BishopFox / ysoserial-bfLinks
A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.
☆34Updated last year
Alternatives and similar repositories for ysoserial-bf
Users that are interested in ysoserial-bf are comparing it to the libraries listed below
Sorting:
- Additional resources for leaking and exploiting ObjRefs via HTTP .NET Remoting (CVE-2024-29059)☆91Updated last year
- Utility for creating ZipSlip archives☆80Updated 2 years ago
- ☆42Updated 2 months ago
- Proof of Concept for Path Traversal in Apache Struts ("CVE-2023-50164")☆57Updated 2 years ago
- A project for fuzzing HTTP/1.1 CL.0 Request Smuggling Attack Vectors☆90Updated last year
- ☆68Updated last year
- Apache commons text - CVE-2022-42889 Text4Shell proof of concept exploit.☆56Updated 2 years ago
- ☆43Updated 2 years ago
- Golden collection of weak passwords☆69Updated last year
- Burp Extension to add additional functionality for pentesting websocket based applications☆103Updated 4 months ago
- Exploits targeting vBulletin.☆75Updated 2 years ago
- Dockerized POC for CVE-2022-42889 Text4Shell☆76Updated 3 years ago
- Exploit for CVE-2024-20767 - Adobe ColdFusion☆34Updated last year
- CVE-2023-33733 reportlab RCE☆119Updated 2 years ago
- Perform TE.CL HTTP Request Smuggling attacks by crafting HTTP Request automatically.☆73Updated 3 years ago
- Authentication Bypass in GoAnywhere MFT☆64Updated last year
- Ruby-SAML / GitLab Authentication Bypass (CVE-2024-45409) exploit☆82Updated last year
- Deserialization payload generator for a variety of .NET formatters☆169Updated last month
- A tool for identifying and exploiting vulnerable Viewstate implementations in ASP.NET☆59Updated last month
- A BurpSuite extension to deploy an OpenVPN config file to DigitalOcean and set up a SOCKS proxy to route traffic through it☆51Updated 2 months ago
- Exploit for CVE-2024-27198 - TeamCity Server☆35Updated last year
- SQLMap wrapper that lets you use Interact.sh as a DNS server for exfiltrating data with zero configuration☆45Updated 9 months ago
- CVE-2023-34362: MOVEit Transfer Unauthenticated RCE☆64Updated last year
- OpenSSH Pre-Auth Double Free CVE-2023-25136 POC☆47Updated 2 years ago
- cve-2022-42889 Text4Shell CVE-2022-42889 affects Apache Commons Text versions 1.5 through 1.9. It has been patched as of Commons Text ver…☆39Updated 3 years ago
- POC for RCE vulnerability in ParseExcel library, and ParseXLSX too, as a depending library☆18Updated last year
- Copy as XMLHttpRequest BurpSuite extension☆32Updated 4 years ago
- This extension enhances Burp Suite by adding several UI and functional features, making it more user-friendly.☆73Updated last year
- My talks...☆25Updated 10 months ago
- Repository to store exploits created by Assetnotes Security Research team☆180Updated 2 years ago