tcyba / this_is_my_study
this_my_ctf
☆17Updated 3 years ago
Alternatives and similar repositories for this_is_my_study:
Users that are interested in this_is_my_study are comparing it to the libraries listed below
- Spel-research☆26Updated 2 years ago
- 当死去的记忆突然开始攻击我,我终于想起了我还写过一款十分十分垃圾的 rasp 靶场。☆78Updated 2 years ago
- CodeQL 寻找 JNDI利用 Lookup接口☆163Updated 2 years ago
- 收录go语言编写的项目、框架和组件出现的cve,或者一些相关的利用方式的文章☆38Updated 2 years ago
- 《Spring漏洞研究》☆45Updated 2 years ago
- Stick to it☆31Updated 3 years ago
- Shiro漏洞实例源码☆26Updated 3 years ago
- java☆54Updated 2 years ago
- [fastjson 1.2.80] CVE-2022-25845 aspectj fileread & groovy remote classload☆90Updated 2 years ago
- javaweb-codereview☆30Updated 6 years ago
- 一些结合第三方组件的Fastjson POC,在1.2.48以后版本中陆续被添加至黑名单。☆56Updated 5 years ago
- A IntelliJ Plugin for Tabby to Find Vulnerabilities Easily☆33Updated 4 months ago
- Kunlun-M 的GUI程序☆51Updated 2 years ago
- ☆50Updated 2 years ago
- 打CTF实在厌倦了找利用链,就知道一个fastjson的版本,一堆依赖找啊找,头都疼。为了解决这个烦恼,用了卓卓师傅的fastjson黑名单工具和库,自己改造了一下。☆32Updated 5 years ago
- 《JNDI-深入理解Java万恶之源》☆37Updated last year
- 在原有yso基础上实现依赖分离,内存马注入等功能。A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.☆68Updated 3 years ago
- Easy burp sign extension!☆54Updated last month
- A vul-finder for loading CPG and automated finding vul-call-chains☆40Updated 5 months ago
- 《ASPX安全-只有ASPX安全才能拯救.NET》Only ASPX Security Can Save The NET.☆33Updated 2 years ago
- 在spring-aop中新发现的反序列化gadget-chain☆43Updated 2 months ago
- Java 内存马生成插件☆50Updated last year
- Apache Dubbo Hessian2 CVE-2021-43297 demo☆46Updated 3 years ago
- 一个简单的批量反编译jar包的小脚本☆35Updated 2 years ago
- CVE-2021-43297 POC,Apache Dubbo<= 2.7.13时可以实现RCE☆38Updated 3 years ago
- Apache Dubbo漏洞测试Demo及其POC☆61Updated last year
- JWT秘钥爆破脚本☆28Updated last year
- 本工具的定位是快速生成Java安全相关的Payload,如内存马、反序列化链、JNDI url、Fastjson等,动态生成相关Payload,并附带相应的文档。☆91Updated 2 weeks ago
- Java命令行文件监控小工具(代码审计)☆100Updated 3 years ago
- JSHunter-一款针对于前端的未授权访问扫描工具☆20Updated 6 months ago