From 0dd66fafe52afe814740b408766da60e70e69094 Mon Sep 17 00:00:00 2001 From: xx <0x7fancyxx@gmail.com> Date: Mon, 25 Sep 2023 11:59:08 +0800 Subject: [PATCH] weekly update at 2023-09-25 --- README.md | 48 ++++++------- allprojects.md | 24 +++---- detail/Tai-e.md | 152 +++++++++++++++++++++++++++++++--------- detail/Viper.md | 32 +++++---- information_analysis.md | 19 ++--- party_a.md | 19 +++-- penetration_test.md | 2 +- 7 files changed, 192 insertions(+), 104 deletions(-) diff --git a/README.md b/README.md index 289ee84..6d2deb1 100644 --- a/README.md +++ b/README.md @@ -17,8 +17,9 @@ | 时间 | 项目名称 | 项目动态 | |----|-----------|--------------------------| +|2023-09-24|[**Viper**](detail/Viper.md)|更新 [v20230924](detail/Viper.md#最近更新) 版本| +|2023-09-23|[**Tai-e**](detail/Tai-e.md)|更新 [v0.2.2](detail/Tai-e.md#最近更新) 版本| |2023-09-18|[**afrog**](detail/afrog.md)|更新 [v2.8.1](detail/afrog.md#最近更新) 版本| -|2023-09-14|[**Viper**](detail/Viper.md)|更新 [v20230914](detail/Viper.md#最近更新) 版本| |2023-09-13|[**Tai-e**](detail/Tai-e.md)|Tai-e加入星链计划| |2023-09-12|[**vArmor**](detail/vArmor.md)|更新 [v0.5.3](detail/vArmor.md#最近更新) 版本| |2023-08-31|[**vArmor**](detail/vArmor.md)|vArmor加入星链计划| @@ -26,28 +27,27 @@ |2023-08-21|[**GShark**](detail/gshark.md)|更新 [v1.2.1](detail/gshark.md#最近更新) 版本| |2023-08-16|[**ENScanGo**](detail/ENScanGo.md)|更新 [v0.0.15](detail/ENScanGo.md#最近更新) 版本| |2023-08-11|[**JYso**](detail/JYso.md)|更新 [v3.4.0](detail/JYso.md#最近更新) 版本| -|2023-07-26|[**veinmind-tools**](detail/veinmind-tools.md)|更新 [v2.1.5](detail/veinmind-tools.md#最近更新) 版本| **2.StarRank** | 序号 | 项目名称 | 项目简介 | Star | |----|-----------|--------------------------|----| -|1|[**HackBrowserData**](detail/HackBrowserData.md)|hack-browser-data 是一个解密浏览器数据(密码/历史记录/Cookies/书签)的导出工具,支持全平台主流浏览器的数据导出窃取。|8662| -|2|[**fscan**](detail/fscan.md)|一款内网综合扫描工具,方便一键自动化、全方位漏扫扫描。支持主机存活探测、端口扫描、常见服务的爆破、ms17010、redis批量写公钥、计划任务反弹shell、读取win网卡信息、web指纹识别、web漏洞扫描、netbios探测、域控识别等功能。|6626| -|3|[**dperf**](detail/dperf.md)|dperf 是一个100Gbps的网络性能与压力测试软件。国内多个知名安全厂商用dperf测试其防火墙。知名开源四层负载均衡DPVS在用dperf做性能测试,发布性能测试报告。|3575| -|4|[**pocsuite3**](detail/pocsuite3.md)|pocsuite3是由Knownsec 404团队开发的开源远程漏洞测试和概念验证开发框架。它带有强大的概念验证引擎,以及针对最终渗透测试人员和安全研究人员的许多强大功能。|3288| +|1|[**HackBrowserData**](detail/HackBrowserData.md)|hack-browser-data 是一个解密浏览器数据(密码/历史记录/Cookies/书签)的导出工具,支持全平台主流浏览器的数据导出窃取。|8694| +|2|[**fscan**](detail/fscan.md)|一款内网综合扫描工具,方便一键自动化、全方位漏扫扫描。支持主机存活探测、端口扫描、常见服务的爆破、ms17010、redis批量写公钥、计划任务反弹shell、读取win网卡信息、web指纹识别、web漏洞扫描、netbios探测、域控识别等功能。|6648| +|3|[**dperf**](detail/dperf.md)|dperf 是一个100Gbps的网络性能与压力测试软件。国内多个知名安全厂商用dperf测试其防火墙。知名开源四层负载均衡DPVS在用dperf做性能测试,发布性能测试报告。|3599| +|4|[**pocsuite3**](detail/pocsuite3.md)|pocsuite3是由Knownsec 404团队开发的开源远程漏洞测试和概念验证开发框架。它带有强大的概念验证引擎,以及针对最终渗透测试人员和安全研究人员的许多强大功能。|3299| |5|[**Viper**](detail/Viper.md)|VIPER是一款图形化内网渗透工具,将内网渗透过程中常用的战术及技术进行模块化及武器化。|3272| -|6|[**CDK**](detail/CDK.md)|CDK是一款为容器环境定制的渗透测试工具,在已攻陷的容器内部提供零依赖的常用命令及PoC/EXP。集成Docker/K8s场景特有的逃逸、横向移动、持久化利用方式,插件化管理。|3224| -|7|[**antSword**](detail/antSword.md)|中国蚁剑是一款开源的跨平台网站管理工具。|2940| -|8|[**AppInfoScanner**](detail/AppInfoScanner.md)|一款适用于以HW行动/红队/渗透测试团队为场景的移动端(Android、iOS、WEB、H5、静态网站)信息收集扫描工具,可以帮助渗透测试工程师、攻击队成员、红队成员快速收集到移动端或者静态WEB站点中关键的资产信息并提供基本的信息输出,如:Title、Domain、CDN、指纹信息、状态信息等。|2567| +|6|[**CDK**](detail/CDK.md)|CDK是一款为容器环境定制的渗透测试工具,在已攻陷的容器内部提供零依赖的常用命令及PoC/EXP。集成Docker/K8s场景特有的逃逸、横向移动、持久化利用方式,插件化管理。|3240| +|7|[**antSword**](detail/antSword.md)|中国蚁剑是一款开源的跨平台网站管理工具。|2961| +|8|[**AppInfoScanner**](detail/AppInfoScanner.md)|一款适用于以HW行动/红队/渗透测试团队为场景的移动端(Android、iOS、WEB、H5、静态网站)信息收集扫描工具,可以帮助渗透测试工程师、攻击队成员、红队成员快速收集到移动端或者静态WEB站点中关键的资产信息并提供基本的信息输出,如:Title、Domain、CDN、指纹信息、状态信息等。