bkfish / Awesome_shiro
CVE-2016-4437-Shiro反序列化爆破模块和key,命令执行,反弹shell的脚本
☆55Updated 4 years ago
Alternatives and similar repositories for Awesome_shiro:
Users that are interested in Awesome_shiro are comparing it to the libraries listed below
- shiro反序列化批量ip快速检测脚本☆78Updated 4 years ago
- WIP: Demo for Attacking Apereo CAS☆90Updated 4 years ago
- 利用长亭xray高级版的回显Gadget重写的一个shiro反序列化利用工具。☆122Updated 4 years ago
- 一个自动化写入php不死马/进程守护马,批量获得flag的线下赛工具☆62Updated 6 years ago
- 关于Struts2框架的历史漏洞个人分析文章☆54Updated 4 years ago
- fastjson 1.2.68 版本 autotype bypass☆140Updated 2 years ago
- ☆69Updated 5 years ago
- DSO-Lab 漏洞研究成果整理☆82Updated 2 years ago
- 中国蚁剑JSP一句话Payload☆120Updated 4 years ago
- 一款用于src资产信息收集的工具☆57Updated 4 years ago
- This tool generates gopher link for exploiting SSRF and gaining RCE in redis with password.用于生成附带密码认证的gopher内容,用于SSRF等利用。☆114Updated 5 years ago
- 爬取各大SRC当日公告 | 通过微信通知的小工具 | 赏金工具☆101Updated 3 years ago
- 在edusrc平台上对于一些通用漏洞检测时编写的简单python POC脚本☆54Updated 2 years ago
- ☆46Updated 5 years ago
- 线下赛自动框架☆24Updated 6 years ago
- F-NAScan-PLUS 安服资产搜集☆142Updated 4 years ago
- ☆83Updated 4 years ago
- RMI 反序列化环境 一步步☆210Updated 4 years ago
- awd比赛用到的脚本☆56Updated 5 years ago
- ☆142Updated 4 years ago
- xxl-job未授权命令执行☆108Updated 3 years ago
- fastjson bypass autotype 1.2.68 with Throwable and AutoCloseable.☆226Updated 2 years ago
- a php serialize/unseralize tools fork from ambionics/phpggc, add chinese common php framework☆90Updated 5 years ago
- 在原有yso基础上实现依赖分离,内存马注入等功能。A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.☆68Updated 3 years ago
- a burp extension to find where use fastjson☆163Updated 5 years ago
- 通达OA一些漏洞点☆160Updated 4 years ago
- Web端POC-EXP 整理☆98Updated 4 years ago
- Spring Cloud SnakeYAML 反序列化一键注入cmdshell和reGeorg☆134Updated 4 years ago
- Apache Shiro 反序列化漏洞检测与利用工具,一键注入内存马☆138Updated 4 years ago
- CAS 硬编码 远程代码执行漏洞☆124Updated 3 years ago