Giter Site home page Giter Site logo

jdumpspider's Introduction

JDumpSpider

HeapDump敏感信息提取工具

下载

预编译包:Releases

编译

需要Maven、JDK 1.8。

首先需要将netbeans-lib-profiler导入本地maven仓库

$ cd lib/
$ mvn install:install-file -Dfile=netbeans-lib-profiler.jar -DgroupId=netbeans -DartifactId=netbeans-lib-profiler -Dversion=1.0 -Dpackaging=jar

导入完成后切换至项目根目录,运行编译打包命令

$ mvn package

支持范围

暂支持提取以下类型的敏感信息

  • 数据源
    • SpringDataSourceProperties
    • WeblogicDataSourceConnectionPoolConfig
    • MongoClient
    • AliDruidDataSourceWrapper
    • HikariDataSource
  • 配置文件信息
    • MapPropertySource
    • OriginTrackedMapPropertySource
    • MutablePropertySource
    • ConsulPropertySource
    • OSS(模糊搜索)
  • Redis配置
    • RedisStandaloneConfiguration
    • JedisClient
  • ShiroKey
    • CookieRememberMeManager
  • 模糊搜索用户信息
    • UserPassSearcher01

更多类型支持尽请期待。

使用

本工具需要使用Java 1.6或更高版本。

$ java -jar .\target\JDumpSpider-1.0-SNAPSHOT-full.jar                  
Missing required parameter: '<heapfile>'
Usage: JDumpSpider [-hV] <heapfile>                   
Extract sensitive information from heapdump file.     
      <heapfile>   Heap file path.                    
  -h, --help       Show this help message and exit.   
  -V, --version    Print version information and exit.

jdumpspider's People

Contributors

whwlsfb avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

jdumpspider's Issues

OSS报错

oss运行报错,应该是首行多了一个括号
image
然后把括号去了后,报错类型转换问题
org.graalvm.visualvm.lib.profiler.oql.engine.api.OQLException: java.lang.ClassCastException: jdk.nashorn.internal.runtime.Undefined cannot be cast to java.lang.String

上次那个话题关闭了吗

还是希望作者增加导出所有内容的功能,因为有时候不知道想搜索的内容,所需要导出来看,感谢

ShiroKey获取失败

ShiroKey
CookieRememberMeManager

获取失败

不仅仅失败,甚至命令行都没有弹出提示获取shirokey

执行时出现了问题

java8 -jar JDumpSpider-1.1-SNAPSHOT-full.jar ./heapdump
Exception in thread "main" java.lang.RuntimeException: java.lang.NumberFormatException: For input string: "d"
at cn.wanghw.Main.getFileVersion(Main.java:111)
at cn.wanghw.Main.call(Main.java:58)
at cn.wanghw.Main.main(Main.java:29)
Caused by: java.lang.NumberFormatException: For input string: "d"
at java.lang.NumberFormatException.forInputString(Unknown Source)
at java.lang.Integer.parseInt(Unknown Source)
at java.lang.Integer.parseInt(Unknown Source)
at cn.wanghw.Main.getFileVersion(Main.java:109)
... 2 more

D:\工具\mat>java -jar JDumpSpider-1.1-SNAPSHOT-full.jar ./heapdump
Exception in thread "main" java.lang.RuntimeException: java.lang.NumberFormatException: For input string: "d"
at cn.wanghw.Main.getFileVersion(Main.java:111)
at cn.wanghw.Main.call(Main.java:58)
at cn.wanghw.Main.main(Main.java:29)
Caused by: java.lang.NumberFormatException: For input string: "d"
at java.base/java.lang.NumberFormatException.forInputString(NumberFormatException.java:67)
at java.base/java.lang.Integer.parseInt(Integer.java:668)
at java.base/java.lang.Integer.parseInt(Integer.java:786)
at cn.wanghw.Main.getFileVersion(Main.java:109)
... 2 more

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.