rmi-deserialization
RMI vulnerability demo
Demonstrating vulnerabilities in Java RMI services
Slides/Demos from the BSides Munich 2019 talk "Attacking Java RMI in 2019"
101 stars
4 watching
6 forks
Language: Java
last commit: over 5 years ago Related projects:
Repository | Description | Stars |
---|---|---|
| A tool used to identify and exploit security vulnerabilities in Java RMI endpoints | 841 |
| A lab project providing code samples and tools to understand deserialization vulnerabilities in Java applications. | 497 |
| Reproducing and analyzing the CVE-2021-29505 vulnerability in Java's XStream deserialization process | 5 |
| Tools for analyzing and exploiting vulnerabilities in Java deserialization vulnerabilities | 587 |
| A plugin for detecting and exploiting vulnerabilities in Java deserialization | 775 |
| A tool designed to exploit vulnerabilities in the Java RMI system using various techniques such as deserialization and socket-based attacks. | 251 |
| A proof of concept project demonstrating a remote code execution vulnerability in Apache Solr via deserialization of untrusted data | 209 |
| A Burp extension that enables Java Deserialization Attacks using a payload generator tool | 208 |
| A Java library that generates high-quality Linked Data from multiple semi-structured data sources using RML rules. | 161 |
| An enumeration and attack tool for insecure RMI services | 720 |
| A Burp Suite Extender to identify Java Deserialization vulnerabilities in client requests and server responses. | 9 |
| A tool to detect and exploit deserialization vulnerabilities in Java and .NET applications. | 574 |
| An active Java deserialization vulnerability identifier and exploiter | 7 |
| An Android app designed to demonstrate common web application vulnerabilities and provide training in secure coding practices. | 10 |
| A cheat sheet providing guidance on deserialization vulnerabilities in Java applications | 3,044 |