securingdev / custom-codeql-queries
Custom / Experimental CodeQL queries
☆37Updated 2 years ago
Alternatives and similar repositories for custom-codeql-queries:
Users that are interested in custom-codeql-queries are comparing it to the libraries listed below
- An example repository that demonstrates how the build custom CodeQL bundles that include query customizations through the `Customizations…☆25Updated 2 years ago
- GreHack 2021 CodeQL for Java workshop☆75Updated 3 years ago
- A project demonstrating an app that is vulnerable to Spring Security authorization bypass CVE-2022-31692☆36Updated 2 years ago
- ☆71Updated 2 years ago
- My CodeQL queries collection☆96Updated last year
- Dependencies with Log4j2 Checklist☆35Updated 3 years ago
- Unofficial Dockerfile and scripts for building CodeQL databases for the OpenJDK☆48Updated last year
- Several XStream gadgets ported from ysoserial☆32Updated 3 years ago
- 收集规则☆30Updated 2 years ago
- Place for random PoCs☆17Updated 4 years ago
- Library for manually creating Java serialization data.☆29Updated 2 years ago
- ☆54Updated 3 years ago
- ☆28Updated 3 years ago
- Ready to use docker image for CodeQL☆88Updated last year
- PaddingZip is a tool that you can craft a zip file that contains the padding characters between the file content.☆62Updated 2 years ago
- CodeQL model generation for Go.☆17Updated 3 years ago
- bypass JEP290 RaspHook code☆62Updated 4 years ago
- ☆22Updated 2 years ago
- Apache/Alibaba Dubbo <= 2.7.3 PoC Code for CVE-2021-25641 RCE via Deserialization of Untrusted Data; Affects Versions <= 2.7.6 With Diffe…☆52Updated 3 years ago
- My solution for GitHub Security Lab CTF 4: CodeQL and Chill - The Java Edition☆19Updated 4 years ago
- bugbounty tools☆18Updated last year
- ☆15Updated 3 years ago
- ☆33Updated 2 years ago
- log4j 1.x RCE Poc -- CVE-2021-4104☆20Updated 3 years ago
- ☆73Updated 2 years ago
- Sample Spring application to Demonstrate the Gateway Actuator☆47Updated 3 years ago
- POC for leaking java version through file and ftp protocols☆24Updated 4 years ago
- CVE-2020-36179~82 Jackson-databind SSRF&RCE☆80Updated 4 years ago
- CVE-2021-4204: Linux Kernel eBPF Local Privilege Escalation☆61Updated 2 years ago
- Java After-Deserialization Attack☆79Updated 3 years ago