JNDI注入测试工具(A tool which generates JNDI links can start several servers to exploit JNDI Injection vulnerability,like Jackson,Fastjson,etc)
80+ Gadgets(30 More than ysoserial). JNDI-Injection-Exploit-Plus is a tool for generating workable JNDI links and provide background services by starting RMI server,LDAP server and HTTP server.
Some payloads of JNDI Injection in JDK 1.8.0_191+
A malicious LDAP server for JNDI injection attacks
A malicious LDAP server for JNDI injection attacks
JNDI注入测试工具内存马版本(增加了注入内存马模块)
JNDI注入测试工具改版(A tool which generates JNDI links can start several servers to exploit JNDI Injection vulnerability,like Jackson,Fastjson,etc)
JNDI Attacking Tool
Log4j jndi injects the Payload generator
PE Injection、DLL Injection、Process Injection、Thread Injection、Code Injection、Shellcode Injection、ELF Injection、Dylib Injection, including 400+Tools and 350+posts
Windows process injection methods
rmi、jndi、ldap、jrmp、jmx、jms一些demo测试
Process Injection
#安全#jSQL Injection is a Java application for automatic SQL database injection.
#安全#sqlmap 是一个开源的渗透测试工具,可以用来自动化的检测,利用SQL注入漏洞,获取数据库服务器的权限。它具有功能强大的检测引擎,针对各种不同类型数据库的渗透测试的功能选项,包括获取数据库中存储的数据,访问操作系统文件甚至可以通过带外数据连接的方式执行操作系统命令。