JNDIExploit or a ysoserial.
-
Updated
Jun 14, 2026 - Java
JNDIExploit or a ysoserial.
ZKar is a Java serialization protocol analysis tool implement in Go.
JMX enumeration and attacking tool.
proof-of-concept for generating Java deserialization payload | Proxy MemShell
Java反序列化/JNDI注入/恶意类生成工具,支持多种高版本bypass,支持回显/内存马等多种扩展利用。
Programmatically create hunting rules for deserialization exploitation with multiple keywords, gadget chains, object types, encodings, and rule types
Some codes for bypassing Oracle WebLogic CVE-2018-2628 patch
RmiTaste allows security professionals to detect, enumerate, interact and exploit RMI services by calling remote methods with gadgets from ysoserial.
Some PoC (Proof-of-Concept) about vulnerability of java deserialization of untrusted data
🌊 Dockerfiles for apps I use. Also take a look at https://github.com/security-dockerfiles
Python-based proof-of-concept tool for generating payloads that utilize unsafe Java object deserialization.
ysoserial A collection of works by various masters
Java object serialization stream parser written in Rust
Automates generating Java serialized payload wordlist with Ysoserial and associated compression/encoding
To associate your repository with the ysoserial topic, visit your repo's landing page and select "manage topics."