XStream-Gadgets
Exploitation gadgets
A collection of gadgets ported from ysoserial, transformed into the XStream serialization format to facilitate exploitation in Java applications.
Several XStream gadgets ported from ysoserial
32 stars
1 watching
5 forks
Language: Java
last commit: over 3 years ago Related projects:
Repository | Description | Stars |
---|---|---|
| A collection of bypass gadgets to extend and wrap ysoserial payloads | 351 |
| A proof-of-concept project demonstrating exploitation of a vulnerability in Jackson-databind via Spring application contexts and expressions. | 121 |
| A tool that exploits vulnerabilities in web servers to execute arbitrary code | 9 |
| A collection of Cobalt Strike scripts designed to facilitate red teaming and exploitation | 800 |
| An exploitation project demonstrating how to chain vulnerabilities in Safari to escalate privilege on macOS | 404 |
| A tool for searching and exploiting vulnerabilities in binary code using Return-Oriented Programming and Jump-Oriented Programming techniques. | 85 |
| A comprehensive database of vulnerability and exploitation reports | 248 |
| A proof-of-concept web application demonstrating an XML External Entity vulnerability | 225 |
| Analyzes Java applications for potential deserialization gadget chains to help identify vulnerabilities and prioritize remediation. | 1,005 |
| An exploit kit designed to start an HTTP Server, RMI Server and LDAP Server to exploit Java web apps vulnerable to JNDI Injection | 903 |
| An implementation of Jupyter interactive widgets in C++ | 137 |
| An in-depth exploration of browser exploitation techniques and vulnerability discovery | 446 |
| A collection of tools and techniques for exploiting vulnerabilities in Google services | 45 |
| A set of tools for gathering information and exploiting vulnerabilities in IBM Power Systems | 97 |
| A vulnerable blogging platform demonstrating various XSS vulnerabilities to showcase security weaknesses and demonstrate exploitation techniques. | 9 |