Repository navigation

#

ysoserial

80+ Gadgets(30 More than ysoserial). JNDI-Injection-Exploit-Plus is a tool for generating workable JNDI links and provide background services by starting RMI server,LDAP server and HTTP server.

Java
823
1 年前

ZKar is a Java serialization protocol analysis tool implement in Go.

Go
625
6 个月前

JMX enumeration and attacking tool.

Java
457
2 个月前

proof-of-concept for generating Java deserialization payload | Proxy MemShell

Java
200
1 年前

Programmatically create hunting rules for deserialization exploitation with multiple keywords, gadget chains, object types, encodings, and rule types

YARA
144
2 年前

Java反序列化/JNDI注入/恶意类生成工具,支持多种高版本bypass,支持回显/内存马等多种扩展利用。

Java
116
14 天前

Some codes for bypassing Oracle WebLogic CVE-2018-2628 patch

Java
114
7 年前

RmiTaste allows security professionals to detect, enumerate, interact and exploit RMI services by calling remote methods with gadgets from ysoserial.

Java
109
5 年前

A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.

Rust
70
3 年前

A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.

Rust
70
3 年前

Some PoC (Proof-of-Concept) about vulnerability of java deserialization of untrusted data

FreeMarker
26
4 年前

Some PoC (Proof-of-Concept) about vulnerability of java deserialization of untrusted data

FreeMarker
26
4 年前

🌊 Dockerfiles for apps I use. Also take a look at https://github.com/security-dockerfiles

Dockerfile
23
5 年前

🌊 Dockerfiles for apps I use. Also take a look at https://github.com/security-dockerfiles

Dockerfile
23
5 年前

Python-based proof-of-concept tool for generating payloads that utilize unsafe Java object deserialization.

Python
9
4 年前

Python-based proof-of-concept tool for generating payloads that utilize unsafe Java object deserialization.

Python
9
4 年前

Python wrapper for ysoserial

Python
5
6 年前

ysoserial A collection of works by various masters

Java
3
1 年前