BishopFox / ysoserial-bfLinks
A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.
☆33Updated last year
Alternatives and similar repositories for ysoserial-bf
Users that are interested in ysoserial-bf are comparing it to the libraries listed below
Sorting:
- Additional resources for leaking and exploiting ObjRefs via HTTP .NET Remoting (CVE-2024-29059)☆91Updated last year
- ☆41Updated last month
- Apache commons text - CVE-2022-42889 Text4Shell proof of concept exploit.☆56Updated last year
- Utility for creating ZipSlip archives☆80Updated 2 years ago
- Proof of Concept for Path Traversal in Apache Struts ("CVE-2023-50164")☆57Updated 2 years ago
- Dockerized POC for CVE-2022-42889 Text4Shell☆76Updated 3 years ago
- Exploits targeting vBulletin.☆75Updated 2 years ago
- A project for fuzzing HTTP/1.1 CL.0 Request Smuggling Attack Vectors☆90Updated last year
- Exploit for CVE-2024-20767 - Adobe ColdFusion☆34Updated last year
- ☆42Updated 2 years ago
- Ruby-SAML / GitLab Authentication Bypass (CVE-2024-45409) exploit☆82Updated last year
- Exploit for CVE-2024-27198 - TeamCity Server☆35Updated last year
- CVE-2023-21554 Windows MessageQueuing PoC,分析见 https://www.zoemurmure.top/posts/cve_2023_21554/☆57Updated 2 years ago
- CVE-2023-33733 reportlab RCE☆117Updated 2 years ago
- Simple tool to decrypt Jenkins encrypted strings☆79Updated 2 years ago
- CVE-2024-23897 jenkins-cli☆15Updated last year
- Burp Extension to add additional functionality for pentesting websocket based applications☆101Updated 4 months ago
- Introduction to CYS4-SensitiveDiscoverer, a Burp extension that discovers sensitive information inside HTTP messages.☆24Updated last year
- ☆68Updated 11 months ago
- PoC repository for CVE-2023-29007☆35Updated 2 years ago
- F5 BIG-IP RCE exploitation (CVE-2022-1388)☆88Updated 3 years ago
- ☆113Updated 2 years ago
- This repository offers insights and a proof-of-concept tool to exploit two significant deserialization vulnerabilities in Inductive Autom…☆46Updated 2 years ago
- A tool for identifying and exploiting vulnerable Viewstate implementations in ASP.NET☆58Updated 2 weeks ago
- Golden collection of weak passwords☆69Updated last year
- CVE-2023-34362: MOVEit Transfer Unauthenticated RCE☆64Updated last year
- OpenSSH Pre-Auth Double Free CVE-2023-25136 POC☆47Updated 2 years ago
- Burp extension to check and exploit the IIS Tilde Enumeration/IIS 8.3 Short Filename Disclosure vulnerability☆61Updated 2 years ago
- Proof of conept to exploit vulnerable proxycommand configurations on ssh clients☆19Updated 2 years ago
- My talks...☆25Updated 10 months ago