j5s / XVulnFinderLinks
Java静态代码安全审计工具,使用JavaParser项目做语法分析,计划支持常见的Web漏洞与组件漏洞
☆21Updated 4 years ago
Alternatives and similar repositories for XVulnFinder
Users that are interested in XVulnFinder are comparing it to the libraries listed below
Sorting:
- 基于Java ASM技术和GadgetInspector的原理,尝试实现一个自动Java代码审计工具。目前做到了可控参数分析和数据流跟踪分析☆39Updated 4 years ago
- 静态程序分析工具 主要生成方法的CFG和.java文件的AST☆132Updated 2 years ago
- 一个基于jvm-sandbox高度定制化rasp☆58Updated 2 years ago
- 针对于Spring框架的自动Java代码审计工具☆37Updated 3 years ago
- Dongtai-plugin-idea is an IDEA plug-in developed by DongTai team for Java Web application developers. This plug-in provides functions suc…☆32Updated 2 years ago
- 自学时写的适合Java安全小白用来学习Java反序列化漏洞的文章和Demo。(随懒狗的学习进度持续更新🐶)。Some articles and demos written during self-study which are suitable for Java Secu…☆11Updated 4 years ago
- 阿里巴巴安全SDK,提供SSRF、JDBC、XXE防护能力☆114Updated 2 months ago
- JAVA IAST Example☆49Updated 4 years ago
- 开发和安全和运营:DevSecOps-Software development (Dev) and Security (Sec) and IT operations (Ops).☆27Updated last year
- 一个java代码审计辅助工具☆29Updated 3 years ago
- nativeRasp that can hook native methods☆24Updated 2 years ago
- Tai-e的Web插件☆23Updated last year
- Spring内存马检测和隐形马研究☆12Updated 4 years ago
- ☆19Updated 2 years ago
- 一款轻量级匹配Sink点的代码审计扫描器,为了帮助红队过程中快速代码审计的小工具☆25Updated last year
- 通过JavaAgent与Javassist技术对JVM加载的类对象进行动态插桩,可以做一些破解、加密验证的绕过等操作☆115Updated last year
- 收录go语言编写的项目、框架和组件出现的cve,或者一些相关的利用方式的文章☆47Updated 3 years ago
- 《JNDI-深入理解Java万恶之源》☆39Updated 2 years ago
- Apache Dubbo漏洞测试Demo及其POC☆65Updated 2 years ago
- CodeQL分析闭源Jar包脚本,基于Apache Ant构建CodeQL数据库☆41Updated 3 years ago
- Java 代码审计-存在风险的函数汇总。方便我们日常代码审计过程中快速定位漏洞点,配合静态代码分析工具做到事半功倍。Java code audit - summary of risky functions. It is convenient for us to quickl…☆31Updated last year
- 当死去的记忆突然开始攻击我,我终于想起了我还写过一款十分十分垃圾的 rasp 靶场。☆79Updated 3 years ago
- 一款使用Yaml定义搜索规则来搜索Class的工具☆107Updated 2 years ago
- 攻击Java Web应用-[Java Web安全]☆79Updated 6 years ago
- 《深入理解DAST动态应用程序安全测试》Dynamic Application Security Testing.☆54Updated 3 years ago
- 《深入理解Semgrep》Finding vulnerabilities with Semgrep.☆58Updated 2 years ago
- 《Spring漏洞研究》☆47Updated 3 years ago
- 一款碾压sqlmap的sql注入漏洞检测系统^^☆16Updated 5 years ago
- A neo4j procedure for tabby☆136Updated 7 months ago
- Java安全,漏洞分析/挖掘/利用☆14Updated 2 years ago