CodeQL 寻找 JNDI利用 Lookup接口
☆166Apr 10, 2022Updated 3 years ago
Alternatives and similar repositories for LookupInterface
Users that are interested in LookupInterface are comparing it to the libraries listed below
Sorting:
- 动态链接库加载工具☆20Jan 26, 2022Updated 4 years ago
- Automatically scan jar packages by using ast to find fastjson gadgets. In particular, this project is limited to mining Gadgets that may …☆49Mar 8, 2022Updated 3 years ago
- CodeQL Java 全网最全的中文学习资料☆799Mar 18, 2022Updated 3 years ago
- JavaAgent内存马实现、检测、修复demo☆11Dec 7, 2022Updated 3 years ago
- JDBC Connection URL Attack☆438Sep 10, 2021Updated 4 years ago
- Java RCE 回显测试代码☆1,016Oct 15, 2020Updated 5 years ago
- Codeql学习笔记☆900Apr 25, 2022Updated 3 years ago
- 记录学习codeql的过程☆394Jun 9, 2023Updated 2 years ago
- 静态程序分析工具 主要生成方法的CFG和.java文件的AST☆132Jul 12, 2023Updated 2 years ago
- java内存对象搜索辅助工具☆823Sep 23, 2022Updated 3 years ago
- spring boot Fat Jar 任意写文件漏洞到稳定 RCE 利用技巧☆754Apr 14, 2021Updated 4 years ago
- 利用任意文件下载漏洞循环下载反编译 Class 文件获得网站 Java 源代码☆711May 10, 2021Updated 4 years ago
- notes☆27Oct 10, 2022Updated 3 years ago
- fastjson 1.2.68 版本 autotype bypass☆142Jun 17, 2022Updated 3 years ago
- Java漏洞学习笔记 Deserialization Vulnerability☆945Jun 14, 2023Updated 2 years ago
- ☆274Oct 28, 2021Updated 4 years ago
- ☆835Jun 7, 2022Updated 3 years ago
- (周瑜)Java - SpringBoot 持久化 WebShell(不仅仅是SpringBoot,适合任何符合JavaEE规范的服务)☆615Dec 29, 2021Updated 4 years ago
- Java反序列化漏洞利用链补全计划,仅用于个人归纳总结。☆420Dec 3, 2021Updated 4 years ago
- 卸载冰蝎内存马☆68Apr 13, 2021Updated 4 years ago
- 自动反编译闭源应用,创建codeql数据库☆316Mar 2, 2022Updated 3 years ago
- Some payloads of JNDI Injection in JDK 1.8.0_191+☆484Dec 9, 2020Updated 5 years ago
- 解决FastJson、Jackson、Log4j2、原生JNDI注入漏洞的高版本JDKBypass利用,探测本地可用反序列化gadget达到命令执行、回显命令执行、内存马注入☆770Jan 26, 2022Updated 4 years ago
- 基于反向代理的水坑部署工具☆261Dec 31, 2021Updated 4 years ago
- ☆294May 7, 2022Updated 3 years ago
- 当死去的记忆突然开始攻击我,我终于想起了我还写过一款十分十分垃圾的 rasp 靶场。☆87Jul 21, 2022Updated 3 years ago
- 一个cobaltstrike shellcode加载器,过国内主流杀软☆124May 21, 2021Updated 4 years ago
- 改造BeichenDream/InjectJDBC加入shiro获取key和修改key功能☆279Nov 28, 2023Updated 2 years ago
- 一个利用ASM对字节码进行污点传播分析的静态代码审计应用(添加了大量代码注释,适合大家进行源码学习)。也加入了挖掘Fastjson反序列化gadget chains和SQLInject(JdbcTemplate、MyBatis、JPA、Hibernate、原生jdbc等)静…☆458Mar 24, 2022Updated 3 years ago
- fastjson不出网利用、c3p0☆255Jul 30, 2021Updated 4 years ago
- 总结了20+.Net反序列化文章,持续更新☆748Apr 3, 2024Updated last year
- 适用于weblogic和Tomcat的无文件的内存马(memshell)☆269Mar 4, 2022Updated 3 years ago
- 这个脚本主要提供对Exchange邮件服务器的账户爆破功能,集成了现有主流接口的爆破方式。☆339May 22, 2023Updated 2 years ago
- ☆21Oct 7, 2022Updated 3 years ago
- WebLogic利用CVE-2020-2883打Shiro rememberMe反序列化漏洞,一键注册蚁剑filter内存shell☆535Aug 25, 2020Updated 5 years ago
- 基于Java实现的Shellcode加载器☆414Sep 4, 2023Updated 2 years ago
- 适合在命令行中使用的轻巧的SQL Server数据库安全检测工具☆431Oct 23, 2021Updated 4 years ago
- 大华智慧园区系统sso_initsession文件上传批量脚本☆21Sep 4, 2023Updated 2 years ago
- FilterBased/ServletBased in memory shell for Tomcat and some other middlewares☆383Nov 6, 2020Updated 5 years ago