|2581| |9|[**Stowaway**](detail/Stowaway.md)|Stowaway 是一款多级代理工具,可将外部流量通过多个节点代理至内网,突破内网访问限制。Stowaway 可以方便渗透测试人员通过多级跳跃,从外部dmz等一系列区域逐步深入核心网络;Stowaway 除了流量转发功能,还提供了端口复用、ssh隧道,流量伪装等专为渗透测试人员所用的功能。|2157| -|10|[**ENScanGo**](detail/ENScanGo.md)|一款基于各大企业信息API的工具,解决在遇到的各种针对国内企业信息收集难题。一键收集控股公司ICP备案、APP、小程序、微信公众号等信息聚合导出。|2093| +|10|[**afrog**](detail/afrog.md)|afrog 是一款性能卓越、快速稳定、PoC 可定制的漏洞扫描工具,PoC 包含 CVE、CNVD、默认口令、信息泄露、指纹识别、未授权访问、任意文件读取、命令执行等多种漏洞类型,帮助网络安全从业者快速验证并及时修复漏洞。|2121| **3.项目更新** | 时间 | 项目迭代版本 | |----|-----------| -|第38周|[**afrog**](detail/afrog.md) 更新 [v2.8.1](detail/afrog.md#最近更新)| +|第38周|[**Viper**](detail/Viper.md) 更新 [v20230924](detail/Viper.md#最近更新) / [**Tai-e**](detail/Tai-e.md) 更新 [v0.2.2](detail/Tai-e.md#最近更新) / [**afrog**](detail/afrog.md) 更新 [v2.8.1](detail/afrog.md#最近更新)| |第37周|[**Viper**](detail/Viper.md) 更新 [v20230914](detail/Viper.md#最近更新) / [**vArmor**](detail/vArmor.md) 更新 [v0.5.3](detail/vArmor.md#最近更新)| |第35周|[**afrog**](detail/afrog.md) 更新 [v2.8.0](detail/afrog.md#最近更新) / [**Viper**](detail/Viper.md) 更新 [v20230831](detail/Viper.md#最近更新) / [**Viper**](detail/Viper.md) 更新 [v20230827](detail/Viper.md#最近更新)| |第34周|[**GShark**](detail/gshark.md) 更新 [v1.2.1](detail/gshark.md#最近更新) / [**Viper**](detail/Viper.md) 更新 [v1.6.4](detail/Viper.md#最近更新)| @@ -62,7 +62,7 @@ | 时间 | 项目名称 | 项目简介 | |----|-----------|--------------------------| -|2023-09-13|[**Tai-e**](detail/Tai-e.md)|Tai-e (Chinese: 太阿; pronunciation: [ˈtaɪə:]) is a new static analysis framework for Java (please see our ISSTA 2023 paper for details), which features arguably the 'best' designs from both the novel ones we proposed and those of classic frameworks such as Soot, WALA, Doop, and SpotBugs. Tai-e is easy-to-learn, easy-to-use, efficient, and highly extensible, allowing you to easily develop new analyses on top of it.| +|2023-09-13|[**Tai-e**](detail/Tai-e.md)|Tai-e(太阿)是一个通用型Java程序分析框架,包含了开发程序分析技术所需的各类基础设施,并提供了可配置性高、功能强大的污点分析系统,用于检测各类隐私泄露、注入攻击等安全漏洞。| |2023-08-31|[**vArmor**](detail/vArmor.md)|vArmor 是一个云原生容器沙箱系统,它借助 Linux 的 LSM 技术(AppArmor & BPF)实现强制访问控制器(即 enforcer),从而对容器进行安全加固。它可以用于增强容器隔离性、减少内核攻击面、增加容器逃逸或横行移动攻击的难度与成本。vArmor 遵循 Kubernetes Operator 设计模式,用户可通过操作 CRD API 对特定的 Workload 进行加固。从而以更贴近业务的视角,实现对容器化微服务的沙箱加固。此外 vArmor 还包含多种内置加固策略,具备开箱即用的特性。| |2023-08-30|[**js-cookie-monitor-debugger-hook**](detail/js-cookie-monitor-debugger-hook.md)|js cookie逆向利器:js cookie变动监控可视化工具 & js cookie hook打条件断点| |2023-06-26|[**JYso**](detail/JYso.md)|JYso是一个可以用于 jndi 注入攻击和生成反序列化数据流的工具,既可以当 JNDIExploit 用也可以当作 ysoserial 使用。| @@ -79,27 +79,27 @@ |------|----------|------|----------|------| |1|[**Elkeid**](detail/Elkeid.md)|bytedance|Elkeid是一个云原生的基于主机的安全(入侵检测与风险识别)解决方案。Elkeid 包含两大部分:Elkeid Agent与Elkeid Driver作为数据采集层,它在Linux系统的内核和用户空间上均可使用,从而提供了具有更好性能的且更丰富的数据。 Elkeid Server可以提供百万级Agent的接入能力,采集Agent数据,支持控制与策略下发。包含实时、离线计算模块,对采集上来的数据进行分析和检测。又有自带的服务发现和管理系统,方便对整个后台管理和操作。|1892| |2|[**linglong**](detail/linglong.md)|awake1t|linglong是一款甲方资产巡航扫描系统。系统定位是发现资产,进行端口爆破。帮助企业更快发现弱口令问题。主要功能包括: 资产探测、端口爆破、定时任务、管理后台识别、报表展示。|1517| -|3|[**veinmind-tools**](detail/veinmind-tools.md)|长亭科技|veinmind-tools 是基于 veinmind-sdk 打造的一个容器安全工具集,目前已支持镜像 恶意文件/后门/敏感信息/弱口令 的扫描,更多功能正在逐步开发中。|1354| -|4|[**murphysec**](detail/murphysec.md)|murphysecurity|墨菲安全专注于软件供应链安全,murphysec 是墨菲安全的 CLI 工具,用于在命令行检测指定目录代码的依赖安全问题,也可以基于 CLI 工具实现在 CI 流程的检测。|1283| +|3|[**veinmind-tools**](detail/veinmind-tools.md)|长亭科技|veinmind-tools 是基于 veinmind-sdk 打造的一个容器安全工具集,目前已支持镜像 恶意文件/后门/敏感信息/弱口令 的扫描,更多功能正在逐步开发中。