☆12Aug 5, 2021Updated 4 years ago
Alternatives and similar repositories for codeql-workshop
Users that are interested in codeql-workshop are comparing it to the libraries listed below
Sorting:
- Sample Spring application to Demonstrate the Gateway Actuator☆48Mar 3, 2022Updated 3 years ago
- log4j-patch 修改字节码实现补丁防御☆20Dec 10, 2021Updated 4 years ago
- codeqlpy☆28Jul 6, 2023Updated 2 years ago
- Soot based Jimple interpreter☆14Mar 31, 2021Updated 4 years ago
- A technique for developing Fortify structural rules and characterization rules.☆14Dec 2, 2019Updated 6 years ago
- 010Editor Templates☆13May 29, 2024Updated last year
- bypass JEP290 RaspHook code☆63Sep 21, 2020Updated 5 years ago
- 基于Java ASM技术和GadgetInspector的原理,尝试实现一个自动Java代码审计工具。目前做到了可控参数分析和数据流跟踪分析☆39Oct 26, 2021Updated 4 years ago
- some codeql rules☆15Apr 6, 2020Updated 5 years ago
- Example nginx backdoor via malicious plugin☆48Mar 3, 2022Updated 3 years ago
- Taint analysis implementation based on Heros and Soot☆45May 6, 2024Updated last year
- Shiro-721 Padding Oracle Attack☆73Jun 4, 2021Updated 4 years ago
- Example for EJB remoting in Wildfly☆21Feb 11, 2021Updated 5 years ago
- JavaRce complements project - use RASP to prevent vulnerabilities☆24Apr 22, 2024Updated last year
- ☆41Mar 10, 2021Updated 4 years ago
- CVE-2018-3252-PoC☆74Dec 7, 2018Updated 7 years ago
- Unofficial Dockerfile and scripts for building CodeQL databases for the OpenJDK☆49Jan 7, 2024Updated 2 years ago
- ☆22Nov 3, 2022Updated 3 years ago
- 该项目是通过go语言实现防止rmi利用被反置的问题。☆44Dec 30, 2021Updated 4 years ago
- Ready to use docker image for CodeQL☆90Jan 10, 2024Updated 2 years ago
- 2020 第三届安洵杯 部分题目环境/源码☆17Dec 22, 2020Updated 5 years ago
- cve-2022-34169 延伸出的Jdk Xalan的payload自动生成工具,可根据不同的Jdk生成出其所对应的xslt文件☆93Jan 17, 2023Updated 3 years ago
- fastjson auto type derivation search☆21Aug 19, 2021Updated 4 years ago
- java 漏洞平台包含各种CVE☆23Jun 17, 2022Updated 3 years ago
- dubbo快速利用exp,基本上老版本覆盖100%。☆161Jun 30, 2025Updated 7 months ago
- Some PoC (Proof-of-Concept) about vulnerability of java deserialization of untrusted data☆26Jul 12, 2021Updated 4 years ago
- Finding Java gadget chains with CodeQL☆184Jan 14, 2025Updated last year
- 记录各语言、框架中危险的sink,个人代码审计、漏洞研究使用。☆117Dec 30, 2021Updated 4 years ago
- ☆28Oct 26, 2021Updated 4 years ago
- 就是一个练习RMI反序列化的最简单环境☆30Jan 8, 2022Updated 4 years ago
- A declarative static analysis tool for jvm bytecode based Datalog like CodeQL☆345Jan 6, 2024Updated 2 years ago
- ☆104Jan 29, 2026Updated 3 weeks ago
- The function of the tool is to inject JNDI through LDAP☆28Dec 21, 2021Updated 4 years ago
- A neo4j procedure for tabby☆137May 17, 2025Updated 9 months ago
- Atlassian Jira Seraph Authentication Bypass RCE(CVE-2022-0540)☆72May 25, 2022Updated 3 years ago
- rmi、jndi、ldap、jrmp、jmx、jms一些demo测试☆310Jun 17, 2022Updated 3 years ago
- SEETF 2022 Public Challenge Files, Sources, and Solutions☆28Jul 27, 2022Updated 3 years ago
- A tool to analyse JMX API security level.☆43Jul 23, 2014Updated 11 years ago
- 一个高价值漏洞采集与推送服务 | A valueable vulnerability collection and push service☆31Sep 24, 2024Updated last year