h30gyan Goto Github PK
Type: User
Bio: Only For JavaSec Learning.
Type: User
Bio: Only For JavaSec Learning.
JavaAgent学习研究项目
快速定位重要代码段
Tomcat8.5.68源码调试IDEA项目
网络安全、Java安全、漏洞分析、代码审计
Java安全☞代码审计/漏洞分析/武器化
awesome-java-security-checklist(关于Java安全方面,Java基础/审计/修复/设计/规范)
BCEL编解码工具
冰蝎客户端源码-V4.0.2
字节码工具
This is the public repository for the CFR Java decompiler
一款使用Yaml定义搜索规则来搜索Class的工具
《深入理解CodeQL》Finding vulnerabilities with CodeQL.
优质的codeql二开规则,持续更新!
记录学习codeql的过程
CodeQLpy是一款基于CodeQL实现的半自动化代码审计工具,目前仅支持java语言。实现从源码反编译,数据库生成,脆弱性发现的全过程,可以辅助代码审计人员快速定位源码可能存在的漏洞。
CVE-2022-22947 注入Godzilla内存马
Some ReadObject Sink With JDBC
就是一个练习Java反序列化的最简单环境
Apache Dubbo漏洞测试Demo及其POC
version<1.2.51 远程命令执行
fastjson bypass autotype 1.2.68 with Throwable and AutoCloseable.
fastjson不出网利用、c3p0
fastjson利用,支持tomcat、spring回显,哥斯拉内存马;回显利用链为dhcp、ibatis、c3p0。
基于dbcp的fastjson rce 回显
fastjson 80 远程代码执行漏洞复现
FastJson全版本Docker漏洞环境(涵盖1.2.47/1.2.68/1.2.80等版本),主要包括JNDI注入及高版本绕过、waf绕过、文件读写、原生反序列化、利用链探测绕过、不出网利用等。从黑盒的角度覆盖FastJson深入利用
[fastjson 1.2.80] CVE-2022-25845 aspectj fileread & groovy remote classload
A declarative, efficient, and flexible JavaScript library for building user interfaces.
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
An Open Source Machine Learning Framework for Everyone
The Web framework for perfectionists with deadlines.
A PHP framework for web artisans
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
Some thing interesting about web. New door for the world.
A server is a program made to process requests and deliver data to clients.
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
Some thing interesting about visualization, use data art
Some thing interesting about game, make everyone happy.
We are working to build community through open source technology. NB: members must have two-factor auth.
Open source projects and samples from Microsoft.
Google ❤️ Open Source for everyone.
Alibaba Open Source for everyone
Data-Driven Documents codes.
China tencent open source team.