keven1z / simpleIAST
simpleIAST- 基于污点追踪的灰盒漏洞扫描工具。
☆75Updated 3 weeks ago
Alternatives and similar repositories for simpleIAST:
Users that are interested in simpleIAST are comparing it to the libraries listed below
- Lessons for syntaxflow zero to hero☆48Updated 5 months ago
- 一个集合了多种语言的实战化Web靶场 | A practical Web shooting range that integrates multiple languages☆71Updated this week
- HW2023中安全厂和超级大厂的大爆炸☆65Updated last year
- proof-of-concept for generating Java deserialization payload | Proxy MemShell☆185Updated 9 months ago
- 内存马查杀工具,尤其针对Agent型,原理是dump出JVM当前的class并进行字节码分析,并加入自动修复的功能☆146Updated last year
- 所有碰到过的默认口令☆102Updated 11 months ago
- 无需文件落地Agent内存马生成器☆223Updated 9 months ago
- 关于内存马的学习研究支持新手从0到1,从内存马原理,内存马植入 内存马检测 到内存马防御与内存马应急以及内存马查杀全系列java内存马/php/.net/c++/python 喜欢可以点个star 后续持续更新☆101Updated 10 months ago
- Small & Fast Vulnerability Scanner Engine based on XRAY YAML Rule | 基于 XRAY YAML 规则的超轻量快速漏洞扫描引擎 | 基于 ANTLR 实现语法分析和完整的 XRAY YAML 规则实现 | 简单…☆154Updated 5 months ago
- A Java Route Collection Tool☆91Updated 7 months ago
- js / html /josn 中获取 泄露的接口 / URL / 未授权路径 获取之后尝试访问☆69Updated 3 years ago
- java-web 自动化鉴权绕过☆262Updated 5 months ago
- 一款基 于Knife4j 的 Swagger 接口自动化测试未授权工具☆97Updated 10 months ago
- JavaPassDump☆242Updated 3 years ago
- A Go library for generating Java deserialization payloads.☆155Updated 6 months ago
- 获取 alibaba druid 一些 sessions , sql , urls☆261Updated 2 years ago
- 记录一些代码审计过的源码☆143Updated 2 weeks ago
- check hikvision/ys7 api☆66Updated last year
- 检测查杀java内存马☆76Updated last year
- 一款Java内存马生成、测试工具,搭配@ax1sX的MemShell食用。☆212Updated 8 months ago
- fastjson 80 远程代码执行漏洞复现☆191Updated 2 years ago
- 自己积累的一些Java反序列化利用链☆87Updated 2 years ago
- evil-mysql-server is a malicious database written to target jdbc deserialization vulnerabilities and requires ysoserial.☆87Updated 2 years ago
- 本工具为jeecg框架漏洞利用工具非jeecg-boot!☆175Updated 7 months ago
- SQL Injection Scout 是一个用于 Burp Suite 的扩展,专为帮助安全研究人员和开发人员检测和分析 SQL 注入漏洞而设计。该扩展提供了丰富的配置选项和直观的用户界面,便于用户自定义扫描和分析过程。☆100Updated this week
- 本工具的定位是快速生成Java安全相关的Payload,如内存马、反序列化链、JNDI url、Fastjson等,动态生成相关Payload,并附带相应的文档。☆91Updated 2 weeks ago
- Godzilla插件|内存马|Suo5内存代理|jmg for Godzilla☆212Updated 9 months ago
- 漏洞poc☆90Updated 3 months ago
- 命令执行不回显但DNS协议出网的命令回显场景解决方案(修改为使用ceye接收请求,添加自定义DNS服务器)☆289Updated last year