mogwailabs / deserialization-filter-blacklistsLinks
Native Java serialization filter blacklist for common gadgets
☆20Updated 6 years ago
Alternatives and similar repositories for deserialization-filter-blacklists
Users that are interested in deserialization-filter-blacklists are comparing it to the libraries listed below
Sorting:
- POC for leaking java version through file and ftp protocols☆24Updated 4 years ago
- Slides/Demos from the BSides Munich 2019 talk "Attacking Java RMI in 2019"☆101Updated 5 years ago
- Spring Boot Actuator + Spring Cloud Vul Env☆19Updated 5 years ago
- ☆58Updated 5 years ago
- CVE-2020-5398 - RFD(Reflected File Download) Attack for Spring MVC☆86Updated 2 years ago
- Papers☆34Updated 5 years ago
- CVE-2019-3799 - Spring Cloud Config Server: Directory Traversal < 2.1.2, 2.0.4, 1.4.6☆31Updated 6 years ago
- 针对域名/页面的接口爬取,递归模式入库☆22Updated 5 years ago
- 总结了一下2019年在JVM环境中使用XXE攻击的知识☆58Updated 5 years ago
- 几条关于CVE-2020-15148(yii2反序列化)的绕过☆75Updated 4 years ago
- Apache Log4j 1.2.X存在反序列化远程代码执行漏洞☆78Updated 5 years ago
- fastjson-1.2.61-RCE☆33Updated 5 years ago
- FasterXML/jackson-databind 远程代码执行漏洞☆74Updated 5 years ago
- kibana < 6.6.0 未授权远程代码命令执行 (Need Timelion And Canvas),CVE-2019-7609☆89Updated 5 years ago
- Java After-Deserialization Attack☆79Updated 4 years ago
- bugbounty tools☆18Updated last year
- https://github.com/GrrrDog/Java-Deserialization-Cheat-Sheet☆51Updated 4 years ago
- Some debug notes and exploit(not blind)☆39Updated 6 years ago
- ☆28Updated 6 years ago
- CVE-2019-2890 WebLogic 反序列化RCE漏洞☆44Updated 5 years ago
- A fastjson payload generator☆58Updated 4 years ago
- Web Server that serves a single file and keeps the connection open until user releases it.☆73Updated 11 years ago
- HackerOne Staffs☆29Updated 5 years ago
- autoType enable☆36Updated 5 years ago
- Dependencies with Log4j2 Checklist☆35Updated 3 years ago
- 用WebShell攻击PHP-FPM Attacking PHP-FPM with WebShell☆41Updated 4 years ago
- Java 反序列化学习的实验代码 Java_deserialize_vuln_lab☆87Updated 6 years ago
- CVE-2020-8840:FasterXML/jackson-databind 远程代码执行漏洞☆36Updated 5 years ago
- ☆18Updated 7 years ago
- phpweb 前台任意文件上传☆16Updated 5 years ago