c0ny1 / xxe-lab
一个包含php,java,python,C#等各种语言版本的XXE漏洞Demo
☆789Updated 2 years ago
Alternatives and similar repositories for xxe-lab:
Users that are interested in xxe-lab are comparing it to the libraries listed below
- 上传漏洞fuzz字典生成脚本☆1,250Updated 4 years ago
- 在渗透测试中快速检测常见中间件、组件的高危漏洞。☆731Updated 3 years ago
- 增强版WeblogicScan、检测结果更精确、插件化、添加CVE-2019-2618,CVE-2019-2729检测,Python3支持☆962Updated 10 months ago
- Burpsuite-Plugins-Usage☆515Updated 5 years ago
- 从wooyun中提取的payload,以及burp插件☆843Updated 2 years ago
- XssPayload List . Usage:☆723Updated 5 years ago
- Shiro<=1.2.4反序列化,一键检测工具☆984Updated 4 years ago
- Burp suite 分块传输辅助插件☆1,972Updated 3 years ago
- bypass disable_functions via LD_PRELOA (no need /usr/sbin/sendmail)☆1,155Updated 3 years ago
- Apache Shiro 反序列化漏洞检测与利用工具☆543Updated 5 years ago
- Burp被动扫描流量转发插件☆1,434Updated 10 months ago
- 360/0Kee-Team/crawlergo动态爬虫结合长亭XRAY扫描器的被动扫描功能☆1,190Updated 3 years ago
- 一个各种方式突破Disable_functions达到命令执行的shell☆1,191Updated last year
- Java反序列化漏洞利用工具V1.0 Java反序列化相关漏洞的检查工具,采用JDK 1.8+NetBeans8.2开发,软件运行必须安装JDK 1.8或者以上版本。 支持:weblogic xml反序列化漏洞 CVE-2017-10271/CNVD-C-2019…☆478Updated 4 years ago
- Collect JSP webshell of various implementation methods. 收集JSP Webshell的各种姿势☆1,381Updated 3 years ago
- SvnExploit支持SVN源代码泄露全版本Dump源码☆979Updated 2 years ago
- PoCBox - Vulnerability Test Aid Platform☆955Updated last year
- PC客户端(C-S架构)渗透测试checklist / Client side(C-S) penetration checklist☆662Updated 4 years ago
- 一款基于BurpSuite的被动式shiro检测插件☆1,733Updated 2 years ago
- myscan 被动扫描☆663Updated 4 years ago
- Weblogic环境搭建工具☆792Updated 5 years ago
- thinkphp v5.x 远程代码执行漏洞-POC集合☆1,136Updated 6 years ago
- sqlmap4burp++是一款兼容Windows,mac,linux多个系统平台的Burp与sqlmap联动插件☆771Updated 5 years ago
- 通过BurpSuite来构建自己的爆破字典,可以通过字典爆破来发现隐藏资产。☆497Updated last year
- Spring Boot Actuator未授权访问【XXE、RCE】单/多目标检测☆515Updated 4 years ago
- 这是一个用于IP和域名碰撞匹配访问的小工具,旨意用来匹配出渗透过程中需要绑定hosts才能访问的弱主机或内部系统。☆1,155Updated 6 years ago
- JNDI服务利用工具 RMI/LDAP,支持部分场景回显、内存shell,高版本JDK场景下利用等,fastjson rce命令执行,log4j rce命令执行 漏洞检测辅助工具☆1,966Updated 11 months ago
- Information Security (Web Security/Penetration Testing Direction) Interview Questions/Solutions 信息安全(Web安全/渗透测试方向)面试题/解题思路☆477Updated 5 years ago
- 一个简单的Fastjson反序列化检测burp插件☆912Updated 3 years ago
- MSSQL注入提权,bypass的一些总结☆723Updated 10 months ago