Jlan45 / ysoserialSecondLinks
A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.
☆14Updated last year
Alternatives and similar repositories for ysoserialSecond
Users that are interested in ysoserialSecond are comparing it to the libraries listed below
Sorting:
- 发布一些我发现的漏洞以及利用脚本。☆15Updated last year
- Yapi mock script RCE another version. Webshell way. 另一种 Webshell 方式的 Yapi 命令执行的方法 相比于其他的利用方式 更加微操和可控 影响更小☆66Updated 11 months ago
- Redis primary/secondary replication RCE☆44Updated 3 years ago
- Netty/WebFlux 内存马☆25Updated last year
- ☆79Updated 7 months ago
- ☆35Updated 2 years ago
- ☆24Updated 5 months ago
- CVE-2023-46604☆28Updated last year
- 分享ABC_123自己改造的ysoserial工具,java反序列化漏洞利用,生成的java反序列化利用链支持jdk1.5版本的老旧系统的利用。☆47Updated 3 months ago
- PoC of Apache Dubbo CVE-2023-23638☆33Updated last year
- CVE-2023-46604☆63Updated last year
- Java 内存马生成插件☆53Updated 2 years ago
- 如果反序列化过程中使用resolveClass拉黑了TemplatesImpl如何绕过☆51Updated last year
- 大华智慧园区系统sso_initsession文件上传批量脚本☆21Updated last year
- JWT秘钥爆破脚本☆28Updated 2 years ago
- 内存马生成工具 Tomcat、Weblogic、CMD、Behinder、Godzilla、Suo5......☆28Updated 4 months ago
- 虚拟WebShell及内存马系列,来源自.NET安全矩阵星球☆28Updated 10 months ago
- 添加Connector内存马与ws内存马检测逻辑☆16Updated 2 years ago
- sliver-webhook 实现上线通知☆25Updated 2 years ago
- 解决先知文件大小限制的问题☆16Updated 10 months ago
- 在spring-aop中新发现的反序列化gadget-chain☆47Updated 5 months ago
- lineadd 渗透测试字典管理工具, 让字典管理生活轻松一点。Penetration test dictionary management tool, make dictionary management life a little easier.☆27Updated last year
- Hessian UTF-8 Overlong Encoding☆18Updated last year
- (0day)DBSyncer后台自定义插件上传-注入内存马☆13Updated 9 months ago
- 就是一个burp插件啦(ÒܫÓױ)☆18Updated 3 years ago
- c3p0 new gadget☆22Updated 2 months ago
- zip slip☆37Updated 2 years ago
- 解密DBeaver数据库软件保存的密码☆30Updated last year
- A IntelliJ Plugin for Tabby to Find Vulnerabilities Easily☆35Updated 7 months ago
- ☆56Updated last year