Whoopsunix / fastjson_study
Abandoned - fastjson 1.2.24-1.2.80 poc & vulns env & how to check vul
☆91Updated last year
Alternatives and similar repositories for fastjson_study:
Users that are interested in fastjson_study are comparing it to the libraries listed below
- 一款让你不只在dubbo-sample、vulhub或者其他测试环境里检测和利用成功的Apache Dubbo 漏洞检测工具。☆167Updated last year
- check hikvision/ys7 api☆70Updated last year
- evil-mysql-server is a malicious database written to target jdbc deserialization vulnerabilities and requires ysoserial.☆88Updated 2 years ago
- 内网集权系统渗透测试笔记☆12Updated 6 months ago
- Spring Actuator端点的BurpSuite被动扫描插件。☆196Updated 2 years ago
- 自己积累的一些Java反序列化利用链☆87Updated 2 years ago
- Java命令行文件监控小工具(代码审计)☆101Updated 3 years ago
- A Java Route Collection Tool☆92Updated 8 months ago
- 哥斯拉nacos后渗透插件 maketoken adduser☆144Updated last year
- Java CVE Vulnerability Environment☆22Updated 10 months ago
- fastjson 80 远程 代码执行漏洞复现☆192Updated 2 years ago
- 一键获取nacos中的配置文件信息和绘制密码本☆118Updated 9 months ago
- Struts2漏洞扫描 Burp插件☆131Updated 2 years ago
- CVE-2023-22527 内存马注入工具☆73Updated last year
- java实现反序列化建立socket连接☆58Updated 3 months ago
- JNDI注入测试工具内存马版本(增加了注入内存马模块)☆114Updated last year
- hrms tool☆63Updated 3 years ago
- Burp被动扫描流量转发插件☆73Updated 8 months ago
- 一款办公应用云凭证利用工具☆91Updated 10 months ago
- FastjsonScan4Burp 一款基于burp被动扫描的fastjson漏洞探测插件,可针对数据包中存在json的参数或请求体进行payload测试。旨在帮助安全人员更加便捷的发现、探测、深入利用fastjson漏洞,目前已实现fastjson探测、版本、依赖探测、出…☆100Updated last month
- Impacket GUI 让Impacket部分横向模块可视化操作,减少复杂指令☆104Updated last year
- ☆19Updated last year
- Apache RocketMQ 远程代码执行漏洞(CVE-2023-33246) Exploit☆104Updated last year
- 自己的JNDI 利用工具,添加一些人性化功能☆130Updated 2 years ago
- JavaSec☆30Updated last year
- CVE-2022-25845(fastjson1.2.80) exploit in Spring Env!☆89Updated 5 months ago
- 基于dbcp的fastjson rce 回显☆191Updated 3 years ago
- 通过jsp脚本扫描并查杀Tomcat内存马,当前支持Servlet-api、Tomcat-Value、Timer、Websocket 、Upgrade 、ExecutorShell内存马的查杀逻辑。☆53Updated 2 years ago
- 一个js文件敏感信息搜集脚本,支持输入url和js文件,也支持批量敏感信息匹配。☆77Updated 2 years ago
- 云环境利用框架(Cloud exploitation framework)主要用来方便红队人员在获得 AK 的后续工作。☆49Updated last year