阿信

Elite
@Maskhe

梦想是成为美少女战士

javasec. 自己学习java安全的一些总结,主要是安全审计相关

1.7k

FastjsonScan. 一个简单的Fastjson反序列化检测burp插件

980

CVE-2020-15148-bypasses. 几条关于CVE-2020-15148(yii2反序列化)的绕过

75

vuls. 收集整理一些漏洞,利用方法,poc等等,方便快速查阅

58

BugBountyNotes. 简单记录下自己在挖掘SRC

33

webshell_bypass_research. 自己零零散散研究以及收集的一些免杀技巧,以便为后续查阅,拓宽思路

14

cve-2020-2555. CVE-2020-2555

14

genealogy. 利用二叉树实现一个简单的家谱管理系统

12

xssprobe. xss探针

11

AxinSAST. Java

10

xss-me. 为了方便快速搭建,把网上流传的改进版的xss.me用docker进行部署

9

evil_ftp. Python

7

xxeDemo. Java

5

vulcheck-java-agent. Java

5

DongTai-agent-java. Java Agent is a Java application probe of DongTai IAST, which collects method invocation data during runtime of Java application by dynamic hooks.

1

codespace_demo. EJS

1

DongTai-engine. DongTai-engine used to analyze the method data collected by the probe, analyze whether there are vulnerabilities in API requests through the algorithm of taint tracking, and is also responsible for timing tasks, including: expired log cleaning, probe state maintenance, data packet replay processing, etc.

1

DongTai. DongTai is an interactive application security testing(IAST) product that supports the detection of OWASP WEB TOP 10 vulnerabilities, multi-request related vulnerabilities (including logic vulnerabilities, unauthorized access vulnerabilities, etc.), third-party component vulnerabilities, etc.

1

obsidian-plugin-demo. obsidian plugin learning demo

1

mosec-composer-plugin. 用于检测composer项目的第三方依赖组件是否存在安全漏洞。

1

dongtai-core. Provides the Django Model class that the DongTai project depends on, the Django API abstract class of the DongTai project, the vulnerability detection engine, constants, documents, etc.

1

mosec-node-plugin. 用于检测 node 项目的第三方依赖组件是否存在安全漏洞。

1

django-filter-tables2-admin. A demo of customized admin developed with django-filter and django-tables2

1

composer-demo.

1

Maskhe. test

1

pentest_tools. C

1

rmi_codebase_poc. Java

1

CVE-2021-21300.

1

test.

1

rmi_cve20173241. Java

1
30
Apply