mogwailabs / deserialization-filter-blacklistsLinks
Native Java serialization filter blacklist for common gadgets
☆20Updated 6 years ago
Alternatives and similar repositories for deserialization-filter-blacklists
Users that are interested in deserialization-filter-blacklists are comparing it to the libraries listed below
Sorting:
- POC for leaking java version through file and ftp protocols☆24Updated 5 years ago
- Spring Boot Actuator + Spring Cloud Vul Env☆19Updated 5 years ago
- CVE-2020-5398 - RFD(Reflected File Download) Attack for Spring MVC☆87Updated 2 years ago
- ☆57Updated 5 years ago
- Slides/Demos from the BSides Munich 2019 talk "Attacking Java RMI in 2019"☆101Updated 6 years ago
- ☆28Updated 6 years ago
- Dependencies with Log4j2 Checklist☆35Updated 3 years ago
- 总结了一下2019年在JVM环境中使用XXE攻击的知识☆58Updated 6 years ago
- Some debug notes and exploit(not blind)☆39Updated 6 years ago
- 几条关于CVE-2020-15148(yii2反序列化)的绕过☆75Updated 5 years ago
- Apache Log4j 1.2.X存在反序列化远程代码执行漏洞☆78Updated 5 years ago
- fastjson-1.2.61-RCE☆33Updated 6 years ago
- ☆11Updated 8 years ago
- Java 反序列化学习的实验代码 Java_deserialize_vuln_lab☆87Updated 7 years ago
- Plugin For BurpSuite (Pentester)☆36Updated 3 years ago
- Java After-Deserialization Attack☆79Updated 4 years ago
- FasterXML/jackson-databind 远程代码执行漏洞☆74Updated 5 years ago
- kibana < 6.6.0 未授权远程代码命令执行 (Need Timelion And Canvas),CVE-2019-7609☆89Updated 6 years ago
- ☆17Updated 7 years ago
- 个人用于在自动化挖掘gadget时,方便查找gadget chains中class所在jar包,以助于便捷审计测试gadget有效性的那么一个小工具。☆60Updated 5 years ago
- A Zhiyuan OA Collaborative Office Remote Code Execution Vulnerability on Windows☆37Updated 6 years ago
- A fastjson payload generator☆58Updated 5 years ago
- Web Server that serves a single file and keeps the connection open until user releases it.☆73Updated 12 years ago
- a Burp Extender that add an random X-Forward-For IP address for each request☆31Updated 9 years ago
- Nagios XI远程命令执行漏洞 <v5.6.9☆23Updated 5 years ago
- CVE-2020-9548:FasterXML/jackson-databind 远程代码执行漏洞☆24Updated 5 years ago
- autoType enable☆36Updated 6 years ago
- 用WebShell攻击PHP-FPM Attacking PHP-FPM with WebShell☆41Updated 4 years ago
- Shiro_721 exp 纯手工实现Padding Oracle整个过程☆67Updated 6 years ago
- Papers☆34Updated 6 years ago