# Drun1baby/JavaSecurityLearning

记录一下 Java 安全学习历程，也算是半条学习路线了

Repository: https://github.com/Drun1baby/JavaSecurityLearning
Canonical: https://ross.abutalabs.com/products/javasecuritylearning
Language: Java
License Family: other
Topics: java
Last push: 2025-06-26T02:47:43+00:00

## Health v2 (maintenance only)
Score: 45/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 28, release rhythm 35, longevity 100
- inputs: {"age_days": 1514, "days_push": 433, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1388, forks 125 (observed 2026-08-28T04:04:35.294708+00:00)

## What it is
A curated learning roadmap and notes repository for Java security, covering Java deserialization vulnerabilities, Commons Collections gadget chains, Shiro exploits, RMI, and related topics. It includes blog articles and sample code for reproducing and debugging vulnerabilities.

## Use cases
- learn java security from scratch
- understand java deserialization vulnerabilities
- study commons collections gadget chains
- learn shiro 550 and 721 exploitation
- find a structured java security learning path
- get sample code for vulnerability debugging

## When to choose
- you want a structured, step-by-step path into Java security
- you need detailed writeups on CC chains and Shiro vulnerabilities
- you prefer learning with accompanying blog posts and runnable code

## When to avoid
- you need production security tooling rather than educational material
- you want content in English (the material is primarily in Chinese)
- you are looking for a general Java programming tutorial unrelated to security

## Facets
- artifact type: learning-resource
- maturity: active
- function: security, developer-tools
- domain: security, tutorials, education, developer-tools
- platform: jvm, cross-platform
- tags: java-security, deserialization, vulnerability-research, learning-path, penetration-testing, chinese-language

## Member repositories
- Drun1baby/JavaSecurityLearning (main) score 45

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:35.294708+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:39:45.155107+00:00, confidence not recorded.
  - readme: https://github.com/Drun1baby/JavaSecurityLearning (fetched 2026-08-28T04:04:35.294708+00:00, sha 57ebdd28ceab)
- Data as of 2026-08-30T08:39:29.467469+00:00.
