Repository navigation

#

deserialization-vulnerability

Dockerfile
1448
15 天前

Fastjson扫描器,可识别版本、依赖库、autoType状态等。A tool to distinguish fastjson ,version and dependency

Go
1017
3 年前

Peas create serialized payload for deserialization RCE attack on python driven applications where pickle ,pyYAML, ruamel.yaml or jsonpickle module is used for deserialization of serialized data. I will update it with more attack vectors to targets other modules.

Python
112
1 年前

Everything I needed to understand what was going on with "Spring4Shell" - translated source materials, exploit, links to demo apps, and more.

Python
107
3 年前

Java反序列化/JNDI注入/恶意类生成工具,支持多种高版本bypass,支持回显/内存马等多种扩展利用。

Java
98
2 个月前

GPT AiCSA(Code security audit),SAST(Static Application Security Testing,静态应用程序安全测试),JAR security analysis, static vulnerability and vulnerability analysis of various programming language codes

JavaScript
60
1 年前

Vulnerable webapp testbed

Java
21
9 年前

AiCSA,Move to https://github.com/hktalent/AiCSA

Shell
10
2 年前

A JBoss Byteman rule to debug the trace the JDK deserialization filtering

5
12 天前

Python Deserialization Payload Generator

Python
4
5 年前

PoC for CVE-2020-28032 (It's just a POP chain in WordPress < 5.5.2 for exploiting PHP Object Injection)

PHP
4
3 年前

maptool unauthenticated rce exploit <1.8.0 beta2b

Python
1
4 年前

This project contains a Java deserialization vulnerability that is exploitable with some ysoserial payloads, but also contains a custom class that can be leveraged to get command execution upon deserialization.

Java
1
3 年前

Fake MySQL Server for Exploit Vulnerability of MySQL JDBC Driver

Java
0
2 年前

This tool is responsible to perform java deserialization attacks on server end points

Python
0
2 年前