Skip to content

Commit 67b32aa

Browse files
authored
Merge branch 'JoyChou93:master' into master
2 parents a8b2a41 + 4711f4e commit 67b32aa

33 files changed

+659
-492
lines changed

README.md

Lines changed: 11 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,12 @@
33

44
Java sec code is a very powerful and friendly project for learning Java vulnerability code.
55

6-
[中文文档](https://github.com/JoyChou93/java-sec-code/blob/master/README_zh.md) 😋[Alibaba Security Purple Team Recruitment](https://talent.alibaba.com/off-campus-position/937731?trace=qrcode_share)
6+
[中文文档](https://github.com/JoyChou93/java-sec-code/blob/master/README_zh.md) 😋
7+
8+
## Recruitment
9+
10+
[Alibaba-Security attack and defense/research(P5-P7)](https://github.com/JoyChou93/java-sec-code/wiki/Alibaba-Purple-Team-Job-Description)
11+
712

813
## Introduce
914

@@ -41,12 +46,14 @@ Sort by letter.
4146
- [Log4j](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/controller/Log4j.java)
4247
- [ooxmlXXE](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/controller/othervulns/ooxmlXXE.java)
4348
- [PathTraversal](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/controller/PathTraversal.java)
49+
- [QLExpress](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/controller/QLExpress.java)
4450
- [RCE](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/controller/Rce.java)
4551
- Runtime
4652
- ProcessBuilder
4753
- ScriptEngine
4854
- Yaml Deserialize
4955
- Groovy
56+
- [Shiro](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/controller/Shiro.java)
5057
- [Swagger](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/config/SwaggerConfig.java)
5158
- [SpEL](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/controller/SpEL.java)
5259
- [SQL Injection](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/controller/SQLI.java)
@@ -145,7 +152,7 @@ Viarus
145152
Example:
146153

147154
```
148-
http://localhost:8080/java-sec-code-1.0.0/rce/exec?cmd=whoami
155+
http://localhost:8080/java-sec-code-1.0.0/rce/runtime/exec?cmd=whoami
149156
```
150157

151158
return:
@@ -203,12 +210,6 @@ Core developers : [JoyChou](https://github.com/JoyChou93), [liergou9981](https:/
203210
Other developers: [lightless](https://github.com/lightless233), [Anemone95](https://github.com/Anemone95), [waderwu](https://github.com/waderwu).
204211

205212

206-
## Donate
207-
208-
If you like the poject, you can donate to support me. With your support, I will be able to make `Java sec code` better 😎.
209-
210-
### Alipay
211-
212-
Scan the QRcode to support `Java sec code`.
213+
## Support
213214

214-
<img title="Alipay QRcode" src="https://aliyun-testaaa.oss-cn-shanghai.aliyuncs.com/alipay_qr.png" width="200">
215+
If you like the poject, you can star java-sec-code project to support me. With your support, I will be able to make `Java sec code` better 😎.

README_zh.md

Lines changed: 10 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,11 @@
22

33
对于学习Java漏洞代码来说,`Java Sec Code`是一个非常强大且友好的项目。
44

5-
[英文文档](https://github.com/JoyChou93/java-sec-code/blob/master/README.md) 😋[阿里集团安全紫军招聘](https://talent.alibaba.com/off-campus-position/937731?trace=qrcode_share)
5+
[英文文档](https://github.com/JoyChou93/java-sec-code/blob/master/README.md) 😋
6+
7+
## 招聘
8+
9+
[Alibaba招聘-安全攻防/研究(P5-P7)](https://github.com/JoyChou93/java-sec-code/wiki/Alibaba-Purple-Team-Job-Description)
610

711
## 介绍
812

@@ -36,12 +40,14 @@ joychou/joychou123
3640
- [Log4j](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/controller/Log4j.java)
3741
- [ooxmlXXE](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/controller/othervulns/ooxmlXXE.java)
3842
- [PathTraversal](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/controller/PathTraversal.java)
43+
- [QLExpress](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/controller/QLExpress.java)
3944
- [RCE](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/controller/Rce.java)
4045
- Runtime
4146
- ProcessBuilder
4247
- ScriptEngine
4348
- Yaml Deserialize
4449
- Groovy
50+
- [Shiro](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/controller/Shiro.java)
4551
- [SpEL](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/controller/SpEL.java)
4652
- [SQL Injection](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/controller/SQLI.java)
4753
- [SSRF](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/controller/SSRF.java)
@@ -137,7 +143,7 @@ Viarus
137143
例子:
138144

139145
```
140-
http://localhost:8080/java-sec-code-1.0.0/rce/exec?cmd=whoami
146+
http://localhost:8080/java-sec-code-1.0.0/rce/runtime/exec?cmd=whoami
141147
```
142148

143149
返回:
@@ -193,12 +199,7 @@ Tomcat默认JSESSION会话有效时间为30分钟,所以30分钟不操作会
193199

194200
核心开发者: [JoyChou](https://github.com/JoyChou93).其他开发者:[lightless](https://github.com/lightless233), [Anemone95](https://github.com/Anemone95)。欢迎各位提交PR。
195201

196-
## 捐赠
197-
198-
如果你喜欢这个项目,你可以捐款来支持我。 有了你的支持,我将能够更好地制作`Java sec code`项目。
199-
200-
### Alipay
202+
## 支持
201203

202-
扫描支付宝二维码支持`Java sec code`
204+
如果你喜欢这个项目,你可以star该项目支持我。 有了你的支持,我将能够更好地制作`Java sec code`项目
203205

204-
<img title="Alipay QRcode" src="https://aliyun-testaaa.oss-cn-shanghai.aliyuncs.com/alipay_qr.png" width="200">

docker-compose.yml

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,11 @@
1-
version : '2'
1+
version : '3'
22
services:
33
jsc:
44
image: joychou/jsc:latest
5+
command: ["java", "-Xdebug", "-Xrunjdwp:transport=dt_socket,server=y,suspend=n,address=0.0.0.0:8000", "-jar", "jsc.jar"]
56
ports:
67
- "8080:8080"
8+
- "8000:8000"
79
links:
810
- j_mysql
911

0 commit comments

Comments
 (0)