ysoserial
Deserialization exploit tool
Generates payloads to exploit unsafe Java object deserialization vulnerabilities
A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.
8k stars
213 watching
2k forks
Language: Java
last commit: 12 months ago
Linked from 1 awesome list
deserializationexploitgadgetjavajavadeserjvmpocserializationvulnerability
Related projects:
Repository | Description | Stars |
---|---|---|
| Generates payloads to exploit unsafe .NET object deserialization. | 3,260 |
| A cheat sheet providing guidance on deserialization vulnerabilities in Java applications | 3,044 |
| Tools for analyzing and exploiting vulnerabilities in Java deserialization vulnerabilities | 587 |
| A presentation and discussion on the security risks of deserialization in Java object graphs. | 5 |
| A utility for generating deserialization payloads in SnakeYAML format to exploit certain security vulnerabilities | 570 |
| A lab project providing code samples and tools to understand deserialization vulnerabilities in Java applications. | 497 |
| Analyzes Java applications for potential deserialization gadget chains to help identify vulnerabilities and prioritize remediation. | 1,005 |
| A Burp extension that enables Java Deserialization Attacks using a payload generator tool | 208 |
| An agent that prevents deserialization attacks by making certain classes unserializable | 186 |
| A tool to deserialize Java objects to XML and load classes/jars dynamically. | 15 |
| A development platform to generate and deploy modern web applications using various frameworks and tools. | 21,622 |
| Reproducing and analyzing the CVE-2021-29505 vulnerability in Java's XStream deserialization process | 5 |
| A plugin for detecting and exploiting vulnerabilities in Java deserialization | 775 |
| Analyzes and exploits vulnerabilities in Java marshalling libraries to demonstrate potential code execution | 3,419 |
| Demonstrating vulnerabilities in Java RMI services | 101 |