|1367| +|4|[**murphysec**](detail/murphysec.md)|murphysecurity|墨菲安全专注于软件供应链安全,murphysec 是墨菲安全的 CLI 工具,用于在命令行检测指定目录代码的依赖安全问题,也可以基于 CLI 工具实现在 CI 流程的检测。|1315| |5|[**appshark**](detail/appshark.md)|bytedance|Appshark 是一个针对安卓的静态分析工具,它的设计目标是针对超大型App的分析,Appshark支持基于json的自定义扫描规则,发现自己关心的安全漏洞以及隐私合规问题,支持灵活配置,可以在准确率以及扫描时间空间之间寻求平衡,支持自定义扩展规则,根据自己的业务需要,进行定制分析|1274| -|6|[**OpenStar**](detail/OpenStar.md)|starjun|OpenStar 是一个基于 OpenResty 的高性能 Web 应用防火墙,支持复杂规则编写。提供了常规的 HTTP 字段规则配置,还提供了 IP 黑白名单、访问频次等配置,对于 CC 防护更提供的特定的规则算法,并且支持搭建集群进行防护。|1206| -|7|[**camille**](detail/camille.md)|zhengjim|现如今APP隐私合规十分重要,各监管部门不断开展APP专项治理工作及核查通报,不合规的APP通知整改或直接下架。camille可以hook住Android敏感接口,并识别是否为第三方SDK调用。根据隐私合规的场景,辅助检查是否符合隐私合规标准。|1192| -|8|[**GShark**](detail/gshark.md)|madneal|一款开源敏感信息检测系统,可以监测包括 GitHub, GitLab(支持私有部署版本), Postman, searchcode 多个平台的敏感信息监测。|723| -|9|[**Juggler**](detail/Juggler.md)|C4o|一个也许能骗到黑客的系统,可以作为WAF等防护体系的一环。|432| -|10|[**vArmor**](detail/vArmor.md)|bytedance|vArmor 是一个云原生容器沙箱系统,它借助 Linux 的 LSM 技术(AppArmor & BPF)实现强制访问控制器(即 enforcer),从而对容器进行安全加固。它可以用于增强容器隔离性、减少内核攻击面、增加容器逃逸或横行移动攻击的难度与成本。vArmor 遵循 Kubernetes Operator 设计模式,用户可通过操作 CRD API 对特定的 Workload 进行加固。从而以更贴近业务的视角,实现对容器化微服务的沙箱加固。此外 vArmor 还包含多种内置加固策略,具备开箱即用的特性。|120| +|6|[**OpenStar**](detail/OpenStar.md)|starjun|OpenStar 是一个基于 OpenResty 的高性能 Web 应用防火墙,支持复杂规则编写。提供了常规的 HTTP 字段规则配置,还提供了 IP 黑白名单、访问频次等配置,对于 CC 防护更提供的特定的规则算法,并且支持搭建集群进行防护。|1216| +|7|[**camille**](detail/camille.md)|zhengjim|现如今APP隐私合规十分重要,各监管部门不断开展APP专项治理工作及核查通报,不合规的APP通知整改或直接下架。camille可以hook住Android敏感接口,并识别是否为第三方SDK调用。根据隐私合规的场景,辅助检查是否符合隐私合规标准。|1208| +|8|[**Tai-e**](detail/Tai-e.md)|pascal-lab|Tai-e(太阿)是一个通用型Java程序分析框架,包含了开发程序分析技术所需的各类基础设施,并提供了可配置性高、功能强大的污点分析系统,用于检测各类隐私泄露、注入攻击等安全漏洞。|812| +|9|[**GShark**](detail/gshark.md)|madneal|一款开源敏感信息检测系统,可以监测包括 GitHub, GitLab(支持私有部署版本), Postman, searchcode 多个平台的敏感信息监测。|723| +|10|[**Juggler**](detail/Juggler.md)|C4o|一个也许能骗到黑客的系统,可以作为WAF等防护体系的一环。|432| **6.[分类:信息收集](reconnaissance.md)** | 序号 | 项目名称 | 作者 | 项目简介 | Star | |------|----------|------|----------|------| -|1|[**ENScanGo**](detail/ENScanGo.md)|wgpsec|一款基于各大企业信息API的工具,解决在遇到的各种针对国内企业信息收集难题。一键收集控股公司ICP备案、APP、小程序、微信公众号等信息聚合导出。|2093| -|2|[**HaE**](detail/HaE.md)|gh0stkey|HaE是一款可以快速挖掘目标指纹和关键信息的Burp插件。|1923| -|3|[**Kunyu**](detail/Kunyu.md)|风起|Kunyu(坤舆),是一款基于ZoomEye API开发的信息收集工具,旨在让企业资产收集更高效,使更多安全相关从业者了解、使用网络空间测绘技术。|866| +|1|[**ENScanGo**](detail/ENScanGo.md)|wgpsec|一款基于各大企业信息API的工具,解决在遇到的各种针对国内企业信息收集难题。一键收集控股公司ICP备案、APP、小程序、微信公众号等信息聚合导出。|2117| +|2|[**HaE**](detail/HaE.md)|gh0stkey|HaE是一款可以快速挖掘目标指纹和关键信息的Burp插件。|1937| +|3|[**Kunyu**](detail/Kunyu.md)|风起|Kunyu(坤舆),是一款基于ZoomEye API开发的信息收集工具,旨在让企业资产收集更高效,使更多安全相关从业者了解、使用网络空间测绘技术。|877| |4|[**Glass**](detail/Glass.md)|s7ckTeam|Glass是一款针对资产列表的快速指纹识别工具,通过调用Fofa/ZoomEye/Shodan/360等api接口快速查询资产信息并识别重点资产的指纹,也可针对IP/IP段或资产列表进行快速的指纹识别。|864| -|5|[**ksubdomain**](detail/ksubdomain.md)|w8ay|ksubdomain是一款基于无状态子域名爆破工具,支持在Windows/Linux/Mac上使用,它会很快的进行DNS爆破,在Mac和Windows上理论最大发包速度在30w/s,linux上为160w/s的速度。|707| +|5|[**ksubdomain**](detail/ksubdomain.md)|w8ay|ksubdomain是一款基于无状态子域名爆破工具,支持在Windows/Linux/Mac上使用,它会很快的进行DNS爆破,在Mac和Windows上理论最大发包速度在30w/s,linux上为160w/s的速度。|717| |6|[**scaninfo**](detail/scaninfo.md)|华东360安服团队|scaninfo 是一款开源、轻量、快速、跨平台的红队内外网打点扫描器。比较同类工具,其能够在 nmap 的扫描速度和 masscan 的准确度之间寻找一个较好的平衡点,能够快速进行端口扫描和服务识别,内置指纹识别用于 web 探测,可以用报告的方式整理扫描结果。|705| |7|[**ZoomEye-Python**](detail/ZoomEye-Python.md)|Knownsec404|ZoomEye-python 是一款基于 ZoomEye API 开发的 Python 库,提供了 ZoomEye 命令行模式,同时也可以作为 SDK 集成到其他工具中。