XDU-SysSec / ExcessivePermissionAttack
Take Over the Whole Cluster: Attacking Kubernetes via Excessive Permissions of Third-party Applications
☆16Updated 11 months ago
Alternatives and similar repositories for ExcessivePermissionAttack:
Users that are interested in ExcessivePermissionAttack are comparing it to the libraries listed below
- Cloud Native Security News☆63Updated 3 months ago
- KernJC: Automated Vulnerable Environment Generation for Linux Kernel Vulnerabilities (Best Practical Paper Award of RAID 2024)☆59Updated 3 months ago
- ☆26Updated last year
- Auto-generated CodeQL rules for matching CVE vulnerabilities and variants.☆169Updated 7 months ago
- 一个搜索网络安全领域顶会论文的小工具☆86Updated 5 months ago
- 容器安全漏洞的分析与复现☆158Updated last year
- ☆166Updated 2 years ago
- ☆38Updated 2 years ago
- CVE-2022-0847 used to achieve container escape 利用CVE-2022-0847 (Dirty Pipe) 实现容器逃逸☆32Updated 2 years ago
- Container (Docker) escape exploits☆51Updated 3 years ago
- ☆128Updated last month
- A penetration toolkit for container environment☆77Updated 3 months ago
- ☆16Updated last year
- 《深入理解Semgrep》Finding vulnerabilities with Semgrep.☆48Updated last year
- 一个辅助提交 CNVD/CNNVD/CVE 漏洞的工具☆18Updated 2 years ago
- collections of container escape techniques 🐿☆68Updated 4 years ago
- ☆11Updated 2 weeks ago
- ☆24Updated 2 years ago
- ☆27Updated 2 years ago
- Artifact for ICSE 2023☆49Updated 2 years ago
- attachments and (some) writeups/source code for RWCTF 6th☆113Updated last year
- A grey-box web application Fuzzer☆23Updated 8 months ago
- Low-level RASP: Protecting Applications Implemented in High-level Programming Languages☆59Updated last year
- This repository is used to provide a reference for CTF dynamic target machine☆14Updated 2 years ago
- S&P2023 Paper☆39Updated 2 years ago
- ☆37Updated 3 years ago
- This project runs a Model Context Protocol (MCP) server that wraps the CodeQL query server. It enables tools like [Cursor](https://cursor…☆79Updated 3 weeks ago
- 基于污点分析的JSP Webshell检测工具,模拟JVM的栈帧操作进行数据流分析,可以检测出各种变形的JSP Webshell☆21Updated 3 years ago
- ☆64Updated last year
- Atropos: Effective Fuzzing of Web Applications for Server-Side Vulnerabilities☆67Updated 8 months ago