OpenRASP 漏洞测试环境
☆314Oct 31, 2023Updated 2 years ago
Alternatives and similar repositories for openrasp-testcases
Users that are interested in openrasp-testcases are comparing it to the libraries listed below
Sorting:
- 基于 Docker 的真实应用测试环境☆262Aug 14, 2023Updated 2 years ago
- IAST 灰盒扫描工具☆447Jul 19, 2022Updated 3 years ago
- java内存对象搜索辅 助工具☆823Sep 23, 2022Updated 3 years ago
- 整理收集Struts2漏洞环境☆270Jan 9, 2018Updated 8 years ago
- ☆835Jun 7, 2022Updated 3 years ago
- Collect JSP webshell of various implementation methods. 梳理和发现的JSP Webshell各种姿势☆1,404Jan 18, 2022Updated 4 years ago
- 在渗透测试中快速检测常见中间件、组件的高危漏洞。☆728Mar 21, 2022Updated 3 years ago
- Java web common vulnerabilities and security code which is base on springboot and spring security☆2,649Dec 2, 2024Updated last year
- Weblogic环境搭建工具☆796Apr 23, 2020Updated 5 years ago
- Burp被动扫描流量转发插件☆1,460Jun 17, 2024Updated last year
- Share Things Related to Java - Java安全漫谈笔记相关内容☆1,991Apr 9, 2025Updated 10 months ago
- Java-Web-Security - Sichere Webanwendungen mit Java entwickeln☆220Feb 19, 2026Updated last week
- Java RCE 回显测试代码☆1,016Oct 15, 2020Updated 5 years ago
- KunLun-M是一个完全开源的静态白盒扫描工具,支持PHP、JavaScript的语义扫描,基础安全、组件安全扫描,Chrome Ext\Solidity的基础扫描。☆2,379Jan 16, 2026Updated last month
- 自动扫描内网常见sql、no-sql数据库脚本(mysql、mssql、oracle、postgresql、redis、mongodb、memcached、elasticsearch),包含未授权访问及常规弱口令检测☆567Dec 1, 2017Updated 8 years ago
- 一个利用ASM对字节码进行污点传播分析的静态代码审计应用(添加了大量代码注释,适合大家进行源码学习)。也加入了挖掘Fastjson反序列化gadget chains和SQLInject(JdbcTemplate、MyBatis、JPA、Hibernate、原生jdbc等)静…☆458Mar 24, 2022Updated 3 years ago
- 360/0Kee-Team/crawlergo动态爬虫结合长亭XRAY扫描器的被动扫描功能☆1,183Nov 10, 2021Updated 4 years ago
- 用于辅助安全工程师漏洞挖掘、测试、复现,集合了mock、httplog、dns tools、xss,可用于测试各类无回显、无法直观判断或特定场景下的漏洞。☆866Jul 21, 2019Updated 6 years ago
- Java安全相关的漏洞和技术demo,原生Java、Fastjson、Jackson、Hessian2、XML反序列化漏洞利用和Spring、Dubbo、Shiro、CAS、Tomcat、RMI、Nexus等框架\中间件\功能的exploits以及Java Security…☆2,689Mar 14, 2024Updated last year
- 一个Mac下信息搜集小脚本 主要用于信息搜集/应急响应/检测挖矿进程/异常进程/异常启动项☆78Jul 21, 2020Updated 5 years ago
- 🔥Open source RASP solution☆2,953Oct 2, 2025Updated 5 months ago
- Burp suite 分块传输辅助插件☆2,023Feb 23, 2022Updated 4 years ago
- Java Agent is a Java application probe of DongTai IAST, which collects method invocation data during runtime of Java application by dynam…☆697Dec 25, 2023Updated 2 years ago
- 洞察-宜信集应用系统资产管理、漏洞全生命周期管理、安全知识库管理三位一体的平台。☆1,181Jan 12, 2021Updated 5 years ago
- weblogic t3 deserialization rce☆268Jul 13, 2017Updated 8 years ago
- Fastjson vulnerability quickly exploits the framework(fastjson漏洞快速利用框架)☆1,389Dec 16, 2022Updated 3 years ago
- JRE8u20_RCE_Gadget☆255Jul 1, 2016Updated 9 years ago
- a webshell resides in the memory of java web server☆699Jun 26, 2018Updated 7 years ago
- 绕过专业工具检测的Webshell研究文章和免杀的Webshell☆1,733Nov 15, 2020Updated 5 years ago
- 自己学习java安全的一些总结,主要是安全审计相关☆1,695Jan 5, 2022Updated 4 years ago
- 利用链、漏洞检测工具☆373Jul 31, 2024Updated last year
- Source Code Security Audit (源代码安全审计)☆3,188Sep 16, 2022Updated 3 years ago
- Java漏洞学习笔记 Deserialization Vulnerability☆945Jun 14, 2023Updated 2 years ago
- MySQL Fake Server use to help MySQL Client File Reading and JDBC Client Java Deserialize☆1,361Nov 18, 2021Updated 4 years ago
- 源代码漏洞の审计☆828Jul 2, 2024Updated last year
- 增强版WeblogicScan、检测结果更精确、插件化、添加CVE-2019-2618,CVE-2019-2729检测,Python3支持☆968Jun 16, 2024Updated last year
- Some payloads of JNDI Injection in JDK 1.8.0_191+☆484Dec 9, 2020Updated 5 years ago
- 适用于weblogic和Tomcat的无文件的内存马(memshell)☆269Mar 4, 2022Updated 4 years ago
- 无回显漏洞测试辅助平台,平台使用Java编写,提供DNSLOG,HTTPLOG等功能,辅助渗透测试过程中无回显漏洞及SSRF等漏洞的验证和利用。☆402Dec 21, 2025Updated 2 months ago