p1n93r / SpringBootAdmin-thymeleaf-SSTI
SpringBootAdmin-thymeleaf-SSTI which can cause RCE
☆77Updated last year
Related projects ⓘ
Alternatives and complementary repositories for SpringBootAdmin-thymeleaf-SSTI
- Java命令行文件监控小工具(代码审计)☆95Updated 2 years ago
- A Java Route Collection Tool☆84Updated 3 months ago
- 自己积累的一些Java反序列化利用链☆86Updated last year
- Spel-research☆24Updated 2 years ago
- ☆80Updated 6 months ago
- 抽离出 utf-8-overlong-encoding 的序列化逻辑,实现 2 3 字节加密序列化数组☆109Updated 7 months ago
- pyyso is a Python package that generate java serialized poc. Including CommonsCollections1-7, JDK7u21, JDK8u20, ldap for jndi, shiro-550,…☆49Updated 2 years ago
- Lessons for syntaxflow zero to hero☆42Updated last month
- Abandoned - fastjson 1.2.24-1.2.80 poc & vulns env & how to check vul☆86Updated last year
- 一款让你不只在dubbo-sample、vulhub或者其他测试环境里检测和利用成功的Apache Dubbo 漏洞检测工具。☆160Updated last year
- java-swing-gui-stater | Java Swing GUI Maven 项目模板 | 简单的教程☆32Updated last week
- evil-mysql-server is a malicious database written to target jdbc deserialization vulnerabilities and requires ysoserial.☆84Updated 2 years ago
- springboot跨线程注入内存马☆114Updated 2 years ago
- 如果反序列化过程中使用resolveClass拉黑了TemplatesImpl如何绕过☆46Updated last year
- Apache RocketMQ 远程代码执行漏洞(CVE-2023-33246) Exploit☆102Updated last year
- proof-of-concept for generating Java deserialization payload | Proxy MemShell☆175Updated 5 months ago
- ☆46Updated 2 months ago
- Some ReadObject Sink With JDBC☆190Updated 6 months ago
- 一款办公应用云凭证利用工具☆85Updated 5 months ago
- fastjson 80 远程代码执行漏洞复现☆179Updated 2 years ago
- 本工具的定位是快速生成Java安全相关的Payload,如内存马、反序列化链、JNDI url、Fastjson等,动态生成相关Payload,并附带相应的文档。☆90Updated 2 years ago
- 4个 .soap 版本的WebShell(持续更新维护),优点:可以运行于子目录,突破了过去只能运行于根目录的限制。4个脚本分别支持调用cmd.exe/哥斯拉/冰蝎/天蝎 客户端。☆174Updated this week
- Web Cache Poisoning Vulnerability Scanner☆32Updated 2 months ago
- 支持常见中间件无文件落地冰蝎内存马注入&&文件上传agent冰蝎马注入☆31Updated last year
- 打造最强的Java安全研究与安全开发面试题库,包含问题和详细的答案,帮助师傅们找到满意的工作☆15Updated 2 years ago
- 《Spring漏洞研究》☆44Updated 2 years ago
- 通过jsp脚本扫描并查杀Tomcat内存马,当前支持Servlet-api、Tomcat-Value、Timer、Websocket 、Upgrade 、ExecutorShell内存马的查杀逻辑。☆49Updated last year
- nacos api bypass & jwt bypass & get all configs☆37Updated last year