|
12 | 12 |
|
13 | 13 | ## 漏洞代码 |
14 | 14 |
|
15 | | -- [XXE](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/controller/XXE.java) |
16 | | -- [SSRF](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/controller/SSRF.java) |
17 | | -- [URL重定向](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/controller/URLRedirect.java) |
18 | | -- [IP伪造](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/controller/IPForge.java) |
19 | | -- [XSS](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/controller/XSS.java) |
20 | | -- [CRLF注入](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/controller/CRLFInjection.java) |
21 | | -- [远程命令执行](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/controller/Rce.java) |
22 | | -- [反序列化](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/controller/Deserialize.java) |
23 | | -- [文件上传](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/controller/FileUpload.java) |
24 | | -- [SQL注入](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/controller/SQLI.java) |
25 | | -- [URL白名单Bypass](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/controller/URLWhiteList.java) |
26 | | -- [Java RMI](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/RMI/Server.java) |
27 | | -- [Fastjson](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/controller/Fastjson.java) |
| 15 | +- [Actuators to RCE](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/resources/logback.xml) |
28 | 16 | - [CORS](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/controller/CORS.java) |
| 17 | +- [CRLF Injection](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/controller/CRLFInjection.java) |
| 18 | +- [CSRF](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/WebSecurityConfig.java) |
| 19 | +- [Deserialize](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/controller/Deserialize.java) |
| 20 | +- [Fastjson](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/controller/Fastjson.java) |
| 21 | +- [File Upload](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/controller/FileUpload.java) |
| 22 | +- [IP Forge](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/controller/IPForge.java) |
| 23 | +- [Java RMI](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/RMI/Server.java) |
29 | 24 | - [JSONP](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/controller/JSONP.java) |
| 25 | +- [RCE](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/controller/Rce.java) |
30 | 26 | - [SPEL](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/controller/SPEL.java) |
31 | | -- [Actuators to RCE](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/resources/logback.xml) |
32 | | -- [CSRF](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/WebSecurityConfig.java) |
| 27 | +- [SQL Injection](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/controller/SQLI.java) |
| 28 | +- [SSRF](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/controller/SSRF.java) |
| 29 | +- [URL Redirect](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/controller/URLRedirect.java) |
| 30 | +- [URL whitelist Bypass](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/controller/URLWhiteList.java) |
| 31 | +- [XSS](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/controller/XSS.java) |
| 32 | +- [XXE](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/controller/XXE.java) |
| 33 | + |
33 | 34 |
|
34 | 35 | ## 漏洞说明 |
35 | 36 |
|
36 | | -- [Java RMI](https://github.com/JoyChou93/java-sec-code/wiki/Java-RMI) |
37 | | -- [XXE](https://github.com/JoyChou93/java-sec-code/wiki/XXE) |
38 | | -- [SQLI](https://github.com/JoyChou93/java-sec-code/wiki/SQL-Inject) |
39 | | -- [Fastjson](https://github.com/JoyChou93/java-sec-code/wiki/Fastjson) |
| 37 | +- [Actuators to RCE](https://github.com/JoyChou93/java-sec-code/wiki/Actuators-to-RCE) |
40 | 38 | - [CORS](https://github.com/JoyChou93/java-sec-code/wiki/CORS) |
41 | 39 | - [CSRF](https://github.com/JoyChou93/java-sec-code/wiki/CSRF) |
| 40 | +- [Fastjson](https://github.com/JoyChou93/java-sec-code/wiki/Fastjson) |
| 41 | +- [Java RMI](https://github.com/JoyChou93/java-sec-code/wiki/Java-RMI) |
42 | 42 | - [JSONP](https://github.com/JoyChou93/java-sec-code/wiki/JSONP) |
43 | | -- [Actuators to RCE](https://github.com/JoyChou93/java-sec-code/wiki/Actuators-to-RCE) |
| 43 | +- [SQLI](https://github.com/JoyChou93/java-sec-code/wiki/SQL-Inject) |
| 44 | +- [SSRF](https://github.com/JoyChou93/java-sec-code/wiki/SSRF) |
44 | 45 | - [URL whitelist Bypass](https://github.com/JoyChou93/java-sec-code/wiki/URL-whtielist-Bypass) |
| 46 | +- [XXE](https://github.com/JoyChou93/java-sec-code/wiki/XXE) |
45 | 47 | - [Others](https://github.com/JoyChou93/java-sec-code/wiki/others) |
46 | 48 |
|
47 | 49 |
|
|
0 commit comments