|
3 | 3 |
|
4 | 4 | Java sec code is a very powerful and friendly project for learning Java vulnerability code. |
5 | 5 |
|
6 | | -[中文文档](https://github.com/JoyChou93/java-sec-code/blob/master/README_zh.md) 😋[Alibaba Security Purple Team Recruitment](https://talent.alibaba.com/off-campus-position/937731?trace=qrcode_share) |
| 6 | +[中文文档](https://github.com/JoyChou93/java-sec-code/blob/master/README_zh.md) 😋 |
| 7 | + |
| 8 | +## Recruitment |
| 9 | + |
| 10 | +[Alibaba-Security attack and defense/research(P5-P7)](https://github.com/JoyChou93/java-sec-code/wiki/Alibaba-Purple-Team-Job-Description) |
| 11 | + |
7 | 12 |
|
8 | 13 | ## Introduce |
9 | 14 |
|
@@ -41,12 +46,14 @@ Sort by letter. |
41 | 46 | - [Log4j](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/controller/Log4j.java) |
42 | 47 | - [ooxmlXXE](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/controller/othervulns/ooxmlXXE.java) |
43 | 48 | - [PathTraversal](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/controller/PathTraversal.java) |
| 49 | +- [QLExpress](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/controller/QLExpress.java) |
44 | 50 | - [RCE](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/controller/Rce.java) |
45 | 51 | - Runtime |
46 | 52 | - ProcessBuilder |
47 | 53 | - ScriptEngine |
48 | 54 | - Yaml Deserialize |
49 | 55 | - Groovy |
| 56 | +- [Shiro](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/controller/Shiro.java) |
50 | 57 | - [Swagger](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/config/SwaggerConfig.java) |
51 | 58 | - [SpEL](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/controller/SpEL.java) |
52 | 59 | - [SQL Injection](https://github.com/JoyChou93/java-sec-code/blob/master/src/main/java/org/joychou/controller/SQLI.java) |
@@ -145,7 +152,7 @@ Viarus |
145 | 152 | Example: |
146 | 153 |
|
147 | 154 | ``` |
148 | | -http://localhost:8080/java-sec-code-1.0.0/rce/exec?cmd=whoami |
| 155 | +http://localhost:8080/java-sec-code-1.0.0/rce/runtime/exec?cmd=whoami |
149 | 156 | ``` |
150 | 157 |
|
151 | 158 | return: |
@@ -203,12 +210,6 @@ Core developers : [JoyChou](https://github.com/JoyChou93), [liergou9981](https:/ |
203 | 210 | Other developers: [lightless](https://github.com/lightless233), [Anemone95](https://github.com/Anemone95), [waderwu](https://github.com/waderwu). |
204 | 211 |
|
205 | 212 |
|
206 | | -## Donate |
207 | | - |
208 | | -If you like the poject, you can donate to support me. With your support, I will be able to make `Java sec code` better 😎. |
209 | | - |
210 | | -### Alipay |
211 | | - |
212 | | -Scan the QRcode to support `Java sec code`. |
| 213 | +## Support |
213 | 214 |
|
214 | | -<img title="Alipay QRcode" src="https://aliyun-testaaa.oss-cn-shanghai.aliyuncs.com/alipay_qr.png" width="200"> |
| 215 | +If you like the poject, you can star java-sec-code project to support me. With your support, I will be able to make `Java sec code` better 😎. |
0 commit comments