☆12Aug 5, 2021Updated 4 years ago
Alternatives and similar repositories for codeql-workshop
Users that are interested in codeql-workshop are comparing it to the libraries listed below
Sorting:
- Sample Spring application to Demonstrate the Gateway Actuator☆48Mar 3, 2022Updated 4 years ago
- log4j-patch 修改字节码实现补丁防御☆20Dec 10, 2021Updated 4 years ago
- 010Editor Templates☆13May 29, 2024Updated last year
- 2020 第三届安洵杯 部分题目环境/源码☆17Dec 22, 2020Updated 5 years ago
- Example nginx backdoor via malicious plugin☆48Mar 3, 2022Updated 4 years ago
- CVE-2018-3252-PoC☆74Dec 7, 2018Updated 7 years ago
- A technique for developing Fortify structural rules and characterization rules.☆14Dec 2, 2019Updated 6 years ago
- Example for EJB remoting in Wildfly☆21Feb 11, 2021Updated 5 years ago
- some codeql rules☆15Apr 6, 2020Updated 5 years ago
- cve-2022-34169 延伸出的Jdk Xalan的payload自动生成工具,可根据不同的Jdk生成出其所对应的xslt文件☆93Jan 17, 2023Updated 3 years ago
- bypass JEP290 RaspHook code☆63Sep 21, 2020Updated 5 years ago
- Unofficial Dockerfile and scripts for building CodeQL databases for the OpenJDK☆49Jan 7, 2024Updated 2 years ago
- ☆22Nov 3, 2022Updated 3 years ago
- ☆41Mar 10, 2021Updated 5 years ago
- Soot based Jimple interpreter☆14Mar 31, 2021Updated 4 years ago
- Ready to use docker image for CodeQL☆90Jan 10, 2024Updated 2 years ago
- JavaRce complements project - use RASP to prevent vulnerabilities☆24Apr 22, 2024Updated last year
- codeqlpy☆28Jul 6, 2023Updated 2 years ago
- 基于Java ASM技术和GadgetInspector的原理,尝试实现一个自动Java代码审计工具。目前做到了可控参数分析和数据流跟踪分析☆39Oct 26, 2021Updated 4 years ago
- Shiro-721 Padding Oracle Attack☆73Jun 4, 2021Updated 4 years ago
- fastjson auto type derivation search☆21Aug 19, 2021Updated 4 years ago
- Taint analysis implementation based on Heros and Soot☆45May 6, 2024Updated last year
- 该项目是通过go语言实现防止rmi利用被反置的问题。☆44Dec 30, 2021Updated 4 years ago
- ☆28Oct 26, 2021Updated 4 years ago
- dubbo快速利用exp,基本上老版本覆盖100%。☆161Jun 30, 2025Updated 8 months ago
- 记录各语言、框架中危险的sink,个人代码审计、漏洞研究使用。☆117Dec 30, 2021Updated 4 years ago
- 向导式CTF题目环境模板生成器☆34Oct 12, 2023Updated 2 years ago
- CVE-2021-38003 exploits extracted from https://twitter.com/WhichbufferArda/status/1609604183535284224☆38Jan 7, 2023Updated 3 years ago
- 就是一个练习RMI反序列化的最简单环境☆30Jan 8, 2022Updated 4 years ago
- WeChat in a Docker container☆11Mar 29, 2024Updated last year
- SEETF 2022 Public Challenge Files, Sources, and Solutions☆28Jul 27, 2022Updated 3 years ago
- 一个高价值漏洞采集与推送服务 | A valueable vulnerability collection and push service☆31Sep 24, 2024Updated last year
- java 漏洞平台包含各种CVE☆23Jun 17, 2022Updated 3 years ago
- A declarative static analysis tool for jvm bytecode based Datalog like CodeQL☆345Jan 6, 2024Updated 2 years ago
- Finding Java gadget chains with CodeQL☆185Jan 14, 2025Updated last year
- Some PoC (Proof-of-Concept) about vulnerability of java deserialization of untrusted data☆26Jul 12, 2021Updated 4 years ago
- Atlassian Jira Seraph Authentication Bypass RCE(CVE-2022-0540)☆72May 25, 2022Updated 3 years ago
- Collections of CTF-WEB-challs mainly for review purpose.☆30Jul 16, 2023Updated 2 years ago
- Scala 3 Decompiler☆11May 17, 2021Updated 4 years ago