we1h0 / awesome-java-security-checklist
awesome-java-security-checklist(关于Java安全方面,Java基础/审计/修复/设计/规范)
☆125Updated 5 years ago
Alternatives and similar repositories for awesome-java-security-checklist:
Users that are interested in awesome-java-security-checklist are comparing it to the libraries listed below
- Java编写的Web漏洞靶场☆85Updated 3 years ago
- 渗透 超全面的渗透资料💯 包含:0day,xss,sql注入,提权……☆65Updated 6 years ago
- 规范渗透测试报告中的漏洞名称以及修复建议☆144Updated 5 years ago
- 打造最强的Java安全研究与安全开发面试题库,帮助师傅们找到满意的工作☆181Updated 3 years ago
- 鹏 RocB - Java代码审计IDEA插件 SAST☆147Updated 3 years ago
- 无回显漏洞测试辅助平台,平台使用Java编写,提供DNSLOG,HTTPLOG等功能,辅助渗透测试过程中无回显漏洞及SSRF等漏洞的验证和利用。☆382Updated last year
- CVE-2022-22947☆219Updated 3 years ago
- java decompile audit tools☆224Updated 2 years ago
- 集成crawlergo、xray、dirsearch、nmap等工具的src漏洞挖掘工具,使用docker封装运行;使用oneforall自动遍历子域名并扫描;☆116Updated 4 years ago
- 漏洞挖掘技巧及其一些工具集成☆136Updated 2 years ago
- 应急响应资料收集☆88Updated 4 years ago
- fastjson bypass autotype 1.2.68 with Throwable and AutoCloseable.☆226Updated 2 years ago
- 代码审计总结☆80Updated 3 years ago
- Auto Code Audit Framework for Java☆96Updated 3 years ago
- 又一个Java Web代码审计工具☆99Updated 6 years ago
- A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.优化了一些东西。☆215Updated 3 years ago
- a burp extension to find where use fastjson☆163Updated 4 years ago
- 一款通过污点追踪发现Jsp webshell的工具(A tool to find Jsp Webshell through stain tracking)☆175Updated 3 years ago
- A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.☆355Updated 2 years ago
- 代码审计知识点整理-php☆95Updated 4 years ago
- AnScan是一款集合信息收集、分布式漏洞扫描、漏洞POC管理等为一体的红队扫描工具☆123Updated 2 years ago
- RASP测试靶场☆164Updated 2 years ago
- SpringBoot Actuator未授权自动化利用,支持信息泄漏/RCE☆231Updated 4 years ago
- SQL 注入利用工具,存在waf的情况下自定义编写tamper脚本 dump数据☆287Updated 4 years ago
- 扫描常见未授权访问(redis、mongodb、memcached、elasticsearch、zookeeper、ftp、CouchDB、docker、Hadoop)☆187Updated 4 years ago
- ☆319Updated 3 years ago
- 个人使用CodeQL编写的一些规则☆176Updated 2 years ago
- Demo code for post <Restrictions of JNDI Manipulation RCE & Bypass>☆261Updated 2 years ago
- 云原生安全资料库☆129Updated 2 months ago
- 🐸Unauthorized Detection Framework未授权访问检测框架☆158Updated last year