Repository navigation

#

ysoserial

80+ Gadgets(30 More than ysoserial). JNDI-Injection-Exploit-Plus is a tool for generating workable JNDI links and provide background services by starting RMI server,LDAP server and HTTP server.

Java
781
10 个月前

ZKar is a Java serialization protocol analysis tool implement in Go.

Go
610
2 个月前

JMX enumeration and attacking tool.

Java
433
1 个月前

proof-of-concept for generating Java deserialization payload | Proxy MemShell

Java
191
10 个月前

Programmatically create hunting rules for deserialization exploitation with multiple keywords, gadget chains, object types, encodings, and rule types

YARA
142
2 年前

Some codes for bypassing Oracle WebLogic CVE-2018-2628 patch

Java
114
7 年前

RmiTaste allows security professionals to detect, enumerate, interact and exploit RMI services by calling remote methods with gadgets from ysoserial.

Java
107
5 年前

Java反序列化/JNDI注入/恶意类生成工具,支持多种高版本bypass,支持回显/内存马等多种扩展利用。

Java
98
2 个月前

A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.

Rust
69
2 年前

A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.

Rust
69
2 年前

Some PoC (Proof-of-Concept) about vulnerability of java deserialization of untrusted data

FreeMarker
26
4 年前

Some PoC (Proof-of-Concept) about vulnerability of java deserialization of untrusted data

FreeMarker
26
4 年前

🌊 Dockerfiles for apps I use. Also take a look at https://github.com/security-dockerfiles

Dockerfile
23
4 年前

🌊 Dockerfiles for apps I use. Also take a look at https://github.com/security-dockerfiles

Dockerfile
22
4 年前

Python-based proof-of-concept tool for generating payloads that utilize unsafe Java object deserialization.

Python
9
3 年前

Python-based proof-of-concept tool for generating payloads that utilize unsafe Java object deserialization.

Python
9
3 年前

Python wrapper for ysoserial

Python
5
6 年前

ysoserial A collection of works by various masters

Java
3
1 年前