CodeQL 寻找 JNDI利用 Lookup接口
☆166Apr 10, 2022Updated 3 years ago
Alternatives and similar repositories for LookupInterface
Users that are interested in LookupInterface are comparing it to the libraries listed below
Sorting:
- 动态链接库加载工具☆20Jan 26, 2022Updated 4 years ago
- Automatically scan jar packages by using ast to find fastjson gadgets. In particular, this project is limited to mining Gadgets that may …☆49Mar 8, 2022Updated 4 years ago
- CodeQL Java 全网最全的中文学习资料☆799Mar 18, 2022Updated 4 years ago
- 静态程序分析工具 主要生成方法的CFG和.java文件的AST☆133Jul 12, 2023Updated 2 years ago
- Java漏洞学习笔记 Deserialization Vulnerability☆946Jun 14, 2023Updated 2 years ago
- JavaAgent内存马实现、检测、修复demo☆11Dec 7, 2022Updated 3 years ago
- Java RCE 回显测试代码☆1,015Oct 15, 2020Updated 5 years ago
- JDBC Connection URL Attack☆441Sep 10, 2021Updated 4 years ago
- Codeql学习笔记☆899Apr 25, 2022Updated 3 years ago
- java内存对象搜索辅助工具☆823Sep 23, 2022Updated 3 years ago
- 记录学习codeql的过程☆395Jun 9, 2023Updated 2 years ago
- fastjson 1.2.68 版本 autotype bypass☆142Jun 17, 2022Updated 3 years ago
- spring boot Fat Jar 任意写文件漏洞到稳定 RCE 利用技巧☆754Apr 14, 2021Updated 4 years ago
- 改造BeichenDream/InjectJDBC加入shiro获取key和修改key功能☆279Nov 28, 2023Updated 2 years ago
- ☆275Oct 28, 2021Updated 4 years ago
- <a href="sumsec.me"><img src="https://readme-typing-svg.demolab.com?font=Fira+Code&size=24&pause=1000&color=FDFDFD&background=13797800&ce…☆56Updated this week
- (周瑜)Java - SpringBoot 持久化 WebShell(不仅仅是SpringBoot,适合任何 符合JavaEE规范的服务)☆614Dec 29, 2021Updated 4 years ago
- 蓝凌OA漏洞利用工具/前台无条件RCE/文件写入☆19Jun 29, 2021Updated 4 years ago
- 利用任意文件下载漏洞循环下载反编译 Class 文件获得网站 Java 源代码☆712May 10, 2021Updated 4 years ago
- notes☆27Oct 10, 2022Updated 3 years ago
- ☆835Jun 7, 2022Updated 3 years ago
- Java反序列化漏洞利用链补全计划,仅用于个人归纳总结。☆420Dec 3, 2021Updated 4 years ago
- 一个利用ASM对字节码进行污点传播分析的静态代码审计应用(添加了大量代码注释,适合大家进行源码学习)。也加入了挖掘Fastjson反序列化gadget chains和SQLInject(JdbcTemplate、MyBatis、JPA、Hibernate、原生jdbc等)静…☆458Mar 24, 2022Updated 3 years ago
- 卸载冰蝎内存马☆68Apr 13, 2021Updated 4 years ago
- ZipCreater主要应用于跨目录的文件上传漏洞的利用,它能够快速进行压缩包生成。☆187Apr 6, 2022Updated 3 years ago
- 🐛糊涂虫工具箱 About The Project https://sumsec.me/2022/Hack-Tools2Web.html☆49Jun 12, 2022Updated 3 years ago
- Bypass 403 or 401 or 404☆101Feb 8, 2021Updated 5 years ago
- 自动反编译闭源应用,创建codeql数据库☆316Mar 2, 2022Updated 4 years ago
- 🚀 一款为了学习go而诞生的漏洞利用工具☆450Jun 14, 2022Updated 3 years ago
- BurpBounty插件的配置文件收集项目☆144Feb 8, 2021Updated 5 years ago
- ☆21Oct 7, 2022Updated 3 years ago
- fastjson不出网利用、c3p0☆256Jul 30, 2021Updated 4 years ago
- Unofficial Dockerfile and scripts for building CodeQL databases for the OpenJDK☆49Jan 7, 2024Updated 2 years ago
- 解决FastJson、Jackson、Log4j2、原生JNDI注入漏洞的高版本JDKBypass利用,探测本地可用反序列化gadget达到 命令执行、回显命令执行、内存马注入☆770Jan 26, 2022Updated 4 years ago
- 当死去的记忆突然开始攻击我,我终于想起了我还写过一款十分十分垃圾的 rasp 靶场。☆88Jul 21, 2022Updated 3 years ago
- Shiro-550 不依赖CC链利用工具☆450Jun 19, 2024Updated last year
- 一个cobaltstrike shellcode加载器,过国内主流杀软☆124May 21, 2021Updated 4 years ago
- 静态分析笔记 Static-Analysis-Notes 程序分析笔记 资源分享☆187Jan 11, 2023Updated 3 years ago
- 基于反向代理的水坑部署工具☆263Dec 31, 2021Updated 4 years ago