shadowsock5 / jackson-databind-POC
☆14Updated 4 years ago
Related projects ⓘ
Alternatives and complementary repositories for jackson-databind-POC
- 一些结合第三方组件的Fastjson POC,在1.2.48以后版本中陆续被添加至黑名单。☆56Updated 5 years ago
- XxlJob<=2.1.2配置不当情况下反序列化RCE☆72Updated 4 years ago
- CVE-2021-43297 POC,Apache Dubbo<= 2.7.13时可以实现RCE☆38Updated 2 years ago
- fastjson 1.2.68 版本 autotype bypass☆140Updated 2 years ago
- Kunlun-M 的GUI程序☆52Updated 2 years ago
- ☆4Updated 4 years ago
- ☆61Updated 4 years ago
- Shiro漏洞实例源码☆25Updated 3 years ago
- ARL官方仓库备份项目+指纹添加工具:ARL(Asset Reconnaissance Lighthouse)资产侦察灯塔系统旨在快速侦察与目标关联的互联网资产,构建基础资产信息库。 协助甲方安全团队或者渗透测试人员有效侦察和检索资产,发现存在的薄弱点和攻击面。☆15Updated 6 months ago
- Automatically scan jar packages by using ast to find fastjson gadgets. In particular, this project is limited to mining Gadgets that may …☆50Updated 2 years ago
- notes☆26Updated 2 years ago
- 打CTF实在厌倦了找利用链,就知道一个fastjson的版本,一堆依赖找啊找,头都疼。为了解决这个烦恼,用了卓卓师傅的fastjson黑名单工具和库,自己改造了一下。☆32Updated 4 years ago
- springboot getRequestURI acl bypass☆37Updated 4 years ago
- CodeQL 寻找 JNDI利用 Lookup接口☆162Updated 2 years ago
- xxl-job RESTful API RCE☆72Updated 3 years ago
- ☆51Updated 2 years ago
- <a href="sumsec.me"><img src="https://readme-typing-svg.demolab.com?font=Fira+Code&size=24&pause=1000&color=FDFDFD&background=13797800&ce…☆53Updated this week
- 记录调试分析ysoserial系列的学习过程,主要包含手动构造的一些poc,便于加深对漏洞和工具的理解☆29Updated 4 years ago
- ThinkPHP各版本反序列化利用代码☆32Updated 4 years ago
- Shiro-721 Padding Oracle Attack☆70Updated 3 years ago
- ☆41Updated 4 years ago
- Java RMI反序列化漏洞插件☆47Updated 3 years ago
- Spring Cloud Netflix Hystrix Dashboard template resolution vulnerability CVE-2021-22053☆37Updated last year
- jre8u20 gadget☆33Updated 3 years ago
- 卸载冰蝎内存马☆68Updated 3 years ago
- bypass JEP290 RaspHook code☆62Updated 4 years ago
- Optical Chain Scanner 光链安全扫描器☆56Updated 3 years ago