ysoserial topic

List ysoserial repositories

beanshooter

362
Stars
44
Forks
Watchers

JMX enumeration and attacking tool.

zkar

567
Stars
52
Forks
Watchers

ZKar is a Java serialization protocol analysis tool implement in Go.

heyserial

136
Stars
20
Forks
Watchers

Programmatically create hunting rules for deserialization exploitation with multiple keywords, gadget chains, object types, encodings, and rule types

ysoserial-cve-2018-2628

113
Stars
49
Forks
Watchers

Some codes for bypassing Oracle WebLogic CVE-2018-2628 patch

JNDI-Injection-Exploit-Plus

612
Stars
84
Forks
Watchers

80+ Gadgets(30 More than ysoserial). JNDI-Injection-Exploit-Plus is a tool for generating workable JNDI links and provide background services by starting RMI server,LDAP server and HTTP server.

RmiTaste

108
Stars
22
Forks
Watchers

RmiTaste allows security professionals to detect, enumerate, interact and exploit RMI services by calling remote methods with gadgets from ysoserial.

Some PoC (Proof-of-Concept) about vulnerability of java deserialization of untrusted data

dockerfiles

23
Stars
8
Forks
Watchers

🌊 Dockerfiles for apps I use. Also take a look at https://github.com/security-dockerfiles

JYso

1.2k
Stars
156
Forks
Watchers

It can be either a JNDIExploit or a ysoserial.

ysoserial-rs

69
Stars
15
Forks
Watchers

A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.