该库可以让技术人员更便捷地搜索、筛选、导出 ZoomEye 的数据|467| -|8|[**ct**](detail/ct.md)|rungobier@Knownsec404|ct 是一款使用 rust 语言进行开发,并且基于ZoomEye域名查询以及利用域名字典进行子域名爆破的工具,同时在最终爆破完成后可使用脚本,将相应的的.gv 文件转化成为相应的 .png 文件进行可视化展示|81| +|8|[**ct**](detail/ct.md)|rungobier@Knownsec404|ct 是一款使用 rust 语言进行开发,并且基于ZoomEye域名查询以及利用域名字典进行子域名爆破的工具,同时在最终爆破完成后可使用脚本,将相应的的.gv 文件转化成为相应的 .png 文件进行可视化展示|91| |9|[**Zoomeye-Tools**](detail/ZoomEye-Tools.md)|Knownsec404|一个配合ZoomEye使用的Chrome插件,可以查看当前网页所在ip信息或跳转查看详细信息,还可以根据关键词一键跳转至ZoomEye进行搜索|41| |10|[**ZoomEye-go**](detail/ZoomEye-go.md)|gyyyy|ZoomEye-go 是一款基于 ZoomEye API 开发的 Golang 库,提供了 ZoomEye 命令行模式,同时也可以作为SDK集成到其他工具中。该库可以让技术人员更便捷地搜索、筛选、导出 ZoomEye 的数据。|27| diff --git a/allprojects.md b/allprojects.md index 08cbdeb..440f1c5 100644 --- a/allprojects.md +++ b/allprojects.md @@ -9,6 +9,7 @@ * [appshark](#appshark) * [OpenStar](#openstar) * [camille](#camille) + * [Tai-e](#tai-e) * [gshark](#gshark) * [Juggler](#juggler) * [vArmor](#varmor) @@ -56,7 +57,6 @@ * [HackBrowserData](#hackbrowserdata) * [KunLun-M](#kunlun-m) * [frida-skeleton](#frida-skeleton) - * [Tai-e](#tai-e) * [java-object-searcher](#java-object-searcher) * [MySQLMonitor](#mysqlmonitor) * [js-cookie-monitor-debugger-hook](#js-cookie-monitor-debugger-hook) @@ -165,6 +165,16 @@ OpenStar 是一个基于 OpenResty 的高性能 Web 应用防火墙,支持复 现如今APP隐私合规十分重要,各监管部门不断开展APP专项治理工作及核查通报,不合规的APP通知整改或直接下架。camille可以hook住Android敏感接口,并识别是否为第三方SDK调用。根据隐私合规的场景,辅助检查是否符合隐私合规标准。 +### [Tai-e](detail/Tai-e.md) +![Author](https://img.shields.io/badge/Author-pascal-lab-orange) +![Language](https://img.shields.io/badge/Language-Java-blue) +![GitHub stars](https://img.shields.io/github/stars/pascal-lab/Tai-e.svg?style=flat&logo=github) +![Version](https://img.shields.io/badge/Version-V0.2.2-red) + + + +Tai-e(太阿)是一个通用型Java程序分析框架,包含了开发程序分析技术所需的各类基础设施,并提供了可配置性高、功能强大的污点分析系统,用于检测各类隐私泄露、注入攻击等安全漏洞。 + ### [GShark](detail/gshark.md) ![Author](https://img.shields.io/badge/Author-madneal-orange) ![Language](https://img.shields.io/badge/Language-Golang-blue) @@ -398,7 +408,7 @@ pocsuite3是由Knownsec 404团队开发的开源远程漏洞测试和概念验 ![Author](https://img.shields.io/badge/Author-FunnyWolf-orange) ![Language](https://img.shields.io/badge/Language-JS/Python-blue) ![GitHub stars](https://img.shields.io/github/stars/FunnyWolf/Viper.svg?style=flat&logo=github) -![Version](https://img.shields.io/badge/Version-V20230914-red) +![Version](https://img.shields.io/badge/Version-V20230924-red) @@ -567,16 +577,6 @@ KunLun-M是一个完全开源的静态白盒扫描工具,支持PHP、JavaScrip frida-skeleton是基于frida的安卓hook框架,提供了很多frida自身不支持的功能,将hook安卓变成简单便捷,人人都会的事情。 -### [Tai-e](detail/Tai-e.md) -![Author](https://img.shields.io/badge/Author-pascal-lab-orange) -![Language](https://img.shields.io/badge/Language-Java-blue) -![GitHub stars](https://img.shields.io/github/stars/pascal-lab/Tai-e.svg?style=flat&logo=github) -![Version](https://img.shields.io/badge/Version-V0.0.3-red) - - - -Tai-e (Chinese: 太阿; pronunciation: [ˈtaɪə:]) is a new static analysis framework for Java (please see our ISSTA 2023 paper for details), which features arguably the 'best' designs from both the novel ones we proposed and those of classic frameworks such as Soot, WALA, Doop, and SpotBugs. Tai-e is easy-to-learn, easy-to-use, efficient, and highly extensible, allowing you to easily develop new analyses on top of it. - ### [java-object-searcher](detail/java-object-searcher.md) ![Author](https://img.shields.io/badge/Author-c0ny1-orange) ![Language](https://img.shields.io/badge/Language-Java-blue) diff --git a/detail/Tai-e.md b/detail/Tai-e.md index be64932..dbd76fc 100644 --- a/detail/Tai-e.md +++ b/detail/Tai-e.md @@ -3,17 +3,14 @@ ![Language](https://img.shields.io/badge/Language-Java-blue) ![Author](https://img.shields.io/badge/Author-pascal-lab-orange) ![GitHub stars](https://img.shields.io/github/stars/pascal-lab/Tai-e.svg?style=flat&logo=github) -![Version](https://img.shields.io/badge/Version-V0.0.3-red) +![Version](https://img.shields.io/badge/Version-V0.2.2-red) ![Time](https://img.shields.io/badge/Join-20230913-green) ## What is Tai-e? -Tai-e (Chinese: 太阿; pronunciation: [ˈtaɪə:]) is a new static analysis framework for Java (please -see our [ISSTA 2023 paper](https://cs.nju.edu.cn/tiantan/papers/issta2023.pdf) for details), which features arguably -the "best" designs from both the novel ones we proposed and those of classic frameworks such as -Soot, WALA, Doop, and SpotBugs. Tai-e is easy-to-learn, easy-to-use, efficient, and highly -extensible, allowing you to easily develop new analyses on top of it. +Tai-e (Chinese: 太阿; pronunciation: [ˈtaɪə:]) is a new static analysis framework for Java (please see our [ISSTA 2023 paper](https://cs.nju.edu.cn/tiantan/papers/issta2023.pdf) for details), which features arguably the "best" designs from both the novel ones we proposed and those of classic frameworks such as Soot, WALA, Doop, and SpotBugs. +Tai-e is easy-to-learn, easy-to-use, efficient, and highly extensible, allowing you to easily develop new analyses on top of it. Currently, Tai-e provides the following major analysis components (and more analyses are on the way): @@ -38,48 +35,107 @@ way): - Bug detectors, e.g., null pointer detector, incorrect `clone()` detector - Your bug detectors -Tai-e is developed in Java, and it can run on major operating systems including Windows, Linux, and -macOS. +Tai-e is developed in Java, and it can run on major operating systems including Windows, Linux, and macOS. -As a courtesy to the developers, we expect that you **please [cite](https://github.com/pascal-lab/Tai-e/blob/master/docs/bibtex.txt) the paper** from ISSTA 2023 describing the Tai-e framework in your research work: +As a courtesy to the developers, we expect that you **please [cite](https://github.com/pascal-lab/Tai-e/blob/master/CITATION.bib) the paper** from ISSTA 2023 describing the Tai-e framework in your research work: Tian Tan and Yue Li. 2023. **Tai-e: A Developer-Friendly Static Analysis Framework for Java by Harnessing the Good Designs of Classics.** -In Proceedings of the 32nd ACM SIGSOFT International Symposium on Software Testing and Analysis (ISSTA '23), July 17–21, 2023, Seattle, WA, USA ([pdf](https://cs.nju.edu.cn/tiantan/papers/issta2023.pdf), [bibtex](https://github.com/pascal-lab/Tai-e/blob/master/docs/bibtex.txt)). +In Proceedings of the 32nd ACM SIGSOFT International Symposium on Software Testing and Analysis (ISSTA '23), July 17–21, 2023, Seattle, WA, USA ([pdf](https://cs.nju.edu.cn/tiantan/papers/issta2023.pdf), [bibtex](https://github.com/pascal-lab/Tai-e/blob/master/CITATION.bib)). ## How to Obtain Runnable Jar of Tai-e? +The simplest way is to download it from [GitHub Releases](https://github.com/pascal-lab/Tai-e/releases). -The simplest way is to download it -from [GitHub Releases](https://github.com/pascal-lab/Tai-e/releases). +Alternatively, you might build the latest Tai-e yourself from the source code. This can be simply accomplished via Gradle (be sure that Java 17 (or higher version) is available on your system). +You just need to run command `gradlew fatJar`, and then the runnable jar will be generated in `tai-e/build/`, which includes