#

jndi

https://static.github-zh.com/github_avatars/feihong-cs?size=40

A malicious LDAP server for JNDI injection attacks

Java 953
4 年前
https://static.github-zh.com/github_avatars/cckuailong?size=40

80+ Gadgets(30 More than ysoserial). JNDI-Injection-Exploit-Plus is a tool for generating workable JNDI links and provide background services by starting RMI server,LDAP server and HTTP server.

Java 831
1 年前
https://static.github-zh.com/github_avatars/wuba?size=40

Antenna是58同城安全团队打造的一款辅助安全从业人员验证网络中多种漏洞是否存在以及可利用性的工具。其基于带外应用安全测试(OAST)通过任务的形式,将不同漏洞场景检测能力通过插件的形式进行集合,通过与目标进行out-bind的数据通信方式进行辅助检测。

JavaScript 716
2 年前
https://static.github-zh.com/github_avatars/Whoopsunix?size=40

Common Exploitation Techniques for Java RCE Vulnerabilities in Real-World Scenarios | 实战场景较通用的 Java Rce 相关漏洞的利用方式

Java 528
6 个月前
https://static.github-zh.com/github_avatars/X1r0z?size=40

A powerful JNDI injection exploitation framework that supports RMI, LDAP and LDAPS protocols, including various bypass methods for high-version JDK restrictions

Java 490
8 天前
https://static.github-zh.com/github_avatars/0x727?size=40

一款用于JNDI注入利用的工具,大量参考/引用了Rogue JNDI项目的代码,支持直接植入内存shell,并集成了常见的bypass 高版本JDK的方式,适用于与自动化工具配合使用。

Java 350
3 年前
https://static.github-zh.com/github_avatars/r00tSe7en?size=40

一个LDAP请求监听器,摆脱dnslog平台

Java 293
2 年前
https://static.github-zh.com/github_avatars/alexbakker?size=40

Tool that runs a test to check whether one of your applications is affected by the recent vulnerabilities in log4j: CVE-2021-44228 and CVE-2021-45046

Go 86
1 年前
https://static.github-zh.com/github_avatars/future-client?size=40

Abuse Log4J CVE-2021-44228 to patch CVE-2021-44228 in vulnerable Minecraft game sessions to prevent exploitation in the session :)

Java 67
4 年前
https://static.github-zh.com/github_avatars/For-ACGN?size=40

Check, exploit, generate class, obfuscate, TLS, ACME about log4j2 vulnerability in one Go program.

Go 56
4 年前
https://static.github-zh.com/github_avatars/cokeBeer?size=40

pyyso is a Python package that generate java serialized poc. Including CommonsCollections1-7, JDK7u21, JDK8u20, ldap for jndi, shiro-550, CommonsBeanutils1 no cc, JRMPClient, high version JDK Bypass, ...

Python 52
3 年前
https://static.github-zh.com/github_avatars/HackJava?size=40

《JNDI-深入理解Java万恶之源》

38
2 年前
https://static.github-zh.com/github_avatars/Al1ex?size=40

CVE-2021-2109 && Weblogic Server RCE via JNDI

Java 31
5 年前
https://static.github-zh.com/github_avatars/ncredinburgh?size=40

#安全#A drop in replacement for the standard Tomcat DataSourceFactory that allows the database connection password to be encrypted using a symmetric key for the purposes of security.

Java 15
6 年前
https://static.github-zh.com/github_avatars/LoliKingdom?size=40

Selection of ways to remove JndiLookup in now obsolete Minecraft versions, or versions that still have log4j < 2.10 and is unable to use `-Dlog4j2.formatMsgNoLookups=true`

Java 12
4 年前
https://static.github-zh.com/github_avatars/rakutentech?size=40

A minimalistic LDAP server that is meant for test vulnerability to JNDI+LDAP injection attacks in Java, especially CVE-2021-44228.

Go 11
4 年前
loading...
Website
Wikipedia