ffadd / JNDIKitLinks
JNDI/LDAP注入利用工具,对命令进行两种编码,支持多种绕过高版本JDK的方式(参考大佬代码造的轮子)
☆44Updated 3 years ago
Alternatives and similar repositories for JNDIKit
Users that are interested in JNDIKit are comparing it to the libraries listed below
Sorting:
- ☆15Updated 3 years ago
- 利用shiro反序列化注入冰蝎内存马☆37Updated 3 years ago
- 窃取当前用户的ssh,sudo密码☆69Updated 2 years ago
- Java Agent memory horse scanner combined with Call Graph modus☆64Updated 2 years ago
- 多组件客户端☆74Updated 7 months ago
- Collect JSP webshell of various implementation methods. 收集JSP Webshell的各种姿势☆15Updated 4 years ago
- 通过JavaAgent与Javassist技术对JVM加载的类对象进行动态插桩,可以做一些破解、加密验证的绕过等操作☆114Updated last year
- NoPacScan is a CVE-2021-42287/CVE-2021-42278 Scanner,it scan for more domain controllers than other script☆88Updated 3 years ago
- Automatically scan jar packages by using ast to find fastjson gadgets. In particular, this project is limited to mining Gadgets that may …☆48Updated 3 years ago
- Java 内存马生成插件☆54Updated 2 years ago
- Yapi mock script RCE another version. Webshell way. 另一种 Webshell 方式的 Yapi 命令执行的方法 相比于其他的利用方式 更加微操和可控 影响更小☆66Updated last year
- 基于污点分析和模拟栈帧技术的JSP Webshell检测☆48Updated 2 months ago
- 添加Connector内存马与ws内存马检测逻辑☆16Updated 3 years ago
- 一个基于DNS隧道的简单C2☆59Updated 3 years ago
- Redis primary/secondary replication RCE☆43Updated 3 years ago
- 无影脚 - 命令行下的日志文件处理工具☆52Updated 3 years ago
- 如何将Java反序列化Payload极致缩小☆66Updated 3 years ago
- (批量化改造)sharpwmi是一个基于rpc的横向移动工具,具有上传文件和执行命令功能。☆109Updated 4 years ago
- woodpecker-framework框架http发包库,专门为漏洞检测与利用场景设计。☆70Updated 3 weeks ago
- portreuse reuseport 端口复用☆61Updated 2 years ago
- detect gitlab detail version☆55Updated last year
- 汇编HTTP请求发送/Assembly Http Request☆51Updated 11 months ago
- 在spring-aop中新发现的反序列化gadget-chain☆52Updated 10 months ago
- A list for Spring Security☆125Updated last year
- java☆54Updated 2 years ago
- 用来存放平时写的一些net内存马,仅用于练手,需要可以自行修改☆89Updated 3 years ago
- docker运行cs4.7server端☆39Updated 3 years ago
- 收集云沙箱上线C2的ip,如微X、奇XX、3X0、virustX等☆125Updated 2 years ago
- Apache Dubbo漏洞测试Demo及其POC☆64Updated 2 years ago
- A mininal go http client for security testing☆49Updated 9 months ago