Tai-e and all its dependencies. -Alternatively, you might build the latest Tai-e yourself from the source code. This can be simply -done via Gradle (be sure that Java 17 (or higher version) is available on your system). You just -need to run command `gradlew fatJar`, and then the runnable jar will be generated in `tai-e/build/`, -which includes Tai-e and all its dependencies. +## How to Include Tai-e in Your Project? +Tai-e is designed as a standalone tool, but you also have the option to include it in your project as a dependency. +It is available on Maven repositories, allowing you to easily integrate it into your Java projects using build tools such as Gradle and Maven. +We maintain both stable and latest versions of Tai-e, and here are the corresponding coordinates in Gradle and Maven script formats: + +### Stable Version +For Gradle: + +```kotlin +dependencies { + implementation("net.pascal-lab:tai-e:0.2.2") +} +``` + +For Maven: + +```xml + + + + net.pascal-lab + tai-e + 0.2.2 + + +``` + +### Latest Version + +For Gradle: + +```kotlin +repositories { + mavenCentral() + maven { url = uri("https://s01.oss.sonatype.org/content/repositories/snapshots/") } +} + +dependencies { + implementation("net.pascal-lab:tai-e:0.5.1-SNAPSHOT") +} +``` + +For Maven: + +```xml + + + snapshots + Sonatype snapshot server + https://s01.oss.sonatype.org/content/repositories/snapshots/ + + + + + + net.pascal-lab + tai-e + 0.5.1-SNAPSHOT + + +``` + +You can use these coordinates in your Gradle or Maven scripts to include the desired version of Tai-e in your project. ## Documentation -### Wiki -We are hosting the documentation of Tai-e -on [the GitHub wiki](https://github.com/pascal-lab/Tai-e/wiki), where you could find more -information about Tai-e such -as [Setup in IntelliJ IDEA](https://github.com/pascal-lab/Tai-e/wiki/Setup-Tai%E2%80%90e-in-IntelliJ-IDEA) -, [Command-Line Options](https://github.com/pascal-lab/Tai-e/wiki/How-to-Run-Tai%E2%80%90e%3F-(command%E2%80%90line-options)) -, -and [Development of New Analysis](https://github.com/pascal-lab/Tai-e/wiki/How-to-Develop-A-New-Analysis-on-Tai%E2%80%90e%3F) -. +### Reference Documentation + +We have provided detailed information of Tai-e in the [Reference Documentation](http://tai-e.pascal-lab.net/docs/current/reference/en/index.html), which covers various aspects such as [Setup in IntelliJ IDEA](http://tai-e.pascal-lab.net/docs/current/reference/en/setup-in-intellij-idea.html), [Command-Line Options](http://tai-e.pascal-lab.net/docs/current/reference/en/command-line-options.html), and [Development of New Analysis](http://tai-e.pascal-lab.net/docs/current/reference/en/develop-new-analysis.html). + +Please note that the reference documentation mentioned above pertains to *the latest version* of Tai-e. +If you need documentation for a specific stable version, please refer to the [Documentation Index](https://tai-e.pascal-lab.net/docs). +Additionally, the documentation is included within the repository and maintained alongside the source code. +You can access the reference documentation for a particular version of Tai-e (in AsciiDoc format) by exploring the [docs/en](https://github.com/pascal-lab/Tai-e/blob/master/docs/en) directory, starting from [index.adoc](https://github.com/pascal-lab/Tai-e/blob/master/docs/en/index.adoc). +This allows you to access version-specific documentation for Tai-e. + +In addition to the reference +documentation, [Javadocs](https://tai-e.pascal-lab.net/docs/current/api/index.html) for Tai-e are +also