Y4er / yaml-payload
Spring Cloud SnakeYAML 反序列化一键注入cmdshell和reGeorg
☆133Updated 4 years ago
Alternatives and similar repositories for yaml-payload:
Users that are interested in yaml-payload are comparing it to the libraries listed below
- WIP: Demo for Attacking Apereo CAS☆89Updated 4 years ago
- Apache Shiro 反序列化漏洞检测与利用工具,一键注入内存马☆138Updated 4 years ago
- SpringBoot Actuator未授权自动化利用,支持信息泄漏/RCE☆231Updated 4 years ago
- GUI Exploit Tool For RedTeam☆7Updated 3 years ago
- woodpecker框架weblogic信息探测插件☆179Updated 2 years ago
- ☆81Updated 3 years ago
- fastjson不出网利用、c3p0☆251Updated 3 years ago
- This tool generates gopher link for exploiting SSRF and gaining RCE in redis with password.用于生成附带密码认证的gopher内容,用于SSRF等利用。☆113Updated 5 years ago
- Source code of Behinder, a shell manager.冰蝎源码,反编译,当前版本3.0 Beta6,支持内存马注入☆90Updated 3 years ago
- 利用字符集编码绕过waf的burpsuite插件☆117Updated 3 years ago
- 用于WebLogic poc及exp测试的基础脚本,后续将集成各版本poc库☆93Updated 4 years ago
- JumpServer远程代码执行漏洞检测利用脚本☆198Updated 4 years ago
- xxl-job未授权命令执行☆105Updated 3 years ago
- 中国蚁剑JSP一句话Payload☆121Updated 4 years ago
- 蓝凌OA的前后台密码的加解密工具☆94Updated 4 years ago
- 🐸fingerprint detect framework 批量深度指纹识别框架☆119Updated 2 years ago
- 利用长亭xray高级版的回显Gadget重写的一个shiro反序列化利用工具。☆122Updated 4 years ago
- 泛微OA_V9全版本的SQL远程代码执行漏洞☆157Updated 2 years ago
- ☆83Updated 4 years ago
- cve-2020-1472 复现利用及其exp☆109Updated 4 years ago
- ☆282Updated 2 years ago
- fastjson 1.2.68 版本 autotype bypass☆140Updated 2 years ago
- 适用于weblogic和Tomcat的无文件的内存 马(memshell)☆266Updated 3 years ago
- DSO-Lab 漏洞研究成果整理☆82Updated 2 years ago
- 阿里云AccessKey泄漏利用工具☆146Updated 3 years ago
- 进行克隆用户、添加用户等账户防护安全检测的轻巧工具☆174Updated 3 years ago
- SMTP Netcat , test SMTP protocol☆105Updated 3 years ago
- fastjson 80 远程代码执行漏洞复现☆191Updated 2 years ago
- 当死去的记忆突然开始攻击我,我终于想起了我还写过一款十分十分垃圾的 rasp 靶场。☆78Updated 2 years ago
- 使用java agent反序列化注入内存shell☆67Updated 4 years ago