blindpirate / spring-rce-2022-03
☆15Updated 2 years ago
Alternatives and similar repositories for spring-rce-2022-03:
Users that are interested in spring-rce-2022-03 are comparing it to the libraries listed below
- spring-cloud-function SpEL RCE, Vultarget & Poc☆133Updated 2 years ago
- log4j2-vaccine☆85Updated 3 years ago
- 通过JavaAgent与Javassist技术对JVM加载的类对象进行动态插桩,可以做一些破解、加密验证的绕过等操作☆98Updated 7 months ago
- 一款使用Yaml定义搜索规则来搜索Class的工具☆104Updated last year
- 本项目可以把一个或多个Jar包构建成数据库,用户连接数据库后通过SQL语句任意搜索需要的内容,例如类和方法信息,方法调用关系等☆76Updated last year
- The project is a simple vulnerability Demo environment written by SpringBoot. Here, I deliberately wrote a vulnerability environment wher…☆87Updated 3 years ago
- Debug CVEs!☆33Updated last year
- 用Java agent实现内存马等功能☆191Updated last year
- jasypt Decrypt Encrypt☆14Updated 3 years ago
- Auto Code Audit Framework for Java☆96Updated 3 years ago
- 利用agent hock指定的class,在jar运行周期内,用于跟踪被执行的方法,辅助做一些事情,比如挖洞啊☆126Updated 4 years ago
- 基于污点分析和模拟栈帧技术的JSP Webshell检测☆45Updated last month
- rmi、jndi、ldap、jrmp、jmx、jms一些demo测试☆306Updated 2 years ago
- Bypass JVM Class ByteCode Verifier , 对抗反编译器☆111Updated last year
- CVE-2022-22965 : about spring core rce☆50Updated 2 years ago
- Java agent without file 无文件的Java agent☆78Updated 2 years ago
- 用nmap 和 elk 做内网资产盘点,依赖 nmap-vulners☆25Updated 4 years ago
- 静态程序分析工具 主要生成方法的CFG和.java文件的AST☆128Updated last year
- ☆269Updated 3 years ago
- 基于亚马逊S3\阿里云OSS\腾讯COS通信隧道的远程管理工具☆320Updated 4 years ago
- Libinjection in Java☆38Updated 8 years ago
- 记录各语言、框架中危险的sink,个人代码审计、漏洞研究使用。☆115Updated 3 years ago
- 一个针对防御 log4j2 CVE-2021-44228 漏洞的 RASP 工具。 A Runtime Application Self-Protection module specifically designed for log4j2 RCE (CVE-2021-442…☆122Updated 3 years ago
- 🌶 一些和容器化/容器编排/服务网格等技术相关的安全代码片段[自用备份]☆80Updated 3 years ago
- 一个 CLASS 文件混淆工具,支持方法名/字段名/参数名引用分析和重命名混淆方式,支持字符串提取/AES加密运行时解密/整型异或混淆/垃圾代码花指令混淆/等方式,支持方法和字段的隐藏,支持INVOKE指令改反射调用,配置简单,容易上手☆191Updated 2 weeks ago
- dubbo快速利用exp,基本上老版本覆盖100%。☆104Updated last year
- ☆36Updated last week
- 用于检测maven项目的第三方依赖组件是否存在安全漏洞。☆103Updated 2 years ago
- A Java runtime information-gathering tool which uses the Java Attach API for information acquisition☆204Updated 3 years ago
- A malicious LDAP server for JNDI injection attacks☆51Updated last year