#

deserialization-vulnerability

https://static.github-zh.com/github_avatars/vulhub?size=40
Dockerfile 1.73 k
5 个月前
https://static.github-zh.com/github_avatars/a1phaboy?size=40

Fastjson扫描器,可识别版本、依赖库、autoType状态等。A tool to distinguish fastjson ,version and dependency

Go 1.04 k
3 年前
https://static.github-zh.com/github_avatars/H4cking2theGate?size=40

Java反序列化/JNDI注入/恶意类生成工具,支持多种高版本bypass,支持回显/内存马等多种扩展利用。

Java 131
7 天前
https://static.github-zh.com/github_avatars/j0lt-github?size=40

Peas create serialized payload for deserialization RCE attack on python driven applications where pickle ,pyYAML, ruamel.yaml or jsonpickle module is used for deserialization of serialized data. I wil...

Python 122
2 年前
https://static.github-zh.com/github_avatars/tweedge?size=40

Everything I needed to understand what was going on with "Spring4Shell" - translated source materials, exploit, links to demo apps, and more.

Python 107
3 年前
https://static.github-zh.com/github_avatars/GhostTroops?size=40

#大语言模型#GPT AiCSA(Code security audit),SAST(Static Application Security Testing,静态应用程序安全测试),JAR security analysis, static vulnerability and vulnerability analysis of various programming language codes

JavaScript 60
2 年前
https://static.github-zh.com/github_avatars/hvqzao?size=40
Java 23
9 年前
https://static.github-zh.com/github_avatars/hktalent?size=40
Shell 10
2 年前
https://static.github-zh.com/github_avatars/thomasleplus?size=40

A JBoss Byteman rule to debug the trace the JDK deserialization filtering

JavaScript 5
3 天前
https://static.github-zh.com/github_avatars/klezVirus?size=40
Python 4
6 年前
https://static.github-zh.com/github_avatars/nth347?size=40

PoC for CVE-2020-28032 (It's just a POP chain in WordPress < 5.5.2 for exploiting PHP Object Injection)

PHP 4
4 年前
https://static.github-zh.com/github_avatars/sum-catnip?size=40
Python 1
5 年前
https://static.github-zh.com/github_avatars/dub-flow?size=40

This project contains a Java deserialization vulnerability that is exploitable with some ysoserial payloads, but also contains a custom class that can be leveraged to get command execution upon deseri...

Java 1
3 年前
https://static.github-zh.com/github_avatars/trganda?size=40

Fake MySQL Server for Exploit Vulnerability of MySQL JDBC Driver

Java 1
2 年前
https://static.github-zh.com/github_avatars/AreedAhmed?size=40

This tool is responsible to perform java deserialization attacks on server end points

Python 0
2 年前
loading...
Website
Wikipedia