TongASDP漏洞测试环境
☆35Mar 22, 2023Updated 3 years ago
Alternatives and similar repositories for tongasdp-test
Users that are interested in tongasdp-test are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- WALA 学习笔记☆14Aug 8, 2023Updated 2 years ago
- ☆41Mar 10, 2021Updated 5 years ago
- nativeRasp that can hook native methods☆23Apr 24, 2023Updated 3 years ago
- Low-level RASP: Protecting Applications Implemented in High-level Programming Languages☆71Oct 19, 2025Updated 9 months ago
- cve-2022-34169 延伸出的Jdk Xalan的payload自动生成工具,可根据不同的Jdk生成出其所对应的xslt文件☆94Jan 17, 2023Updated 3 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- JAVA IAST Example☆48Dec 13, 2021Updated 4 years ago
- Apache Shiro CVE-2022-32532☆13Jun 28, 2022Updated 4 years ago
- A declarative static analysis tool for jvm bytecode based Datalog like CodeQL☆341Jan 6, 2024Updated 2 years ago
- A PHP code transformer to provide protection against injection attacks☆10Jul 11, 2011Updated 15 years ago
- 基于JVM-Sandbox实现RASP安全监控防护☆51Aug 8, 2023Updated 2 years ago
- 识别操作系统指纹☆20Jan 17, 2022Updated 4 years ago
- ☆21Jan 16, 2024Updated 2 years ago
- Finding Java/C# gadget chains with CodeQL☆188Jun 22, 2026Updated last month
- CodeQL 寻找 JNDI利用 Lookup接口☆167Apr 10, 2022Updated 4 years ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- ☆15Aug 6, 2021Updated 4 years ago
- https://github.com/GrrrDog/Java-Deserialization-Cheat-Sheet☆54Sep 11, 2021Updated 4 years ago
- goon,是一款基于golang开发的扫描工具,暂时支持portscan、webscan、titlescan、dirscan、fofascan、pluginscan等模块功能,当然也支持将这些模块联动起来的autoscan。后期也会慢慢加入其他零件模块,感谢您的使用,也希望…☆10Jun 28, 2021Updated 5 years ago
- 自动反编译闭源应用,创建codeql数据库☆318Mar 2, 2022Updated 4 years ago
- SpringBootAdmin-thymeleaf-SSTI which can cause RCE☆88Jul 18, 2023Updated 3 years ago
- 超硬核!使用图数据技术发现软件漏洞☆184Sep 1, 2021Updated 4 years ago
- spring boot Fat Jar 任意写文件漏洞到稳定 RCE 利用技巧☆760Apr 14, 2021Updated 5 years ago
- tomcat使用了自带session同步功能时,不安全的配置(没有使用EncryptInterceptor)导致存在的反序列化漏洞,通过精心构造的数据包, 可以对使用了tomcat自带session同步功能的服务器进行攻击。PS:这个不是CVE-2020-9484,9484…☆214May 19, 2020Updated 6 years ago
- fastjson 1.2.68 版本 autotype bypass☆141Jun 17, 2022Updated 4 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- fastjson-1.2.61-RCE☆33Sep 26, 2019Updated 6 years ago
- analysis java dependence and store in neo4j☆18Oct 22, 2018Updated 7 years ago
- Slides/Demos from the BSides Munich 2019 talk "Attacking Java RMI in 2019"☆101Sep 20, 2019Updated 6 years ago
- 一个利用ASM对字节码进行污点传播分析的静态代码审计应用(添加了大量代码注释,适合大家进行源码学习)。也加入了挖掘Fastjson反序列化gadget chains和SQLInject(JdbcTemplate、MyBatis、JPA、Hibernate、原生jdbc等)静…☆455Mar 24, 2022Updated 4 years ago
- RASP测试靶场☆190Dec 22, 2022Updated 3 years ago
- ☆153Jun 24, 2019Updated 7 years ago
- Basic code for creating the Alibaba FastJson + Spring gadget chain, as used to exploit Apache Dubbo in CVE-2019-17564 - more information …☆16Dec 10, 2022Updated 3 years ago
- Django QuerySet.annotate(), aggregate(), extra() SQL 注入☆24May 31, 2022Updated 4 years ago
- A helpful Java Deserialization exploit framework.☆1,246Feb 17, 2025Updated last year
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- ☆11Jun 27, 2026Updated last month
- bypass JEP290 RaspHook code☆63Sep 21, 2020Updated 5 years ago
- fastjson auto type derivation search☆22Aug 19, 2021Updated 4 years ago
- fastjson bypass autotype 1.2.68 with Throwable and AutoCloseable.☆229Oct 12, 2022Updated 3 years ago
- Weblogic coherence.jar RCE☆176May 10, 2020Updated 6 years ago
- xAST评价体系,让安全工具不再“黑盒”. The xAST evaluation benchmark makes security tools no longer a "black box".☆485May 21, 2026Updated 2 months ago
- 《深入理解SAST静态应用安全测试》Static Application Security Testing.☆399Sep 28, 2025Updated 10 months ago