available as a useful reference resource. ### Changelog -Since we are actively developing and updating Tai-e, we record the notable changes we made, especially the new features and breaking changes, in [CHANGELOG](https://github.com/pascal-lab/Tai-e/blob/master/CHANGELOG.md). If you find something wrong after updating Tai-e, maybe you could check [CHANGELOG](https://github.com/pascal-lab/Tai-e/blob/master/CHANGELOG.md) for useful information. +Since we are actively developing and updating Tai-e, we record the notable changes we made, especially the new features and breaking changes, in [CHANGELOG](https://github.com/pascal-lab/Tai-e/blob/master/CHANGELOG.md). +If you find something wrong after updating Tai-e, maybe you could check [CHANGELOG](https://github.com/pascal-lab/Tai-e/blob/master/CHANGELOG.md) for useful information. ## Tai-e Assignments - -In addition, we have developed -an [educational version of Tai-e](http://tai-e.pascal-lab.net/en/intro/overview.html) where eight -programming assignments are carefully designed for systematically training learners to implement -various static analysis techniques to analyze real Java programs. The educational version shares a -large amount of code with Tai-e, thus doing the assignments would be a good way to get familiar with -Tai-e. +In addition, we have developed an [educational version of Tai-e](http://tai-e.pascal-lab.net/en/intro/overview.html) where eight programming assignments are carefully designed for systematically training learners to implement various static analysis techniques to analyze real Java programs. +The educational version shares a large amount of code with Tai-e, thus doing the assignments would be a good way to get familiar with Tai-e. ## 项目相关 @@ -87,4 +143,34 @@ Tai-e. ## 最近更新 +#### [v0.2.2] - 2023-09-23 + +**新功能** + +* 添加选项--app-class-path +* 添加选项--keep-results +* 添加选项--output-dir +* 添加选项-wc, --world-cache-mode +* 添加 def-use 分析 +* 添加 dominator-finding 算法 +* 添加类、函数和字段的通用签名信息 +* 添加文档源文件 +* 污点分析 + * 支持函数形参和实参的污点源 + * 支持字段加载的污点源 + * 支持函数参数的污点清理 + * 转储污点流程图 + * 支持加载多个污点配置文件 + * 支持变量和实例字段/数组元素之间的污点传输 + * 支持 call-site 模式 +* 指针分析 + * 支持添加程序的入口点进行分析 + * 支持设置分析时间限制 + * 支持原始类型值的传播 + * 支持基于推理和基于日志的混合反射分析 + * 添加 Solar 反射分析 (TOSEM'19) + * 支持基于注释的调用处理程序注册 + * 支持转储 YAML 格式的指针分析集合。 +* 更多详细更新内容:https://github.com/pascal-lab/Tai-e/releases + diff --git a/detail/Viper.md b/detail/Viper.md index 8acec58..5f3ecac 100644 --- a/detail/Viper.md +++ b/detail/Viper.md @@ -3,7 +3,7 @@ ![Language](https://img.shields.io/badge/Language-JS/Python-blue) ![Author](https://img.shields.io/badge/Author-FunnyWolf-orange) ![GitHub stars](https://img.shields.io/github/stars/FunnyWolf/Viper.svg?style=flat&logo=github) -![Version](https://img.shields.io/badge/Version-V20230914-red) +![Version](https://img.shields.io/badge/Version-V20230924-red) ![Time](https://img.shields.io/badge/Join-20210323-green) @@ -79,6 +79,22 @@ ## 最近更新 +#### [v20230924] - 2023-09-24 + +**新功能** +- 自动编排新增Session定时任务功能 +- 新增TCPLOG服务器模块 +- 新增Last日志删除模块 + +**优化** +- 前端界面支持OSX的Payload和Handler生成 +- Session展示区域支持伸缩(点击右侧按钮扩大缩小) +- 合并metasploit-framework 6.3.35版本 + +**Bugfix** +- fix 监听通信通道选择Session后不显示问题 +- fix 内存执行C#可执行文件模块报错问题 + #### [v20230914] - 2023-09-14 **优化** @@ -135,18 +151,4 @@ - 修复已经上线的session界面未显示 - 修复日志逻辑问题 -#### [v1.6.3] - 2023-08-12 - -**优化** -- 调整vipermsf及viperpython日志级别及格式,便于定位问题 -- 关闭vipermsf的cpulimit -- 新增vipermsf心跳异常提示 -- 更新沙箱IP列表 -- 优化网络拓扑动态效果 -- 合并metasploit-framework 6.3.30版本 - -**Bugfix** -- 修复session下载文件时会偶发性的下载了1m中断 -- 修复thin的pid文件未清除导致重启msf后台服务无法启动 - diff --git a/information_analysis.md b/information_analysis.md index 9f04c4d..8b2dd4e 100644 --- a/information_analysis.md +++ b/information_analysis.md @@ -3,11 +3,10 @@ 1. [HackBrowserData](#hackbrowserdata) 2. [KunLun-M](#kunlun-m) 3. [frida-skeleton](#frida-skeleton) -4. [Tai-e](#tai-e) -5. [java-object-searcher](#java-object-searcher) -6. [MySQLMonitor](#mysqlmonitor) -7. [js-cookie-monitor-debugger-hook](#js-cookie-monitor-debugger-hook) -8. [CodeReviewTools](#codereviewtools) +4. [java-object-searcher](#java-object-searcher) +5. [MySQLMonitor](#mysqlmonitor) +6. [js-cookie-monitor-debugger-hook](#js-cookie-monitor-debugger-hook) +7. [CodeReviewTools](#codereviewtools) ---------------------------------------- @@ -41,16 +40,6 @@ KunLun-M是一个完全开源的静态白盒扫描工具,支持PHP、JavaScrip frida-skeleton是基于frida的安卓hook框架,提供了很多frida自身不支持的功能,将hook安卓变成简单便捷,人人都会的事情。 -### [Tai-e](detail/Tai-e.md) -![Author](https://img.shields.io/badge/Author-pascal-lab-orange) -![Language](https://img.shields.io/badge/Language-Java-blue) -![GitHub stars](https://img.shields.io/github/stars/pascal-lab/Tai-e.svg?style=flat&logo=github) -![Version](https://img.shields.io/badge/Version-V0.0.3-red) - - - -Tai-e (Chinese: 太阿; pronunciation: [ˈtaɪə:]) is a new static analysis framework for Java (please see our ISSTA 2023 paper for details), which features arguably the 'best' designs from both the novel ones we proposed and those of classic frameworks such as Soot, WALA, Doop, and SpotBugs. Tai-e is easy-to-learn, easy-to-use, efficient, and highly extensible, allowing you to easily develop new analyses on top of it. - ### [java-object-searcher](detail/java-object-searcher.md) ![Author](https://img.shields.io/badge/Author-c0ny1-orange) ![Language](https://img.shields.io/badge/Language-Java-blue) diff --git a/party_a.md b/party_a.md index eb961c9..6cede15 100644 --- a/party_a.md +++ b/party_a.md @@ -8,10 +8,11 @@ 6. [appshark](#appshark) 7. [OpenStar](#openstar) 8. [camille](#camille) -9. [GShark](#gshark) -10. [Juggler](#juggler) -11. [vArmor](#varmor) -12. [Hades](#hades) +9. [Tai-e](#tai-e) +10. [GShark](#gshark) +11. [Juggler](#juggler) +12. [vArmor](#varmor) +13. [Hades](#hades) ---------------------------------------- @@ -95,6 +96,16 @@ OpenStar 是一个基于 OpenResty 的高性能 Web 应用防火墙,支持复 现如今APP隐私合规十分重要,各监管部门不断开展APP专项治理工作及核查通报,不合规的APP通知整改或直接下架。camille可以hook住Android敏感接口,并识别是否为第三方SDK调用。根据隐私合规的场景,辅助检查是否符合隐私合规标准。 +### [Tai-e](detail/Tai-e.md) +![Author](https://img.shields.io/badge/Author-pascal-lab-orange) +![Language](https://img.shields.io/badge/Language-Java-blue) +![GitHub stars](https://img.shields.io/github/stars/pascal-lab/Tai-e.svg?style=flat&logo=github) +![Version](https://img.shields.io/badge/Version-V0.2.2-red) + + + +Tai-e(太阿)是一个通用型Java程序分析框架,包含了开发程序分析技术所需的各类基础设施,并提供了可配置性高、功能强大的污点分析系统,用于检测各类隐私泄露、注入攻击等安全漏洞。 + ### [GShark](detail/gshark.md) ![Author](https://img.shields.io/badge/Author-madneal-orange) ![Language](https://img.shields.io/badge/Language-Golang-blue) diff --git a/penetration_test.md b/penetration_test.md index fb3fe42..10a4a5a 100644 --- a/penetration_test.md +++ b/penetration_test.md @@ -43,7 +43,7 @@ pocsuite3是由Knownsec 404团队开发的开源远程漏洞测试和概念验 ![Author](https://img.shields.io/badge/Author-FunnyWolf-orange) ![Language](https://img.shields.io/badge/Language-JS/Python-blue) ![GitHub stars](https://img.shields.io/github/stars/FunnyWolf/Viper.svg?style=flat&logo=github) -![Version](https://img.shields.io/badge/Version-V20230914-red) +![Version](https://img.shields.io/badge/Version-V20230924-red)