Papers developed within CSecGroup, listed in reverse chronological order.
- GitLab web hooks SSRF(CVE-2018-8801) Patch analysis and How to safely fix SSRF
- Fix xstream object deserialization via White Listing.2018
- 应用安全:JAVA反序列化漏洞之殇.2017
- Struts2漏洞利用原理及OGNL机制研究.2017
- SDL-软件安全设计初窥.2016
- Talking About Exploit Writing.2011