Java 反序列化学习的实验代码 Java_deserialize_vuln_lab
☆87Nov 26, 2018Updated 7 years ago
Alternatives and similar repositories for Java_deserialize_vuln_lab
Users that are interested in Java_deserialize_vuln_lab are comparing it to the libraries listed below
Sorting:
- ☆22Sep 26, 2017Updated 8 years ago
- QAQ Just study unserialize vulnerabilities in Java :)☆196Aug 22, 2018Updated 7 years ago
- 用WebShell攻击PHP-FPM Attacking PHP-FPM with WebShell☆41May 6, 2021Updated 4 years ago
- F-NAScan-PLUS 安服资产搜集☆142Feb 16, 2021Updated 5 years ago
- fastjson remote code execute poc 直接用intellij IDEA打开即可 首先编译得到Test.class,然后运行Poc.java☆403Dec 16, 2022Updated 3 years ago
- 使得Cobaltstrike支持Atexec☆89Jun 30, 2020Updated 5 years ago
- JRE8u20_RCE_Gadget☆255Jul 1, 2016Updated 9 years ago
- 一个利用ASM对字节码进行污点传播分析的静态代码审计应用(添加了大量代码注释,适合大家进行源码学习)。也加入了挖掘Fastjson反序列化gadget chains和SQLInject(JdbcTemplate、MyBatis、JPA、Hibernate、原生jdbc等)静…☆458Mar 24, 2022Updated 3 years ago
- Java通用漏洞修复安全组件☆60Jul 12, 2025Updated 7 months ago
- Web Security Technology & Vulnerability Analysis Whitepapers☆549Jan 1, 2019Updated 7 years ago
- Java层frida hook学习笔记 https://uknowsec.cn☆47Feb 6, 2020Updated 6 years ago
- 通过脉脉用户猜测企业邮箱☆238May 7, 2020Updated 5 years ago
- HackerOne Staffs☆29Dec 9, 2019Updated 6 years ago
- 安全相关思维导图收集整理☆17Apr 16, 2019Updated 6 years ago
- flash 劫持轮子,CSRF,劫持,跳转,swf 有需求可以提issues ,src挖掘,劫持response☆86Nov 9, 2019Updated 6 years ago
- 分享在建设安全管理体系、ISO27001、等级保护、安全评审过程中的点点滴滴☆23Aug 27, 2018Updated 7 years ago
- rmi、jndi、ldap、jrmp、jmx、jms一些demo测试☆310Jun 17, 2022Updated 3 years ago
- 把jsp的cmdshell升级为冰蝎一句话☆11Sep 23, 2019Updated 6 years ago
- a webshell resides in the memory of java web server☆700Jun 26, 2018Updated 7 years ago
- PHP 白盒分析工具,结合AST 和数据流跟踪分析代码,达到自动化白盒审计功 能☆148May 14, 2018Updated 7 years ago
- ☆41Nov 9, 2018Updated 7 years ago
- 一款基于webshell命令执行功能实现的GUI webshell管理工具,支持流量加密☆218Jun 4, 2021Updated 4 years ago
- 一款简易的插件化的漏洞扫描器框架☆67Sep 23, 2018Updated 7 years ago
- docker 安全基线规范☆91Jun 27, 2018Updated 7 years ago
- ☆37Aug 25, 2020Updated 5 years ago
- 蚁剑其他脚本AES编/解码器☆36Aug 28, 2019Updated 6 years ago
- ssrf、ssrfIntranetFuzz、dnsRebinding、recordEncode、dnsPoisoning、Support ipv4/ipv6☆217Aug 17, 2017Updated 8 years ago
- 整理收集Struts2漏洞环境☆270Jan 9, 2018Updated 8 years ago
- Java RCE 回显测试代码☆1,016Oct 15, 2020Updated 5 years ago
- 一个各种方式突破Disable_functions达到命令执行的shell☆1,198Oct 17, 2023Updated 2 years ago
- python3 写的一些权限维持脚本☆38Feb 10, 2020Updated 6 years ago
- Fastjson vulnerability quickly exploits the framework(fastjson漏洞快速利用框架)☆1,388Dec 16, 2022Updated 3 years ago
- java内存对象搜索辅助工具☆823Sep 23, 2022Updated 3 years ago
- Slides/Demos from the BSides Munich 2019 talk "Attacking Java RMI in 2019"☆101Sep 20, 2019Updated 6 years ago
- A fake JDBC driver that allows OS command execution.☆125Oct 2, 2022Updated 3 years ago
- reGeorg的特殊版本,适用于老版本weblogic。☆151Apr 30, 2020Updated 5 years ago
- Spring Boot Actuator (jolokia) XXE/RCE☆324Jun 16, 2020Updated 5 years ago
- Use to perform Microsoft exchange account brute-force.☆73Apr 17, 2021Updated 4 years ago
- Python2编写的struts2漏洞全版本检测和利用工具☆1,419May 7, 2019Updated 6 years ago