Medium-high contributions. High contributions. More 2025 2024 2023 2022 2021 Contribution activity January 2025 javasec has no activity yet for this period. LoadingShow more activity Seeing something unexpected? Take a look at theGitHub profile guide....
java-sec/JavaRcePublic forked fromWhoopsunix/JavaRce NotificationsYou must be signed in to change notification settings Fork0 Star1 main 1Branch0Tags Code This branch is40 commits behindWhoopsunix/JavaRce:main. README JavaRceDemo By. Whoopsunix ...
一、项目背景: Hello-Java-Sec项目为 Github中 一个面向安全开发的 Java漏洞代码审计靶场。 靶场地址:https://github.com/j3ers3/Hello-Java-Sec 本地使用idea部署即可 二、代码审计: 通过阅读代码可知,代码采用 @RequestMap
git clone https://github.com/j3ers3/Hello-Java-Sec.git 配置数据库连接:src/main/resources/application.properties spring.datasource.url=jdbc:mysql://127.0.0.1:3306/test spring.datasource.username=root spring.datasource.password=123456 导入db.sql数据 root@l-virtual-machine:/opt/Hello-Java-Sec# ...
VisualVM is now available as a separate download from https://visualvm.github.io. other-libs/corba ➜ CORBA _DynAnyFactoryStub readObject Accepts Only Stringified ior in IOR: URI format (JDK-8285021 (not public)) The readObject method of _DynAnyFactoryStub has been amended, such that, ...
VisualVM is now available as a separate download from https://visualvm.github.io. other-libs/corba ➜ CORBA _DynAnyFactoryStub readObject Accepts Only Stringified ior in IOR: URI format (JDK-8285021 (not public)) The readObject method of _DynAnyFactoryStub has been amended, such that, ...
通过DFG构建data dependence graph (DDG) ST:summary table,记录component之间的沟通信息(通过RPC等) 可以添加插件 2018年提出的更新大多数是在算法上 主要功能点是在inter-component communication上的bug检出率高,相比较于Flowdroid针对每一个app构建一个model,这个软件细化到component层面。通过上述的图,检查出bug,例如...
1、JavaGuide 地址:https://github.com/Snailclimb/JavaGuide 一份Java学习指南,涵盖大部分Java程序员...
学习java审计,记录以下一些漏洞的原理并且自己写一下代码。漏洞代码:https://github.com/zjhzjhhh/JavaSec谢谢师傅们点个star! 0x01 SSRF详解 SSRF原理: SSRF(Server-Side Request Forgery:服务器端请求伪造) 是一种由攻击者构造形成由服务端发起请求的一个安全漏洞。 攻击的目标是从外网无法访问的内部系统 ( 正是...
https://github.com/JoyChou93/java-sec-code __EOF__ 本文作者:N0r4h 本文链接:https://www.cnblogs.com/N0r4h/p/15873187.html关于博主:一个废物到自闭的人版权声明:本博客所有文章除特别声明外,均采用 BY-NC-SA 许可协议。转载请注明出处!声援博主:如果您觉得文章对您有帮助,可以点击文章右下角【推荐...