mogwailabs / deserialization-filter-blacklistsLinks
Native Java serialization filter blacklist for common gadgets
☆20Updated 6 years ago
Alternatives and similar repositories for deserialization-filter-blacklists
Users that are interested in deserialization-filter-blacklists are comparing it to the libraries listed below
Sorting:
- POC for leaking java version through file and ftp protocols☆24Updated 5 years ago
- CVE-2020-5398 - RFD(Reflected File Download) Attack for Spring MVC☆87Updated 3 years ago
- Spring Boot Actuator + Spring Cloud Vul Env☆19Updated 5 years ago
- Slides/Demos from the BSides Munich 2019 talk "Attacking Java RMI in 2019"☆101Updated 6 years ago
- 总结了一下2019年在JVM环境中使用XXE攻击的知识☆58Updated 6 years ago
- ☆57Updated 5 years ago
- ☆14Updated 7 years ago
- FasterXML/jackson-databind 远程代码执行漏洞☆73Updated 5 years ago
- kibana < 6.6.0 未授权远程代码命令执行 (Need Timelion And Canvas),CVE-2019-7609☆89Updated 6 years ago
- 针对域名/页面的接口爬取,递归模式入库☆22Updated 6 years ago
- ☆28Updated 6 years ago
- Apache Log4j 1.2.X存在反序列化远程代码执行漏洞☆78Updated 5 years ago
- Some debug notes and exploit(not blind)☆39Updated 6 years ago
- 几条关于CVE-2020-15148(yii2反序列化)的绕过☆75Updated 5 years ago
- Java 反序列化学习的实验代码 Java_deserialize_vuln_lab☆87Updated 7 years ago
- Zimbra XXE+SSRF+UPLOAD Poc☆59Updated 6 years ago
- fastjson-1.2.61-RCE☆33Updated 6 years ago
- CVE-2019-3799 - Spring Cloud Config Server: Directory Traversal < 2.1.2, 2.0.4, 1.4.6☆31Updated 6 years ago
- Java After-Deserialization Attack☆78Updated 4 years ago
- autoType enable☆36Updated 6 years ago
- ☆73Updated 3 years ago
- Jira未授权SSRF漏洞☆31Updated 6 years ago
- some struts tag , attributes which out of the range will call SetDynamicAttribute() function, it will cause ONGL expression execute☆70Updated 5 years ago
- Papers☆34Updated 6 years ago
- A fastjson payload generator☆58Updated 5 years ago
- a Burp Extender that add an random X-Forward-For IP address for each request☆31Updated 9 years ago
- 用WebShell攻击PHP-FPM Attacking PHP-FPM with WebShell☆41Updated 4 years ago
- Nexus Repository Manager 3 Remote Code Execution without authentication < 3.15.0☆84Updated 6 years ago
- Plugin For BurpSuite (Pentester)☆36Updated 3 years ago
- source code of XCTF 2019 Final web task "tfboys"☆30Updated 3 years ago