A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.
-
Updated
Mar 31, 2024 - Java
A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.
SpringBoot 相关漏洞学习资料,利用方法和技巧合集,黑盒安全评估 check list
溯光 (TrackRay) 3 beta⚡渗透测试框架(资产扫描|指纹识别|暴力破解|网页爬虫|端口扫描|漏洞扫描|代码审计|AWVS|NMAP|Metasploit|SQLMap)
项目是根据LandGrey/SpringBootVulExploit清单编写,目的hvv期间快速利用漏洞、降低漏洞利用门槛。
HummerRisk 是云原生安全平台,包括混合云安全治理和云原生安全检测。
Jar Analyzer - 一个JAR包分析工具,批量分析,SCA漏洞分析,方法调用关系搜索,字符串搜索,Spring组件分析,信息泄露检查,CFG程序分析,JVM栈帧分析,进阶表达式搜索,字节码指令级的动态调试分析,反编译JAR包一键导出,一键提取序列化数据恶意代码,一键分析BCEL字节码
spring boot Fat Jar 任意写文件漏洞到稳定 RCE 利用技巧
MySQL Fake Server (纯Java实现,支持GUI版和命令行版,提供Dockerfile,支持多种常见JDBC利用)
Sample codes written for the Hackers to Hackers Conference magazine 2017 (H2HC).
Joint Advanced Defect assEsment for android applications
OWASP VulnerableApp Project: For Security Enthusiasts by Security Enthusiasts.
JFrog IntelliJ IDEA plugin
一个针对防御 log4j2 CVE-2021-44228 漏洞的 RASP 工具。 A Runtime Application Self-Protection module specifically designed for log4j2 RCE (CVE-2021-44228) defense.
The Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parameters
Vulnerable Client-Server Application (VuCSA) is made for learning how to perform penetration tests of non-http thick clients. It is written in Java (with JavaFX graphical user interface) and contains multiple challenges including SQL injection, RCE, XML vulnerabilities and more.
Java Object Deserialization on Android
CVE-2022-41852 Proof of Concept (unofficial)
The Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parameters
Simple PoC for demonstrating Race Conditions on Websockets
CVE-2023-22515
Add a description, image, and links to the vulnerability topic page so that developers can more easily learn about it.
To associate your repository with the vulnerability topic, visit your repo's landing page and select "manage topics."