to Chaitin requirements & support to version 1.4.4 & learning purpose☆443Nov 11, 2020Updated 5 years ago
- RMI 反序列化环境 一步步☆213Aug 31, 2020Updated 5 years ago
- 修改的SweetPotato,使之可以用于CobaltStrike v4.0☆246Apr 30, 2020Updated 5 years ago
- 创建服务持久化☆108Apr 26, 2021Updated 4 years ago
- 记录各语言、框架中危险的sink,个人代码审计、漏洞研究使用。☆117Dec 30, 2021Updated 4 years ago
- PocHubs是为了整合网上知名开源框架的漏洞详细和POC☆230Jun 19, 2019Updated 6 years ago
- WebLogic利用CVE-2020-2883打Shiro rememberMe反序列化漏洞,一键注册蚁剑filter内存shell☆535Aug 25, 2020Updated 5 years ago
- xss漏洞模糊测试payload的最佳集合 2020版☆511May 25, 2020Updated 5 years ago
- 通过NetSessionEnum获取域内机器对应用户☆67May 6, 2020Updated 5 years ago
- JCE - JSP/JPSX CodeEncode - 用于 Webshell 逃避静态查杀的辅助脚本☆258Oct 29, 2021Updated 4 years ago