Java
CtrlK
  • About This Book
  • 🍖Prerequisites
    • 反射
    • 类加载
    • RMI & JNDI
    • Misc
  • 👻Serial Journey
    • URLDNS
    • SerialVersionUID
    • Commons Collection 🥏
    • FastJson 🪁
    • Other Components
  • 🌵RASP
    • JavaAgent
    • JVM
    • ByteCode
    • JNI
    • ASM 🪡
    • Rasp防御命令执行
    • OpenRASP
  • 🐎Memory Shell
    • Tomcat-Architecture
    • Servlet API
    • Tomcat-Middlewares
    • Agent MemShell
    • WebSocket
    • 内存马查杀
    • IDEA本地调试Tomcat
  • ✂️JDBC Attack
    • MySQL JDBC Attack
    • H2 JDBC Attack
  • 🎨Templates
    • FreeMarker
    • Thymeleaf
    • Enjoy
  • 🎏MessageQueue
    • ActiveMQ CNVD-2023-69477
    • AMQP CVE-2023-34050
    • Spring-Kafka CVE-2023-34040
    • RocketMQ CVE-2023-33246
  • 🛡️Shiro
    • Shiro Intro
    • Request URI ByPass
    • Context Path ByPass
    • Remember Me反序列化 CC-Shiro
    • CB1与无CC依赖的反序列化链
  • 🍺Others
    • Deserialization Twice
    • A New Blazer 4 getter RCE
    • Apache Commons Jxpath
    • El Attack
    • Spel Attack
    • C3P0原生反序列化的JNDI打法
    • Log4j
    • Echo Tech
    • CTF 🚩
      • 长城杯-b4bycoffee (ROME反序列化)
      • MTCTF2022(CB+Shiro绕过)
      • CISCN 2023 西南赛区半决赛 (Hessian原生JDK+Kryo反序列化)
      • CISCN 2023 初赛 (高版本Commons Collections下其他依赖的利用)
      • CISCN 2021 总决赛 ezj4va (AspectJWeaver写字节码文件到classpath)
      • D^3CTF2023 (新的getter+高版本JNDI不出网+Hessian异常toString)
      • WMCTF2023(CC链花式玩法+盲读文件)
      • 第六届安洵杯网络安全挑战赛(CB PriorityQueue替代+Postgresql JDBC Attack+FreeMarker)
  • 🔍Code Inspector
    • CodeQL 🧶
    • SootUp ✨
    • Tabby 🔦
    • Theory
Powered by GitBook
On this page

Was this helpful?

  1. 🍺Others

CTF 🚩

长城杯-b4bycoffee (ROME反序列化)MTCTF2022(CB+Shiro绕过)CISCN 2023 西南赛区半决赛 (Hessian原生JDK+Kryo反序列化)CISCN 2023 初赛 (高版本Commons Collections下其他依赖的利用)CISCN 2021 总决赛 ezj4va (AspectJWeaver写字节码文件到classpath)D^3CTF2023 (新的getter+高版本JNDI不出网+Hessian异常toString)WMCTF2023(CC链花式玩法+盲读文件)第六届安洵杯网络安全挑战赛(CB PriorityQueue替代+Postgresql JDBC Attack+FreeMarker)
PreviousSpringBoot Under TomcatNext长城杯-b4bycoffee (ROME反序列化)

Last updated 1 year ago

Was this helpful?