A hands-on simulation of CVE-2017-5638 (Apache Struts2 RCE), showcasing exploit reproduction, OS-level command execution, and mitigations such as input sanitization and endpoint monitoring. Built in Python/Flask with Jupyter notebook demosEducational repo demonstrating real-world software vulnerabilities: Apache Struts2 CVE-2017-5638 RCE, data exfiltration, weak encryption, and mitigation strategies (sanitization, monitoring, crypto best practices).
Red team vs blue team demo of OS security flaws: exploit, persistence (backdoor), and defense techniques (monitoring, TLS validation).
登录后查看神龙缓存的 POC 文件快照
登录查看