用Go+Fyne开发的,展示JAVA序列化流以及集成一键插入脏数据,UTF过长编码绕WAF(Utf OverLoad Encoding),修改类SerializeVersionUID功能的图形化工具。
☆127Jan 14, 2025Updated last year
Alternatives and similar repositories for SerializeJava
Users that are interested in SerializeJava are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- 本工具为jeecg框架漏洞利用工具非jeecg-boot!☆183Aug 13, 2024Updated last year
- JavaGadgetGenerator 工具,支持 ysoserial,Hessian,字节码,Expr/SSTI,Shiro,JDBC 等 Gadget 生成,封装,混淆,出网延迟探测,内存马注入等...☆571Apr 3, 2026Updated 2 months ago
- 一款Java内存马生成 、测试工具,搭配@ax1sX的MemShell食用。☆262Feb 15, 2026Updated 3 months ago
- 使用 agent 实现反序列化 utf8 overlong☆86Apr 24, 2024Updated 2 years ago
- GodInfo 是一个功能全面的后渗透信息和凭据收集工具,旨在帮助安全测试人员在获得授权访问权限后,快速收集目标系统的信息和凭据。☆255Apr 29, 2025Updated last year
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- 一款支持自定义的 Java 回显载荷生成工具|A customizable Java echo payload generation tool.☆464Jan 12, 2025Updated last year
- 用java实现构造openwire协议,利用activeMQ < 5.18.3 RCE 回显利用 内存马注入☆290Nov 20, 2023Updated 2 years ago
- 一款让你不只在dubbo-sample、vulhub或者其他测试环境里检测和利用成功的Apache Dubbo 漏洞检测工具。☆172Aug 9, 2023Updated 2 years ago
- 帆软bi反序列化漏洞利用工具☆423Jan 25, 2025Updated last year
- 让"WAF绕过"变得简单☆437Jan 26, 2025Updated last year
- 《深入JDBC安全:特殊URL构造与不出网反序列化利用技术揭秘》对应研究总结项目 "Deep Dive into JDBC Security: Special URL Construction and Non-Networked Deserialization Explo…☆591Feb 7, 2026Updated 4 months ago
- 可能是windows最小的wget (862字节)☆70Dec 13, 2024Updated last year
- JNDI在java高版本的利用工具,FUZZ利用链☆601Oct 8, 2022Updated 3 years ago
- 命令执行不回显但DNS协议出网的命令回显场景解决方案☆277Jan 10, 2023Updated 3 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- 一款专注于 Java 主流 Web 中间件的内存马快速生成工具,致力于简化安全研究人员和红队成员的工作流程,提升攻防效率☆1,500May 30, 2026Updated last week
- ☆78Nov 22, 2024Updated last year
- NacosExploit 命令执行 内存马等利用☆218Jul 18, 2024Updated last year
- 某软最新公开gadgegt,新加入不出网利用。☆88Sep 6, 2024Updated last year
- grs内网穿透工具通过reality协议隐藏特征☆611Dec 4, 2025Updated 6 months ago
- 哥斯拉Hikvision综合安防后渗透插件,运行中心/web前台/MinIO 配置提取(解密)重置密码,还原密码。☆174Oct 8, 2024Updated last year
- PHP文件上传50+绕过手法全景解析☆18Mar 16, 2025Updated last year
- 🔍 CodeAuditAssistant - JetBrains Code Audit Plugin (Beta) ⚡ Deep Call-Chain Tracking | 🚀 Method/Class Search | 🔥 Prebuilt Vuln Sink…☆785Mar 14, 2026Updated 2 months ago
- A powerful JNDI injection exploitation framework that supports RMI, LDAP and LDAPS protocols, including various bypass methods for high-v…☆585May 4, 2026Updated last month
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- 腾讯安全沙龙 一 二 三 期PPT集合☆19May 24, 2025Updated last year
- JavaPassDump☆275Jan 7, 2022Updated 4 years ago
- 帆软报表漏洞检测工具☆120Jun 10, 2025Updated 11 months ago
- Confluence CVE 2021,2022,2023 利用工具,支持命令执行,哥斯拉,冰蝎 内存马注入☆558Feb 1, 2024Updated 2 years ago
- Godzilla插件|内存马|Suo5内存代理|jmg for Godzilla☆243Jun 6, 2024Updated 2 years ago
- 支持注入内存马和Bypass WAF☆29Dec 12, 2023Updated 2 years ago
- 用于Webshell木马免杀、流量加密传输,多多支持star☆1,052Jun 27, 2025Updated 11 months ago
- 命令执行不回显但DNS协议出网的命令回显场景解决方案(修改 为使用ceye接收请求,添加自定义DNS服务器)☆292Aug 20, 2023Updated 2 years ago
- Burpsuite - Js Route Scan 正则匹配获取响应中的路由进行被动探测与递归目录探测的burp插件☆375Jun 7, 2024Updated 2 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- burp手工检测fastjson辅助☆89Mar 4, 2024Updated 2 years ago
- 闭源系统半自动漏洞挖掘工具,针对 jar/war/zip 进行静态代码分析,输出从source到sink的可达路径。LLM将验证路径可达性,并根据上下文给出该路径可信分数☆508Jan 12, 2026Updated 4 months ago
- 亿赛通电子文档安全管理系统XStream反序列化漏洞任意文件上传利用☆120Aug 9, 2024Updated last year
- MDUT-Extend(扩展版本)☆925Mar 27, 2026Updated 2 months ago
- 针对JWT渗透开发的漏洞验证/密钥爆破工具,针对CVE-2015-9235/空白密钥/未验证签名攻击/CVE-2016-10555/CVE-2018-0114/CVE-2020-28042的结果生成用于FUZZ,也可使用字典/字符枚举(包括JJWT)的方式进行爆破(JWT …☆289Aug 12, 2025Updated 9 months ago
- 复杂请求下的Shiro反序列化利用工具☆420Mar 12, 2024Updated 2 years ago
- ☆312Feb 27, 2025Updated last year