基于dbcp的fastjson rce 回显
☆197Jun 28, 2021Updated 4 years ago
Alternatives and similar repositories for fastjson-local-echo
Users that are interested in fastjson-local-echo are comparing it to the libraries listed below
Sorting:
- fastjson不出网利用、c3p0☆255Jul 30, 2021Updated 4 years ago
- springboot跨线程注入内存马☆123Apr 10, 2022Updated 3 years ago
- (批量化改造)sharpwmi是一个基于rpc的横向移动工具,具有上传文件和执行命令功能。☆108Jan 8, 2021Updated 5 years ago
- JNDI在java高版本的利用工具,FUZZ利用链☆597Oct 8, 2022Updated 3 years ago
- ☆523Sep 16, 2022Updated 3 years ago
- 🚀 一款为了学习go而诞生的漏洞利用工具☆450Jun 14, 2022Updated 3 years ago
- A memory shell for ruoyi☆266Apr 28, 2023Updated 2 years ago
- Java RCE 回显测试代码☆1,016Oct 15, 2020Updated 5 years ago
- 解决FastJson、Jackson、Log4j2、原生JNDI注入漏洞的高版本JDKBypass利用,探测本地可用反序列化gadget达到命令执行、回显命令执行、内存马注入☆770Jan 26, 2022Updated 4 years ago
- 自己的JNDI 利用工具,添加一些人性化功能☆131Sep 4, 2022Updated 3 years ago
- 帆软/致远密码解密 工具☆360Jul 29, 2021Updated 4 years ago
- fastjson漏洞burp插件,检测fastjson<1.2.68基于dnslog,fastjson<=1.2.24和1.2.33<=fatjson<=1.2.47的不出网检测和TomcatEcho,SpringEcho回显方案。☆124May 14, 2021Updated 4 years ago
- JDBC Connection URL Attack☆438Sep 10, 2021Updated 4 years ago
- AK资源管理工具,阿里云/腾讯云/华为云/AWS/UCLOUD/京东云/百度云/七牛云存储/火山引擎 AccessKey AccessKeySecret,利用AK 获取资源信息和操作资源,ECS/CVM/E2/UHOST/ECI/BCC执行命令,OSS/COS/S3/BOS…☆778Feb 13, 2025Updated last year
- fastjson 被动扫描、不出网payload生成☆367Nov 19, 2021Updated 4 years ago
- ☆239Updated this week
- ☆294May 7, 2022Updated 3 years ago
- Fastjson姿势技巧集合☆1,824Oct 20, 2023Updated 2 years ago
- rmi打内存马工具,适用于目标用不了ldap的情况☆254Jul 12, 2023Updated 2 years ago
- 命令执行不回显但DNS协议出网的命令回显场景解决方案☆277Jan 10, 2023Updated 3 years ago
- 改造BeichenDream/InjectJDBC加入shiro获取key和修改key功能☆279Nov 28, 2023Updated 2 years ago
- spring boot Fat Jar 任意写文件漏洞到稳定 RCE 利用技巧☆754Apr 14, 2021Updated 4 years ago
- 各种数据库的利用姿势☆1,034Jan 3, 2025Updated last year
- 域控安全one for all☆736Sep 9, 2024Updated last year
- 冰蝎 哥斯拉 WebShell bypass☆762Jan 15, 2026Updated last month
- JNDI服务利用工具 RMI/LDAP,支持部分场景回显、内存shell,高版本JDK场景下利用等,fastjson rce命令执行,log4j rce命令执行 漏洞检测辅助工具☆2,012May 21, 2024Updated last year
- 获取 alibaba druid 一些 sessions , sql , urls☆292Apr 4, 2025Updated 10 months ago
- 命令执行不回显但DNS协议出网的命令回显场景解决方案(修改为使用ceye接收请求,添加自定义DNS服务器)☆292Aug 20, 2023Updated 2 years ago
- Redis-Attack By Replication (通过主从复制攻击Redis)☆356Nov 25, 2022Updated 3 years ago
- heapdump敏感信息查询工具,例如查找 spring heapdump中的密码明文,AK,SK等☆1,433May 21, 2024Updated last year
- 拿来即用的Tomcat7/8/9/10版本Listener/Filter/Servlet内存马,支持注入CMD内存马和冰蝎内存马☆511Aug 31, 2022Updated 3 years ago
- 应对渗透中极限环境下命令回显 & 文件落地☆132Jul 1, 2022Updated 3 years ago
- Java应用的一些配置文件字典,来源于公开的字典与平时收集☆321Feb 1, 2024Updated 2 years ago
- ysoserial修改版,着重修改ysoserial.payloads.util.Gadgets.createTemplatesImpl使其可以通过引入自定义class的形式来执行命令、内存马、反序列化回显。☆753Jan 11, 2024Updated 2 years ago
- ☆306Feb 27, 2025Updated last year
- Ecloud是一款基于http/1.1协议传输TCP流量工具,适用于内网不出网时通过web代理脚本转发tcp流量☆112Aug 24, 2021Updated 4 years ago
- Nacos JRaft Hessian 反序列化 RCE 加载字节码 注入内存马 不出网利用☆848Jul 7, 2023Updated 2 years ago
- frp0.38.1 支持域前置、远程加载配置文件、配置文件自删除、流量特征修改☆133Apr 26, 2022Updated 3 years ago
- DNSLOG平台 golang☆439Dec 30, 2021Updated 4 years ago